avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,105 views

8,664 detections

Detects Azure Bastion RDP or SSH tunnel sessions initiated by users who have no history of using Bastion in the last 60 days, or by users connecting from a geographic location not observed in their recent sign-in history. This behavior may indicate account compromise and unauthorized lateral movement attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects the execution of RMM (Remote Monitoring and Management) installers (Atera or SimpleHelp) via msiexec.exe or setup.exe when launched from directories commonly used for downloads (Temp/Downloads) and originating from web browsers or Microsoft Office applications. This behavior is indicative of a potential drive-by download or phishing attack aimed at installing unauthorized remote access software.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the presence of specific keywords within PowerShell Script Block logs (EventCode 4104) that are characteristic of Anti-Malware Scan Interface (AMSI) bypass techniques. These include attempts to manipulate the AMSI context, reflectively load assemblies to modify memory, or force scan failures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
501
This rule monitors for file access events (Sysmon Event ID 11) targeting sensitive web browser files, including logins (passwords), cookies, and web data, by processes other than the legitimate browser executables. Such access is a strong indicator of credential theft or session hijacking attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from common public file sharing and code repository sites, which is a known technique for adversaries to stage or download malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects indicators of the DCShadow attack technique by monitoring for the creation of nTDSDSA objects (which define domain controllers) or the addition of suspicious Service Principal Names (SPNs) often used in DCShadow simulations (GC/ or E3514235-4B06) to computer accounts. These indicators suggest an attacker is attempting to register a rogue Domain Controller to manipulate Active Directory data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects processes other than standard web browsers performing network connections that coincide with OAuth token acquisition activities (POST requests containing 'access_token' in the response body). This behavior is indicative of potential token theft or unauthorized programmatic access to OAuth-protected resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of legitimate Windows binaries (Certutil and BITSAdmin) to communicate with external, non-Microsoft IP addresses, which is indicative of potential tool downloading or data exfiltration. The rule explicitly filters out known Microsoft update domains to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential data staging and exfiltration behavior characterized by large volumes of outbound network data combined with high frequency file write operations across multiple file types. It monitors Sysmon Event IDs 3 (Network connection) and 11 (FileCreate) to identify indicators often associated with pre-encryption staging by ransomware or data theft campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects when an executable or process loads a DLL from commonly writable locations like AppData, Temp, or ProgramData, while also correlating this activity with the loading of .NET CLR runtime components (mscoree.dll, clr.dll, etc.) and potential configuration file modifications. This behavior is indicative of .NET-based injection techniques such as AppDomainManager injection or DLL hijacking targeting .NET applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001