avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views

8,664 detections

This rule detects suspicious activity related to accessing or dumping the NTDS.dit file, which contains Active Directory credential information. It looks for process creation events involving tools commonly used for NTDS.dit extraction (e.g., ntdsutil, secretsdump), file access events on NTDS.dit paths, and privilege use (SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege) often associated with credential dumping.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects PowerShell processes executing with command-line arguments that suggest the use of 'Get-Alias' (gal) or 'Get-Command' (gcm) followed by suspicious patterns. This could indicate an adversary attempting to discover system capabilities or installed modules.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects suspicious network connections to 'outlook-one.vercel.app' or 'api.telegram.org' when initiated by common web browsers (msedge.exe, chrome.exe, firefox.exe) or Outlook (outlook.exe). This pattern can indicate phishing attempts, credential harvesting, or data exfiltration via Telegram bots.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects when fodhelper.exe, a legitimate Windows utility, is used to spawn processes other than cmd.exe or conhost.exe. This behavior is commonly associated with UAC bypass techniques where fodhelper.exe is abused to execute arbitrary commands with elevated privileges without a UAC prompt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the creation or update of an Azure Sentinel analytics rule. This can indicate administrative activity related to security monitoring configuration. Monitoring these changes is crucial for detecting potential tampering with detection capabilities or the introduction of malicious rules.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects instances where a user clicks on a URL identified as potentially malicious (phishing-related) and subsequently has a risky sign-in event in Azure AD. The rule correlates URL click events from email with Azure AD sign-in logs, specifically looking for sign-ins marked as risky or originating from suspicious user agents (e.g., specific axios versions). The phishing URLs are identified by keywords such as 'azureapplicationregistration.pages.dev', 'chrnobinson.com', 'workers.dev', '.pages.dev', '.web.core.windows.net', '/oauth2/v2.0/authorize', 'client_id=', and 'scope=openid'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the presence of known Chaos ransomware samples by matching their SHA256 hashes against process execution events and file events. If a process with a matching hash is executed or a file with a matching hash is observed, an alert will be triggered.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the addition of users to specific high-value or sensitive groups in Microsoft Entra ID (Azure AD), which could indicate potential unauthorized privilege escalation or persistence attempts by an attacker.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of .ics calendar invitation files in common user download and temporary directories when originated by web browsers or Microsoft Outlook. This pattern is often indicative of spearphishing campaigns where attackers use weaponized calendar files to deliver malicious payloads or links, attempting to exploit users through social engineering.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002