avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,092 views

8,664 detections

This rule detects known Living-off-the-Land Binaries (LOLBins) initiating outbound network connections to specific non-standard or commonly suspicious ports (8080, 8443, 4444, 1337, 1234). The rule excludes private/loopback network traffic and common Microsoft-related domains to reduce noise. Such behavior is often indicative of malicious activity, including C2 communication or unauthorized file downloads via trusted system processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
This rule detects potential token theft or MFA bypass by correlating successful MFA-satisfied interactive sign-ins with subsequent non-interactive sign-ins (token refreshes) occurring within a 60-minute window from different IP addresses for the same user. This pattern is indicative of an attacker stealing a session token (e.g., via session cookie theft or AiTM phishing) and using it to authenticate from a different location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects when a single user account performs 3 or more Privileged Identity Management (PIM) role activations within a 30-minute window. This behavior may indicate an attacker who has compromised a privileged account and is rapidly assuming multiple roles to perform lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the execution of potentially malicious processes (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe) initiated by mmc.exe or explorer.exe, excluding known legitimate Microsoft Management Console (MMC) flags and common management snap-ins. This pattern is indicative of potential proxy execution or misuse of system administration utilities to run unauthorized code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule detects when a user grants an OAuth application consent to access high-privilege scopes in an Azure environment. It specifically flags instances where the consent is not for all principals and the user performing the action is not a Global Administrator, which may indicate an attacker-controlled application being granted access to sensitive data or resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
Detects the use of common PowerShell cmdlets often associated with fileless malware execution, such as 'Invoke-Expression', 'IEX', or 'DownloadString', initiated by 'powershell.exe'. These patterns are frequently used to download and execute malicious payloads directly in memory, bypassing traditional disk-based scanning.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
106
This rule detects multiple outbound network connections to a specific set of known malicious C2 IP addresses on specific ports within a one-hour window. This behavior is indicative of a multi-payload delivery pattern associated with malware families such as Remcos, Agent Tesla, and RedLine.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
306