
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,138 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects updates or deletions of Azure Active Directory (Entra ID) Conditional Access policies that occur outside of typical business hours (Monday-Friday 08:00-18:00 UTC). Such modifications can be an indicator of an adversary attempting to circumvent security controls or maintain persistent, unauthorized access.
Detects network traffic on port 443 originating from non-browser processes destined for known DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9). This behavior can indicate an attempt to bypass standard network DNS filtering or to establish Command and Control (C2) communication channels using the DoH protocol.
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
This rule detects potential email spoofing attempts by identifying mismatches between P1 (envelope) and P2 (header) sender addresses, identifying discrepancies between sender and reply-to domains, and flagging emails where the display name impersonates common executive or IT support roles.
This rule detects potentially malicious activities related to Active Directory Certificate Services (AD CS). It identifies suspicious certificate export commands (certutil, PowerShell), non-privileged processes writing to system certificate stores, and dangerous AD CS enrollment patterns such as Subject Alternative Name (SAN) modifications, often associated with ESC1 privilege escalation techniques.
This rule detects potentially malicious modification or configuration changes to Azure Function Apps. It monitors for operations such as creation, updates, and configuration changes that contain suspicious indicators like hardcoded credentials (TOKEN, SECRET, PASS), potential reverse shell patterns, or large Base64 encoded payloads. The rule specifically excludes known CI/CD pipeline callers to minimize false positives.
Detects Active Directory Certificate Services (ADCS) certificate enrollment requests where the requester attempts to enroll a certificate with a Subject Alternative Name (SAN) identifying a different principal than the requester's own account. This pattern is indicative of the ESC1 ADCS misconfiguration abuse, which can lead to privilege escalation by impersonating other domain entities.
Detects anomalous activities targeting SaaS CRM applications (Salesforce, Microsoft Dynamics 365, HubSpot), including high-volume bulk exports, off-hours access, mass API queries for sensitive objects, and suspicious OAuth token grants.
