
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Clipboard hijacking malware for cryptocurrency address substitution
Open-source derived remote access trojan with plugin architecture
Detects anomalous credential access behavior in Azure Key Vault where a single identity performs more than 20 secret, key, or certificate read/list operations within a 5-minute window. This behavior is indicative of potential unauthorized reconnaissance or exfiltration of secrets stored in Key Vaults, excluding known automation service principals.
Clipboard hijacking malware for cryptocurrency address substitution
Open-source derived remote access trojan with plugin architecture
macOS malware used by JINX-0164 against cryptocurrency developers
This rule detects potentially compromised accounts by correlating successful device code authentication events that exhibit anomalous characteristics (such as first-time usage, high/medium risk scores, or non-compliant/unmanaged device status) with highly sensitive Azure AD/Graph API administrative operations occurring within 30 minutes of the sign-in.
Detects Entra ID guest (B2B) users performing a sign-in from a previously unseen IP address or country (observed over the last 30 days), followed within a 4-hour window by sensitive file operations in SharePoint, OneDrive, or Teams (e.g., file downloads, exports, or sensitivity label changes). This pattern is indicative of potential account takeover or unauthorized access to sensitive corporate data.
Detects the configuration and usage of personal Microsoft OneDrive accounts on corporate endpoints. This is achieved by monitoring for OneDrive process execution with personal account command-line arguments, OneDrive setup utilities configured with personal tenant identifiers, and file system activity within directory paths associated with personal OneDrive synchronization.
This rule detects the addition of new certificates or client secrets to Azure App Registrations or Service Principals by a user who is not recorded as an owner of that application in the last 90 days. This behavior is a common persistence and privilege escalation technique used by attackers to maintain access to cloud environments.
