avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

Detects the execution of VS Code Tunnel processes (code-tunnel.exe or code.exe with tunnel arguments) initiated by processes other than standard development-related parent processes (e.g., explorer, terminal, IDEs). This behavior may indicate an adversary attempting to establish persistent unauthorized remote access to a compromised host using the VS Code Tunnel functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects repeated authentication failures (Event ID 4625) with a specific sub-status code 0xC0000072, which indicates that the user account is disabled. This behavior is indicative of a brute-force or credential-stuffing attack against disabled accounts, or potentially misconfigured automated services attempting to authenticate with stale credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects when a user account is added to a security-enabled global, local, or universal group in Active Directory. This behavior is captured by monitoring Security Events 4728 (global group), 4732 (local group), and 4756 (universal group). The rule flags actions performed by user accounts (excluding system accounts) and aggregates them by the source account performing the modification.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects cases where a user privilege is granted (EventCode 4717) and subsequently revoked (EventCode 4718) within a 60-minute window. This behavior often indicates transient privilege abuse, where an attacker grants themselves temporary elevated rights to perform an action and then revokes them to evade detection or minimize their footprint.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects potential Remote Desktop Protocol (RDP) brute force campaigns by aggregating Windows Event ID 4625 (logon failure) with Logon Type 10. The rule triggers when a significant number of failed authentication attempts against a single target account and host are observed within a 1-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects when a user account is added to a security-enabled global, local, or universal group in Active Directory. This behavior is captured by monitoring Security Events 4728 (global group), 4732 (local group), and 4756 (universal group). The rule flags actions performed by user accounts (excluding system accounts) and aggregates them by the source account performing the modification.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the installation of a new Windows service by monitoring Security Event IDs 4697 and 601. It extracts details about the service name, file path, and account used. The rule flags services that have suspicious binary paths, such as those within user-writable directories (Temp, AppData, Downloads) or paths containing common living-off-the-land binaries, which may indicate persistence or the loading of malicious drivers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects rapid creation of multiple user accounts within a one-hour window. This behavior can be indicative of malicious activity, such as an attacker creating persistence accounts or staging multiple accounts for lateral movement or automated attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of known forensic imaging tools (FTK Imager or AD Imager) or commands interacting with the Active Directory database (ntds.dit). This behavior is characteristic of unauthorized attempts to extract credential hashes from the NTDS.dit file for offline cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where AutoHotkey scripts launch Microsoft Edge or Google Chrome in headless mode. This behavior is indicative of automated browser manipulation, often used in credential harvesting, session hijacking, or automated interaction with web-based platforms by malicious entities such as UNC6692.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001