avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views

8,664 detections

Detects the execution of known Kerberoasting tools such as Rubeus and Impacket (GetST, GetTGT, asktgs) or command-line arguments indicative of Kerberoasting, specifically targeting RC4/ETYPE-23 ticket requests that are often used to crack service account passwords offline.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects common lateral movement patterns associated with Pass-the-Hash (PtH) attacks, specifically identifying remote execution via WMI/services, the use of explicit credentials in management utilities (wmic/net), and suspicious network connections from known administration tools over lateral movement ports.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects anomalous high-volume file download activities from Microsoft SharePoint and OneDrive for Business, which may indicate data exfiltration. The rule aggregates download events by user and IP address over 10-minute intervals and triggers when the download count exceeds 200, excluding known service/backup accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects the execution of known network exploitation tools like Responder.py or MultiRelay.py, as well as unauthorized processes binding to ports used for LLMNR (UDP 5355) and NBT-NS (UDP 137), which are classic indicators of potential adversary-in-the-middle attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects when a single user account performs 3 or more Privileged Identity Management (PIM) role activations within a 30-minute window. This behavior may indicate an attacker who has compromised a privileged account and is rapidly assuming multiple roles to perform lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-volume failed authentication attempts targeting a specific user account from a source IP address, indicative of 'MFA fatigue' or 'push bombing' attacks. This rule monitors endpoint-visible logon failure events as captured by EDR telemetry to identify potential attempts to circumvent multi-factor authentication by spamming the user with requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
405
This rule detects indicators of WMI event subscription persistence, including the creation of WMI event filters, consumers, and bindings. It monitors for the use of command-line tools like wmic, powershell, or mofcomp to manipulate WMI objects, and identifies suspicious process activity originating from WMI provider host or consumer processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) when initialized with an INF file from potentially suspicious directories (e.g., Temp, AppData), or when cmstp.exe is observed spawning common command-line shells (cmd.exe, powershell.exe) or rundll32.exe, which is indicative of potential proxy execution or UAC bypass techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects when users access or download suspicious file types (specifically .xlsm, .docm, or .ics) from Microsoft SharePoint, Teams, or Exchange, where the filenames contain keywords associated with common phishing lures such as credentials, invoices, payroll, or password resets. This monitors for indicators of potential spearphishing attempts involving malicious documents or calendar invites within the M365 environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102