avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,052 views

8,664 detections

This rule detects the use of the Windows Service Control Manager (sc.exe) to create or start a service on a remote host, identified by the presence of UNC paths (\\) and service management commands (create, start) in the command line.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the usage of net.exe or net1.exe to enumerate domain users, groups, local administrators, and domain controllers, which is frequently indicative of post-compromise reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects Distributed Component Object Model (DCOM) lateral movement activity by monitoring for mmc.exe and dllhost.exe network connections to non-local endpoints or when these processes are spawned by suspicious parent processes typically associated with command execution or malicious behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the use of rundll32.exe to execute code via remote URLs, JavaScript, or specific DLL functions known to be abused for proxy execution. This behavior is commonly associated with fileless malware and living-off-the-land techniques to bypass security controls by utilizing legitimate Windows binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects suspicious activity related to the Print Spooler service (spoolsv.exe), specifically focusing on the spawning of known command-line interpreters (cmd.exe, powershell.exe, rundll32.exe) by spoolsv.exe, as well as the creation or modification of DLL files within the system print spool drivers directory by processes other than spoolsv.exe. This activity is often associated with privilege escalation and persistence techniques involving print spooler service abuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of named pipes with names commonly utilized by offensive C2 frameworks such as Cobalt Strike, Metasploit, and Covenant. By monitoring for specific pipe naming patterns created by non-system processes, this rule aims to identify potential post-exploitation activity, C2 beacons, or lateral movement tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects successful sign-ins using the OAuth 2.0 Device Code Flow. This flow is often abused in phishing attacks (device code phishing) where an attacker tricks a user into authenticating a malicious application. A successful sign-in using this method could indicate a compromised account or a successful phishing attempt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
508
Detects Microsoft 365 sign-ins using the device code grant flow from an unusual location or a previously unseen/unmanaged device. This behavior is consistent with OAuth phishing abuse, specifically 'device code phishing' where an adversary tricks a user into entering a code/credentials on a malicious authorization page to obtain a device token.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
608
This rule detects potential AS-REP Roasting activity by monitoring for a single source IP address requesting Kerberos TGTs (Event ID 4768) for multiple distinct user accounts within a 10-minute window. This behavior often indicates an attacker attempting to identify and harvest Kerberos pre-authentication hashes from accounts that do not require pre-authentication, which can then be cracked offline.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002