avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,043 views

8,664 detections

This rule detects the execution of the Rubeus tool or the usage of common command-line arguments associated with Kerberoasting activities (e.g., GetUserSPNs, Request-SPNTicket). Kerberoasting is a technique used to extract service account password hashes from Active Directory by requesting service tickets for accounts with Service Principal Names (SPNs). These hashes can then be cracked offline to obtain cleartext credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects outbound network connections from devices to known FortiBleed command and control (C2) servers and sniffer infrastructure IP addresses. This rule helps identify potential compromises involving the FortiBleed vulnerability exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
14013
Detects instances where the Squid proxy application is used to establish network connections over ports 21 (FTP) or 22 (SSH) to specific external IP ranges. This behavior may indicate an attacker using the internal proxy server to anonymize command-and-control (C2) traffic or perform unauthorized external reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
107
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
207
This rule monitors file system events for the creation of files with common web shell names (e.g., shell.php, cmd.php) within known web server directory paths (e.g., wwwroot, inetpub). The detection of these specific file names in directories typically used for serving web content is a strong indicator of a potential web shell deployment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
107
Detects anomalous authentication patterns where a single source IP address exhibits multiple failed login attempts followed by at least one successful login within a 10-minute time window, indicative of credential stuffing or password spraying.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
205
This rule detects when a non-administrative user grants an application high-privilege OAuth scopes (such as mail reading, file access, or directory management) within an Azure/Microsoft 365 environment. Such consent grants can be used by attackers to maintain persistence and bypass MFA by gaining delegated access to sensitive resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
105
This rule detects the use of PowerShell or Command Prompt to execute commands related to Remote Monitoring and Management (RMM) software or remote management tools such as IDrive or TeamViewer. It specifically looks for command-line arguments involving RMM-related keywords combined with execution flags or piping operators, which is a common pattern for automating the deployment, configuration, or malicious use of these remote access tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
Detects when a new federated identity credential is successfully added to an Azure Active Directory (Entra ID) application. This activity is a common method for attackers to establish persistent access to cloud resources by bypassing password-based authentication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105
Detects changes to SharePoint tenant-level or site-level sharing policies that expand external access to 'Anyone' (anonymous links) or 'ExternalUserAndGuestSharing'. Such modifications represent a significant security posture regression that may facilitate unauthorized data access or facilitate exfiltration pathways.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
205