
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
Detects suspicious usage of remote execution tools like PsExec, WMIC, and PowerShell, which are commonly used for lateral movement by adversaries. The rule identifies instances where these tools are executed multiple times within a short period (more than 2 times in 5 minutes) from non-system accounts and outside of standard system directories, indicating potential malicious activity.
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
This rule detects successful outbound SSH (port 22) connections originating from a private IP address on a device to a public IP address. This could indicate unauthorized remote access, data exfiltration, or command and control activity.
This rule detects changes to a user account's User Account Control (UAC) settings, specifically when the 'NewUacValue' is set to '0x2080'. This value corresponds to the 'ACCOUNTDISABLE' flag, indicating that a user account has been disabled. Monitoring such changes can help identify potential malicious activity where an attacker might disable legitimate user accounts to disrupt operations or hinder incident response.
Detects the use of dsquery.exe to enumerate users in Active Directory. This command-line utility is often used by attackers for reconnaissance to gather information about domain users.
Detects suspicious PowerShell execution initiated by explorer.exe, specifically when the command line includes a .lnk file, execution policy bypass, and contains keywords or paths commonly associated with malicious activity (e.g., tor, ssh, github.io, dropbox.com, or suspicious temporary/public directories). This pattern is often observed in initial access or execution phases of attacks.
This rule detects multiple failed SSL login attempts from a single source IP to a destination IP within a 24-hour period. A threshold of 10 failed attempts is used to identify potential brute-force attacks or credential stuffing against SSL-enabled services.
KQL Query from file: Detects when a user uploads, shares, or sends executable files (e.g., .exe, .dll, .scr) through Office 365 services (OneDrive / SharePoint / Exchange). This Query is used to find the SHA values of file.
This rule identifies if a given IP address falls within the known IP ranges used by Apple's iCloud Private Relay service. It retrieves a list of IPv4 and IPv6 ranges from a public GitHub repository and then checks if a specified IP address is contained within any of these ranges. This can be used to identify traffic potentially obfuscated by iCloud Private Relay.
