avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

This rule detects an unusually high volume of registry access events (Event ID 4656) targeting either the 'HKLM' (HKEY_LOCAL_MACHINE) hive or 'System Registry' within a one-hour window. A count of 10 or more such events by a single user on a specific computer within an hour is considered suspicious. This activity could indicate an adversary attempting to enumerate system configurations, modify system settings for persistence, or gather information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects a high volume of access attempts to the IPC$ administrative share from a single source IP address within a one-hour window. This behavior can be indicative of reconnaissance, lateral movement, or other malicious activities using SMB/Windows Admin Shares.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects a high volume of failed object access attempts (EventID 4674) by a single user on a specific computer within a one-hour window. This could indicate an adversary attempting to discover or access sensitive resources, potentially as part of privilege escalation or data exfiltration efforts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects modifications to the 'AdminCount' attribute in Active Directory, indicated by Event ID 5136. Changes to this attribute can signify privilege escalation attempts or modifications to highly privileged accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects when a user account repeatedly (3 or more times within an hour) requests either 'SeDebugPrivilege' or 'SeImpersonatePrivilege' (Event ID 4672). This behavior can be indicative of an attacker attempting to escalate privileges or manipulate access tokens, often seen in techniques like token impersonation or debugging processes for malicious purposes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects an unusually high volume (10 or more within an hour) of file creations with extensions commonly associated with backup files (.backup, .bak, .old). This activity could indicate an adversary attempting to inhibit system recovery by creating numerous backup files, potentially to overwrite legitimate backups or to stage data for exfiltration or destruction.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects execution chains where npm launches Node.js and Node.js subsequently launches Bun. This sequence may indicate malicious package execution, dependency confusion attacks, CI/CD compromise, or supply-chain abuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Identifies device code sign-ins originating from infrastructure previously associated with phishing operations and adversary-controlled relay servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001