
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,137 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of regsvr32.exe with command-line arguments indicative of 'Squiblydoo' style attacks, which use the signed Windows binary to proxy the execution of remote scripts or local COM scriptlets (.sct files). The rule specifically flags the use of /i with HTTP(S) URLs, loading scrobj.dll, or specific combinations of /s /u /i flags to bypass application control mechanisms.
Detects network connection attempts to the cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) initiated by processes that are not known cloud management agents or system utilities, which may indicate unauthorized credential or IAM role token theft.
Detects suspicious execution of command-line tools like curl, wget, or PowerShell to query OAuth/token-related endpoints (e.g., /token, oauth, access_token). The rule filters out expected parent processes (e.g., shells, IDEs, common build tools) to identify potentially malicious attempts to steal application access tokens.
Detects DNS resolutions for major AI/LLM provider domains (e.g., OpenAI, Anthropic, Google AI) originating from processes that are not common, known browsers or development tools. This behavior is indicative of potentially malicious applications or malware using AI APIs for automated tasks, such as content exfiltration or sophisticated C2 communication.
Detects potential container breakout attempts on Windows systems by monitoring for the launch of privileged containers with sensitive host paths mounted, the execution of host-level processes directly spawned by container runtime binaries (docker.exe, containerd.exe), and direct access to sensitive host filesystems (e.g., C:\windows, C:\etc, C:\programdata) by container runtimes.
Detects execution of Azure Automation runbook jobs by managed identities that have recently been assigned high-privilege roles (Owner, Contributor, or User Access Administrator). This behavior is indicative of potential privilege escalation or abuse of existing high-privilege identities to execute unauthorized automation tasks.
Detects techniques used to bypass PowerShell Constrained Language Mode (CLM) including version downgrades, execution from trusted binary proxy hosts (such as InstallUtil, MSBuild, or Regasm), and manipulation of the __PSLockDownPolicy environment variable.
Detects MFA fatigue attacks where a user receives more than 10 MFA push denials within a 10-minute window, followed immediately by a successful authentication from a different IP address. This behavior is indicative of an adversary bombarding a user with push notifications until they are approved, followed by account takeover.
Detects high-impact configuration changes to Azure management groups or subscriptions (e.g., write/delete operations) that are performed by non-privileged accounts or outside of defined business change windows. This activity can indicate unauthorized privilege escalation, resource manipulation, or reconnaissance by an adversary.
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
