
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where the Node.js executable (node.exe) spawns common command shells or scripting interpreters such as cmd.exe, powershell.exe, pwsh.exe, or wscript.exe. This behavior is often indicative of Node.js-based applications being used as a staging point for command execution, a common pattern in post-exploitation or the usage of malicious npm packages.
This rule detects when a user or administrator grants consent to an Azure AD or Office 365 application for permissions that provide significant access to mail, files, contacts, or directory data. This activity is a common vector for illicit OAuth consent attacks, where adversaries gain persistent access to sensitive data without requiring direct user credentials.
This rule detects potential internal network reconnaissance activities by monitoring for either mass execution of network discovery commands (such as 'net view' or 'net share') targeting multiple unique hosts within a 5-minute window, or by monitoring for mass outbound network connections to port 445 (SMB) across multiple unique destination hosts within the same timeframe. This behavior is indicative of an attacker attempting to map available network shares or identify reachable systems for lateral movement.
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
Detects unauthorized processes, such as shells, scripting engines, or command-line utilities, that attempt to display or access environment variables containing sensitive cloud credential patterns (e.g., AWS_ACCESS, API_KEY). This behavior often indicates an attempt to steal cloud provider credentials from the host environment.
Detects high-volume file modifications or renames performed by a single process over a short window, affecting many unique file paths. This behavioral pattern is highly indicative of ransomware activity attempting to encrypt data for impact.
Detects anomalous or suspicious behavior from Microsoft 365 Copilot agents, plugins, or sessions. This includes bulk access to files containing sensitive keywords, unauthorized export or sharing of sensitivity-labeled documents, and high-volume Microsoft Graph API read activity targeting sensitive paths in SharePoint or OneDrive.
Detects execution of Azure Automation runbook jobs by managed identities that have recently been assigned high-privilege roles (Owner, Contributor, or User Access Administrator). This behavior is indicative of potential privilege escalation or abuse of existing high-privilege identities to execute unauthorized automation tasks.
This rule detects potentially compromised accounts by correlating successful device code authentication events that exhibit anomalous characteristics (such as first-time usage, high/medium risk scores, or non-compliant/unmanaged device status) with highly sensitive Azure AD/Graph API administrative operations occurring within 30 minutes of the sign-in.
Detects successful sign-ins using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, ROPC) for user accounts that are in scope of a Conditional Access policy requiring multi-factor authentication (MFA). Legacy protocols do not support modern authentication flows, effectively bypassing configured MFA requirements and increasing the risk of credential-based attacks.
