
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,987 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects anomalous activities targeting SaaS CRM applications (Salesforce, Microsoft Dynamics 365, HubSpot), including high-volume bulk exports, off-hours access, mass API queries for sensitive objects, and suspicious OAuth token grants.
Flags HarborWatch RAT C2 traffic from mysql.exe to known malicious IPs.
Detects inbound RPC calls to the Server Service interface using operation number 12 (NetrSessionEnum), which may indicate remote session enumeration for account discovery and reconnaissance.
Identifies ScreenConnect client service execution initiated by trusted system processes (dfsvc.exe, services.exe) while referencing suspicious top-level domains (.top, .info, .site, .tk, .xyz, .pw, .ml, .club, .cf, ws) in the command line. This activity may indicate unauthorized remote access deployment or abuse of legitimate remote access tools.
Identifies 'forfiles.exe' being executed with a combination of multiple command-line switches ('/c', '/p', '/m' or their hyphenated equivalents). This pattern can indicate automated scripting or malicious Living-off-the-Land activity, where 'forfiles.exe' is used to execute commands on multiple files or in specific directories.
Detects named pipe activity with remote access enabled, initiated by JsonVMAccessExtension.exe running as SYSTEM. This may indicate abuse of the Azure VM Access Extension for unauthorized remote access.
Detects trusted .NET tooling launching shells, scripting engines, or administrative utilities that are not typically associated with legitimate compilation workflows, potentially indicating malicious execution or post-exploitation.
This rule detects multiple attempts by a user account to perform a Directory Synchronization (DirSync) operation, which is a common indicator of a DCSync attack. The rule specifically looks for Event ID 4662 with properties containing 'DS-DirSync' or '131072', filters for user accounts, excludes known service accounts, and triggers if there are 5 or more attempts from the same account and computer.
Adversaries may create an encrypted RAR archive with specific compression level.
Detects processes loading the Sunburst backdoor DLL.
