avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views

8,664 detections

Detects when a single account initiates a high volume of Office file (Word, Excel, PowerPoint) copy or move operations within a one-hour window. This could indicate data exfiltration or staging activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects web application processes accessing .env files shortly after execution activity. Bissa Scanner harvested environment files immediately after successful exploitation to collect secrets and credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects abuse of the applescript:// execution mechanism used by newer ClickFix variants to bypass Apple's Terminal paste protections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation or modification of WMI event subscriptions via EventID 5861 from the Microsoft-Windows-WMI-Activity log. This activity, involving EventFilters, EventConsumers, or FilterToConsumerBindings, is a well-known technique used by adversaries to establish persistence and achieve execution triggered by system events, often resulting in elevated SYSTEM privileges.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects updates or deletions of Azure Active Directory (Entra ID) Conditional Access policies that occur outside of typical business hours (Monday-Friday 08:00-18:00 UTC). Such modifications can be an indicator of an adversary attempting to circumvent security controls or maintain persistent, unauthorized access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects attempts to terminate security-related processes or stop security-related services using common administrative tools like taskkill.exe, sc.exe, net.exe, or net1.exe. This activity is often indicative of an adversary attempting to disable security monitoring and protection software to facilitate further malicious actions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects the installation of known vulnerable kernel drivers (Bring Your Own Vulnerable Driver - BYOVD). These drivers are often exploited by adversaries to gain kernel-level code execution, elevate privileges, or disable security tools (EDR).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the use of NTFS Alternate Data Streams (ADS) by monitoring process command lines, initiating process command lines, and folder paths for patterns indicative of ADS notation. The rule specifically flags potential execution or access patterns involving common script interpreters (wscript, cscript, powershell, pwsh) combined with ADS, as well as general ADS usage in file paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003