avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where a user or service principal is assigned to high-privilege roles (e.g., Global Administrator, Owner) without utilizing the Microsoft Entra Privileged Identity Management (PIM) service. This is indicated by the absence of 'PIM' in the LoggedByService field for a successful 'Add member to role' operation, which could signify an attempt to bypass established access controls and gain unauthorized elevated persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential clipboard data theft by monitoring Windows Sysmon Event ID 10 for process access events involving clipboard-related APIs (OpenClipboard, GetClipboardData) by untrusted processes, and PowerShell Script Block Logging (Event ID 4104) for the use of Get-Clipboard cmdlets. This identifies attempts by non-standard or unauthorized processes to access sensitive information copied by a user.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects instances where known endpoint security product binaries (EDR/AV) load DLL files from directories outside of their trusted, standard installation paths. This behavior is a common indicator of DLL sideloading, where an attacker attempts to masquerade malicious code as a component of a trusted security process to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects when the WMI provider host process (wmiprvse.exe) spawns common scripting interpreters or command-line shells such as cmd.exe, powershell.exe, or wscript.exe. This behavior is a common indicator of remote command execution via WMI, often used by adversaries for lateral movement, remote code execution, or persistence within a Windows environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of known living-off-the-land binaries (LOLBins) such as mshta.exe, certutil.exe, bitsadmin.exe, wscript.exe, or cscript.exe directly by explorer.exe. This pattern is indicative of a user-initiated execution, potentially triggered by social engineering lures like the 'ClickFix' technique, where a user is tricked into pasting and running malicious commands in the Windows Run dialog or a command prompt context.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where a legitimately signed executable located in protected system directories (System32, SysWOW64, Program Files) loads a DLL module from common user-writable directories (Temp, AppData, Public, ProgramData). This behavior is characteristic of DLL sideloading, where an adversary leverages a trusted binary to execute malicious code contained in a side-loaded DLL.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential BaoLoader drive-by compromise attempts by monitoring two stages: first, the creation of executable files in temporary or application data directories by browser processes; and second, the execution of command-line shells by processes running from those same directories where the browser acted as the grandparent.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule monitors for two distinct suspicious activities: 1) Inbound emails where the sender display name matches a list of executive titles, commonly indicative of Business Email Compromise (BEC) or executive impersonation attacks; 2) The creation of cloud service accounts with names mimicking administrative or IT support roles, which may indicate an adversary establishing persistent, privileged access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
014
This rule monitors for two types of anomalous network behavior: first, it identifies connections to known domains from IP addresses not previously associated with those domains over a seven-day lookback period. Second, it identifies HTTP proxy responses (from Zscaler or Squid) where the content-length significantly deviates from the historical baseline for specific URLs. These patterns are potential indicators of C2 channel shifts or data exfiltration via web protocols.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004