avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views

8,664 detections

Detects anomalous ICMP Echo Request packets (Type 8) directed towards external networks that contain a payload size greater than 128 bytes. Such anomalies are often indicative of ICMP tunneling, which may be leveraged by adversaries for command and control (C2) communication or data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects changes to Microsoft Entra (formerly Azure AD) Conditional Access policies. This includes additions, updates, or deletions of these security policies, which could indicate an attacker attempting to weaken authentication requirements, bypass multi-factor authentication, or establish persistence within the identity environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects user sign-in activity originating from more than two distinct countries within the same hour, which is often indicative of impossible travel or compromised credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects instances where the Active Directory domain database file (ntds.dit) is accessed by processes other than known legitimate tools such as lsass.exe or ntdsutil.exe. This activity is a strong indicator of credential dumping attempts to extract Active Directory hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects successful assignment of highly privileged roles (Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator) to a user in Microsoft Entra ID (formerly Azure AD). This is often a sign of privilege escalation or persistence establishment by an attacker.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
403
Detects user sign-in activity originating from more than two distinct countries within the same hour, which is often indicative of impossible travel or compromised credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects the creation of a file named 'NTDS.zip', which is a common naming convention used by adversaries when compressing the Active Directory database (NTDS.dit) for staging and subsequent exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects sign-in events using the device code authentication flow (OAuth 2.0 device authorization grant) where the originating IP address is external to the organization's private network. This flow is often abused by attackers to bypass traditional MFA or interact with headless environments via common HTTP client libraries like Python requests, Go-http, or Axios.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule monitors for additions of users to highly sensitive Active Directory groups, such as Domain Admins or Enterprise Admins, by tracking specific Windows security events (4728, 4732, 4756). Unauthorized membership changes in these groups are a classic indicator of privilege escalation or persistence maintenance by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects specific object access (EventID 4662) targeting sensitive Active Directory objects, including Domain Admin, Enterprise Admin, or other high-value security principal containers. These GUIDs are associated with common Active Directory enumeration or exploitation techniques used to identify critical infrastructure or perform reconnaissance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103