avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views

8,664 detections

This rule detects an unusually high number of web search queries (identified by 'search' or 'query' in the URI) originating from a single IP address within a one-hour window. A threshold of 100 or more queries triggers the alert. This behavior could indicate automated activity such as web scraping, reconnaissance, or a denial-of-service attempt against the search functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects repeated execution of 'maven' or 'gradle' commands on a system within a one-hour window. A high count (5 or more) of these commands from the same account on the same computer within an hour could indicate unusual development activity, automated build processes, or potentially malicious activity related to software supply chain compromise or development environment abuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of files ending with '.sig', '.asc', or '.cer'. These extensions are commonly associated with digital signatures, PGP/GPG keys, and certificates, which could indicate activities like code signing, certificate generation/import, or PGP/GPG key manipulation by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects processes making a high volume of network connections (10 or more within an hour) to URLs containing 'release' or 'download'. This behavior can be indicative of malware downloading additional components, updates, or exfiltrating data, but could also be legitimate software updates or large file transfers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects repeated execution of commands containing both 'version' and 'control' keywords within the command line. It specifically looks for at least 5 such executions within a one-hour window on the same computer by the same account. This pattern could indicate an adversary attempting to enumerate system or software versions, or interact with version control systems, potentially as part of reconnaissance or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects when a single process account initiates the deletion of 10 or more executable (.exe), dynamic link library (.dll), or system (.sys) files within a 5-minute window on a device. This behavior can be indicative of malicious activity such as malware cleanup, anti-forensics, or an attempt to disrupt system functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule monitors successful operations related to Azure Traffic Manager within Azure Activity logs. It summarizes the count of such operations by the caller and time, ordered by the most recent activity. This can be used to track administrative actions or changes made to Traffic Manager configurations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects an unusual number of successful encryption-related operations performed by a single caller within a one-hour window in Azure Activity logs. This could indicate legitimate bulk administrative tasks or potentially malicious activity such as data encryption for impact (e.g., ransomware) or preparation for exfiltration by an attacker.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects a spike in modifications or creations of Azure Diagnostic Settings within a one-hour window. A high volume of 'Diagnostic Setting' operations by a single caller could indicate an attempt to alter logging configurations, potentially to impair defenses or hide malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the execution of processes where the command line contains keywords commonly associated with privilege escalation or gaining administrative privileges, such as 'getadmin' or 'privesc'. It monitors Windows Security Event ID 4688, which logs process creation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001