avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,138 views

8,664 detections

Detects updates or deletions of Azure Active Directory (Entra ID) Conditional Access policies that occur outside of typical business hours (Monday-Friday 08:00-18:00 UTC). Such modifications can be an indicator of an adversary attempting to circumvent security controls or maintain persistent, unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic on port 443 originating from non-browser processes destined for known DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9). This behavior can indicate an attempt to bypass standard network DNS filtering or to establish Command and Control (C2) communication channels using the DoH protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential email spoofing attempts by identifying mismatches between P1 (envelope) and P2 (header) sender addresses, identifying discrepancies between sender and reply-to domains, and flagging emails where the display name impersonates common executive or IT support roles.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
This rule detects potentially malicious activities related to Active Directory Certificate Services (AD CS). It identifies suspicious certificate export commands (certutil, PowerShell), non-privileged processes writing to system certificate stores, and dangerous AD CS enrollment patterns such as Subject Alternative Name (SAN) modifications, often associated with ESC1 privilege escalation techniques.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects potentially malicious modification or configuration changes to Azure Function Apps. It monitors for operations such as creation, updates, and configuration changes that contain suspicious indicators like hardcoded credentials (TOKEN, SECRET, PASS), potential reverse shell patterns, or large Base64 encoded payloads. The rule specifically excludes known CI/CD pipeline callers to minimize false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
604
Detects Active Directory Certificate Services (ADCS) certificate enrollment requests where the requester attempts to enroll a certificate with a Subject Alternative Name (SAN) identifying a different principal than the requester's own account. This pattern is indicative of the ESC1 ADCS misconfiguration abuse, which can lead to privilege escalation by impersonating other domain entities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects anomalous activities targeting SaaS CRM applications (Salesforce, Microsoft Dynamics 365, HubSpot), including high-volume bulk exports, off-hours access, mass API queries for sensitive objects, and suspicious OAuth token grants.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004