avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,502 copies160 likes52,040 views

8,664 detections

Detects updates or deletions of Azure Active Directory (Entra ID) Conditional Access policies that occur outside of typical business hours (Monday-Friday 08:00-18:00 UTC). Such modifications can be an indicator of an adversary attempting to circumvent security controls or maintain persistent, unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential unauthorized access to Azure Storage Blobs following the retrieval of storage account access keys. It correlates 'ListKeys' API events with subsequent blob access activities from either unrecognized IP addresses or via Shared Access Signature (SAS) tokens, indicating potential credential misuse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where a non-SYSTEM parent process spawns a child process running as SYSTEM, characteristic of 'Potato' family exploits (e.g., JuicyPotato, PrintSpoofer) leveraging SeImpersonatePrivilege to elevate privileges. The rule specifically filters for known legitimate SYSTEM process spawners while highlighting suspicious parent-child process relationships.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of bitsadmin.exe to initiate file transfers from remote HTTP/HTTPS locations. This behavior is frequently used by adversaries to download malicious payloads onto a host using legitimate system utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects changes to SharePoint tenant-level or site-level sharing policies that expand external access to 'Anyone' (anonymous links) or 'ExternalUserAndGuestSharing'. Such modifications represent a significant security posture regression that may facilitate unauthorized data access or facilitate exfiltration pathways.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
506
Detects the execution of processes with command-line arguments indicative of destructive activity, such as wiping disks, partitions, or boot records, often associated with wiper malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
008
Detects anomalous or suspicious behavior from Microsoft 365 Copilot agents, plugins, or sessions. This includes bulk access to files containing sensitive keywords, unauthorized export or sharing of sensitivity-labeled documents, and high-volume Microsoft Graph API read activity targeting sensitive paths in SharePoint or OneDrive.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
206
Detects the transmission of potential sensitive information, such as passwords, tokens, API keys, or private keys, within Microsoft Teams chat messages by matching message content against a regular expression pattern for common credential formats.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
606
This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
106