avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where a user or service principal is assigned to high-privilege roles (e.g., Global Administrator, Owner) without utilizing the Microsoft Entra Privileged Identity Management (PIM) service. This is indicated by the absence of 'PIM' in the LoggedByService field for a successful 'Add member to role' operation, which could signify an attempt to bypass established access controls and gain unauthorized elevated persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially malicious modification or configuration changes to Azure Function Apps. It monitors for operations such as creation, updates, and configuration changes that contain suspicious indicators like hardcoded credentials (TOKEN, SECRET, PASS), potential reverse shell patterns, or large Base64 encoded payloads. The rule specifically excludes known CI/CD pipeline callers to minimize false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network traffic on port 443 originating from non-browser processes destined for known DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9). This behavior can indicate an attempt to bypass standard network DNS filtering or to establish Command and Control (C2) communication channels using the DoH protocol.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects instances where processes other than legitimate browser-related binaries access sensitive SQLite database files (Login Data and Cookies) associated with Google Chrome or Microsoft Edge. This activity is a common indicator of credential theft by malicious tools or scripts attempting to extract stored passwords or session cookies.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where a non-SYSTEM parent process spawns a child process running as SYSTEM, characteristic of 'Potato' family exploits (e.g., JuicyPotato, PrintSpoofer) leveraging SeImpersonatePrivilege to elevate privileges. The rule specifically filters for known legitimate SYSTEM process spawners while highlighting suspicious parent-child process relationships.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001