avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,042 views

8,664 detections

Detects an unusually high volume (100 or more within an hour) of API calls (POST, DELETE, PUT methods to URIs containing 'api') originating from a single IP address. This activity could indicate various malicious behaviors such as brute-force attacks, credential stuffing, web application attacks, or a denial-of-service attempt against the API endpoint.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects a high volume of network connections (10 or more within an hour) from a single process to remote URLs containing 'artifact' or 'maven' on standard HTTP (port 80) or HTTPS (port 443) ports. This activity could indicate legitimate software development or build processes, but also potentially malicious activities such as supply chain compromise, data staging, or exfiltration of development-related artifacts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects when multiple versions of files are deleted within SharePoint by a single user. This could indicate an attempt to remove historical data or cover tracks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the successful creation or update of an Azure API Management Service. This activity could indicate legitimate administrative actions or, if unexpected, potential unauthorized access or privilege escalation within the Azure environment. Monitoring these events can help identify suspicious configuration changes or resource provisioning by malicious actors.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects a spike in successful operations related to Azure Storage Account Keys by a single caller within a one-hour window. This could indicate an adversary attempting to enumerate, access, or exfiltrate storage account keys, or a legitimate user performing multiple key management activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects an unusual volume of 'Logging' or 'Monitor' operations within Azure Activity logs from a single caller within an hour. This could indicate an adversary attempting to enumerate logging configurations, monitor activities, or potentially tamper with logging settings as a precursor to other malicious activities or an attempt to cover tracks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying successful user sign-ins from a new, historically unseen IP address occurring within 30 minutes of a legitimate sign-in from a known IP, indicating the potential replay of a stolen session or refresh token.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
507
This rule detects a high volume of access attempts (5 or more within an hour) to administrative shares (C$, D$, E$, ADMIN$) from a single source IP address. This activity can be indicative of lateral movement, data exfiltration, or reconnaissance by an adversary attempting to gain access to sensitive information or spread malware across the network.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects suspicious command-line activity indicative of potential token impersonation or theft. It specifically looks for the keywords 'token' or 'impersonate' within process creation command lines (EventID 4688) and triggers an alert if these keywords appear 3 or more times within an hour on the same computer by the same account. This could indicate an adversary attempting to manipulate access tokens to elevate privileges or operate under a different security context.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects when a user adds mailbox permissions to three or more mailboxes within a one-hour window in Exchange Online. This behavior can indicate an adversary attempting to gain persistent access to multiple mailboxes, often for data exfiltration or further compromise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102