avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views

8,664 detections

Detects reconnaissance activity where adversaries enumerate domain user accounts using standard Windows command-line tools, PowerShell Active Directory modules, and direct LDAP queries. This behavior is commonly performed to identify user accounts for subsequent password spraying, brute force attacks, or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects users who modify their MFA settings (registration/update/delete) and subsequently perform privileged actions (such as adding role members or service principal credentials) within a short timeframe, while simultaneously observed active in communication applications like Teams, Zoom, or Webex. This behavior is indicative of potential account takeover where an adversary modifies authentication methods to gain persistent access, followed by privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects modifications to COM object InProcServer32 registry keys within the user's registry hive (HKEY_USERS). Attackers often hijack COM objects to achieve persistence by pointing them to malicious DLLs or OCX files. This rule specifically filters out common legitimate paths (Windows directories, Program Files) and known installers to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects unauthorized processes attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data' in Google Chrome, Microsoft Edge, or Brave. These files contain stored credentials and session information that are frequent targets for credential theft malware and post-exploitation activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects changes to the attributes of the AdminSDHolder object in Active Directory. The AdminSDHolder object is a template used by the Active Directory security descriptor propagator (SDProp) to enforce permissions on protected administrative groups. Modification of this object is a highly suspicious activity that can be used to establish persistence or grant excessive privileges by poisoning the security descriptors of all protected objects within the domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects AS-REQ requests for accounts where Kerberos pre-authentication is disabled (PreAuthType 0) and insecure ticket encryption types (0x17, 0x18, 0x1) are used. This behavior is indicative of an AS-REP Roasting attack, where an adversary attempts to obtain the encrypted AS-REP response for an account to perform offline brute-force password cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized processes attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data' in Google Chrome, Microsoft Edge, or Brave. These files contain stored credentials and session information that are frequent targets for credential theft malware and post-exploitation activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
Detects a high volume of file uploads (greater than 50) to OneDrive or SharePoint by a single user within a 5-minute window, potentially indicating bulk exfiltration of data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications to Windows Defender registry keys responsible for defining file, path, process, or extension exclusions. Adversaries often modify these settings to prevent security software from scanning their malicious artifacts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
302