avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous credential access behavior in Azure Key Vault where a single identity performs more than 20 secret, key, or certificate read/list operations within a 5-minute window. This behavior is indicative of potential unauthorized reconnaissance or exfiltration of secrets stored in Key Vaults, excluding known automation service principals.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
304
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
macOS malware used by JINX-0164 against cryptocurrency developers
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially compromised accounts by correlating successful device code authentication events that exhibit anomalous characteristics (such as first-time usage, high/medium risk scores, or non-compliant/unmanaged device status) with highly sensitive Azure AD/Graph API administrative operations occurring within 30 minutes of the sign-in.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects Entra ID guest (B2B) users performing a sign-in from a previously unseen IP address or country (observed over the last 30 days), followed within a 4-hour window by sensitive file operations in SharePoint, OneDrive, or Teams (e.g., file downloads, exports, or sensitivity label changes). This pattern is indicative of potential account takeover or unauthorized access to sensitive corporate data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the configuration and usage of personal Microsoft OneDrive accounts on corporate endpoints. This is achieved by monitoring for OneDrive process execution with personal account command-line arguments, OneDrive setup utilities configured with personal tenant identifiers, and file system activity within directory paths associated with personal OneDrive synchronization.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects the addition of new certificates or client secrets to Azure App Registrations or Service Principals by a user who is not recorded as an owner of that application in the last 90 days. This behavior is a common persistence and privilege escalation technique used by attackers to maintain access to cloud environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004