avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views

8,664 detections

Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects suspicious usage of remote execution tools like PsExec, WMIC, and PowerShell, which are commonly used for lateral movement by adversaries. The rule identifies instances where these tools are executed multiple times within a short period (more than 2 times in 5 minutes) from non-system accounts and outside of standard system directories, indicating potential malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects successful outbound SSH (port 22) connections originating from a private IP address on a device to a public IP address. This could indicate unauthorized remote access, data exfiltration, or command and control activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
This rule detects changes to a user account's User Account Control (UAC) settings, specifically when the 'NewUacValue' is set to '0x2080'. This value corresponds to the 'ACCOUNTDISABLE' flag, indicating that a user account has been disabled. Monitoring such changes can help identify potential malicious activity where an attacker might disable legitimate user accounts to disrupt operations or hinder incident response.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the use of dsquery.exe to enumerate users in Active Directory. This command-line utility is often used by attackers for reconnaissance to gather information about domain users.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects suspicious PowerShell execution initiated by explorer.exe, specifically when the command line includes a .lnk file, execution policy bypass, and contains keywords or paths commonly associated with malicious activity (e.g., tor, ssh, github.io, dropbox.com, or suspicious temporary/public directories). This pattern is often observed in initial access or execution phases of attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects multiple failed SSL login attempts from a single source IP to a destination IP within a 24-hour period. A threshold of 10 failed attempts is used to identify potential brute-force attacks or credential stuffing against SSL-enabled services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
KQL Query from file: Detects when a user uploads, shares, or sends executable files (e.g., .exe, .dll, .scr) through Office 365 services (OneDrive / SharePoint / Exchange). This Query is used to find the SHA values of file.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
This rule identifies if a given IP address falls within the known IP ranges used by Apple's iCloud Private Relay service. It retrieves a list of IPv4 and IPv6 ranges from a public GitHub repository and then checks if a specified IP address is contained within any of these ranges. This can be used to identify traffic potentially obfuscated by iCloud Private Relay.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101