
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,082 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of PowerShell commands used to initiate remote sessions (e.g., New-PSSession, Invoke-Command) targeting specific remote hosts, excluding localhost connections and common system processes. This behavior is often associated with lateral movement or remote administration activities.
Detects the use of known named pipes associated with Cobalt Strike post-exploitation frameworks, often used for inter-process communication during beaconing or lateral movement.
This rule detects potentially malicious software supply chain attacks by identifying suspicious child processes spawned by package managers (pip, npm) or Python scripting engines within a short timeframe. It specifically looks for shells (cmd, powershell, bash, etc.) being invoked immediately after a package installation or script execution, and correlates this activity with suspicious outbound network connections originating from these processes.
Detects successful user sign-ins from a country that has not been observed in the user's sign-in activity over the past 30 days. This baseline helps identify potentially compromised accounts by surfacing geographic anomalies.
Detects any modification (add, update, or delete) to Entra ID cross-tenant access settings. Adversaries may manipulate these trust configurations to weaken inbound security restrictions, establish unauthorized access between tenants, or facilitate cross-tenant impersonation.
This rule detects the creation of named pipes associated with known command-and-control (C2) frameworks, post-exploitation toolkits, and suspicious system activity. By filtering out common legitimate system processes and monitoring for specific pipe patterns (e.g., Cobalt Strike, Metasploit, PsExec, and sensitive RPC endpoints), the rule identifies potential lateral movement, remote execution, and post-exploitation communication channels.
This rule detects known Living-off-the-Land Binaries (LOLBins) initiating outbound network connections to specific non-standard or commonly suspicious ports (8080, 8443, 4444, 1337, 1234). The rule excludes private/loopback network traffic and common Microsoft-related domains to reduce noise. Such behavior is often indicative of malicious activity, including C2 communication or unauthorized file downloads via trusted system processes.
This rule detects when sensitive administrative roles are assigned directly to users in Microsoft Entra ID (formerly Azure AD) without utilizing the Privileged Identity Management (PIM) service. Direct assignment of these roles bypasses the security controls and JIT (Just-In-Time) access workflows enforced by PIM, potentially indicating unauthorized privilege escalation or a misconfiguration.
This rule detects potential Kerberoasting activity by monitoring Windows Event ID 4769 (Kerberos service ticket request). It identifies excessive requests for service tickets using RC4 encryption (0x17) by a single account within a 10-minute window, excluding common service accounts and krbtgt requests.
Detects bulk file access, download, or sync operations by a single user account within a 30-minute window in Microsoft SharePoint Online or OneDrive for Business. This behavior is indicative of potential data exfiltration or unauthorized mass collection of sensitive information.
