
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,042 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects an unusually high volume (100 or more within an hour) of API calls (POST, DELETE, PUT methods to URIs containing 'api') originating from a single IP address. This activity could indicate various malicious behaviors such as brute-force attacks, credential stuffing, web application attacks, or a denial-of-service attempt against the API endpoint.
This rule detects a high volume of network connections (10 or more within an hour) from a single process to remote URLs containing 'artifact' or 'maven' on standard HTTP (port 80) or HTTPS (port 443) ports. This activity could indicate legitimate software development or build processes, but also potentially malicious activities such as supply chain compromise, data staging, or exfiltration of development-related artifacts.
This rule detects when multiple versions of files are deleted within SharePoint by a single user. This could indicate an attempt to remove historical data or cover tracks.
Detects the successful creation or update of an Azure API Management Service. This activity could indicate legitimate administrative actions or, if unexpected, potential unauthorized access or privilege escalation within the Azure environment. Monitoring these events can help identify suspicious configuration changes or resource provisioning by malicious actors.
Detects a spike in successful operations related to Azure Storage Account Keys by a single caller within a one-hour window. This could indicate an adversary attempting to enumerate, access, or exfiltrate storage account keys, or a legitimate user performing multiple key management activities.
Detects an unusual volume of 'Logging' or 'Monitor' operations within Azure Activity logs from a single caller within an hour. This could indicate an adversary attempting to enumerate logging configurations, monitor activities, or potentially tamper with logging settings as a precursor to other malicious activities or an attempt to cover tracks.
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying successful user sign-ins from a new, historically unseen IP address occurring within 30 minutes of a legitimate sign-in from a known IP, indicating the potential replay of a stolen session or refresh token.
This rule detects a high volume of access attempts (5 or more within an hour) to administrative shares (C$, D$, E$, ADMIN$) from a single source IP address. This activity can be indicative of lateral movement, data exfiltration, or reconnaissance by an adversary attempting to gain access to sensitive information or spread malware across the network.
This rule detects suspicious command-line activity indicative of potential token impersonation or theft. It specifically looks for the keywords 'token' or 'impersonate' within process creation command lines (EventID 4688) and triggers an alert if these keywords appear 3 or more times within an hour on the same computer by the same account. This could indicate an adversary attempting to manipulate access tokens to elevate privileges or operate under a different security context.
This rule detects when a user adds mailbox permissions to three or more mailboxes within a one-hour window in Exchange Online. This behavior can indicate an adversary attempting to gain persistent access to multiple mailboxes, often for data exfiltration or further compromise.
