avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,137 views

8,664 detections

Detects the execution of regsvr32.exe with command-line arguments indicative of 'Squiblydoo' style attacks, which use the signed Windows binary to proxy the execution of remote scripts or local COM scriptlets (.sct files). The rule specifically flags the use of /i with HTTP(S) URLs, loading scrobj.dll, or specific combinations of /s /u /i flags to bypass application control mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects network connection attempts to the cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) initiated by processes that are not known cloud management agents or system utilities, which may indicate unauthorized credential or IAM role token theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects suspicious execution of command-line tools like curl, wget, or PowerShell to query OAuth/token-related endpoints (e.g., /token, oauth, access_token). The rule filters out expected parent processes (e.g., shells, IDEs, common build tools) to identify potentially malicious attempts to steal application access tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects DNS resolutions for major AI/LLM provider domains (e.g., OpenAI, Anthropic, Google AI) originating from processes that are not common, known browsers or development tools. This behavior is indicative of potentially malicious applications or malware using AI APIs for automated tasks, such as content exfiltration or sophisticated C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential container breakout attempts on Windows systems by monitoring for the launch of privileged containers with sensitive host paths mounted, the execution of host-level processes directly spawned by container runtime binaries (docker.exe, containerd.exe), and direct access to sensitive host filesystems (e.g., C:\windows, C:\etc, C:\programdata) by container runtimes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects execution of Azure Automation runbook jobs by managed identities that have recently been assigned high-privilege roles (Owner, Contributor, or User Access Administrator). This behavior is indicative of potential privilege escalation or abuse of existing high-privilege identities to execute unauthorized automation tasks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects techniques used to bypass PowerShell Constrained Language Mode (CLM) including version downgrades, execution from trusted binary proxy hosts (such as InstallUtil, MSBuild, or Regasm), and manipulation of the __PSLockDownPolicy environment variable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects MFA fatigue attacks where a user receives more than 10 MFA push denials within a 10-minute window, followed immediately by a successful authentication from a different IP address. This behavior is indicative of an adversary bombarding a user with push notifications until they are approved, followed by account takeover.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects high-impact configuration changes to Azure management groups or subscriptions (e.g., write/delete operations) that are performed by non-privileged accounts or outside of defined business change windows. This activity can indicate unauthorized privilege escalation, resource manipulation, or reconnaissance by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
503
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103