avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

Detects instances where the Node.js executable (node.exe) spawns common command shells or scripting interpreters such as cmd.exe, powershell.exe, pwsh.exe, or wscript.exe. This behavior is often indicative of Node.js-based applications being used as a staging point for command execution, a common pattern in post-exploitation or the usage of malicious npm packages.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects when a user or administrator grants consent to an Azure AD or Office 365 application for permissions that provide significant access to mail, files, contacts, or directory data. This activity is a common vector for illicit OAuth consent attacks, where adversaries gain persistent access to sensitive data without requiring direct user credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential internal network reconnaissance activities by monitoring for either mass execution of network discovery commands (such as 'net view' or 'net share') targeting multiple unique hosts within a 5-minute window, or by monitoring for mass outbound network connections to port 445 (SMB) across multiple unique destination hosts within the same timeframe. This behavior is indicative of an attacker attempting to map available network shares or identify reachable systems for lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
304
Detects unauthorized processes, such as shells, scripting engines, or command-line utilities, that attempt to display or access environment variables containing sensitive cloud credential patterns (e.g., AWS_ACCESS, API_KEY). This behavior often indicates an attempt to steal cloud provider credentials from the host environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects high-volume file modifications or renames performed by a single process over a short window, affecting many unique file paths. This behavioral pattern is highly indicative of ransomware activity attempting to encrypt data for impact.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects anomalous or suspicious behavior from Microsoft 365 Copilot agents, plugins, or sessions. This includes bulk access to files containing sensitive keywords, unauthorized export or sharing of sensitivity-labeled documents, and high-volume Microsoft Graph API read activity targeting sensitive paths in SharePoint or OneDrive.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
404
Detects execution of Azure Automation runbook jobs by managed identities that have recently been assigned high-privilege roles (Owner, Contributor, or User Access Administrator). This behavior is indicative of potential privilege escalation or abuse of existing high-privilege identities to execute unauthorized automation tasks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects potentially compromised accounts by correlating successful device code authentication events that exhibit anomalous characteristics (such as first-time usage, high/medium risk scores, or non-compliant/unmanaged device status) with highly sensitive Azure AD/Graph API administrative operations occurring within 30 minutes of the sign-in.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
Detects successful sign-ins using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, ROPC) for user accounts that are in scope of a Conditional Access policy requiring multi-factor authentication (MFA). Legacy protocols do not support modern authentication flows, effectively bypassing configured MFA requirements and increasing the risk of credential-based attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
404