avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

Detects the creation or modification of services associated with PsExec, a legitimate tool often abused by adversaries for remote execution. The rule looks for specific service names or file paths indicative of PsExec activity, including the default 'PSEXESVC' service name, or file paths containing 'ADMIN$' or 'IPC$' shares, or a randomly named executable in the SystemRoot directory. It filters out activity from designated administrative workstations and common system accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects the successful removal of Azure Resource Management locks. Attackers may attempt to delete these locks to modify, move, or delete protected resources that would otherwise be restricted, often as a precursor to data destruction or infrastructure tampering.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential credential dumping attempts against the Local Security Authority Subsystem Service (LSASS). It monitors two distinct suspicious behaviors: 1) The enablement of 'SeDebugPrivilege' by non-system processes via Windows security event 4703, and 2) Suspicious OpenProcess calls targeting sensitive Windows processes (lsass.exe, csrss.exe, winlogon.exe, services.exe, smss.exe) initiated by non-system accounts with high-level access rights.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors for unauthorized deletion or modification of Microsoft Sentinel alert rules and automation rules. Such actions are indicative of an attacker attempting to impair security monitoring, silence alerts, or disable automated responses to maintain persistence and evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of 'net.exe' or 'net1.exe' with arguments 'view', 'share', or 'use' that appear in rapid succession or are initiated by potentially suspicious parent processes. This behavior is often associated with network enumeration and reconnaissance activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where processes other than legitimate browser components attempt to access, read, or copy the browser 'Login Data' file. This file stores credentials used by Google Chrome and Microsoft Edge, and unauthorized access is a common technique used by credential-stealing malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the successful removal of Azure Resource Management locks. Attackers may attempt to delete these locks to modify, move, or delete protected resources that would otherwise be restricted, often as a precursor to data destruction or infrastructure tampering.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the use of wmic.exe to execute commands or retrieve OS information on remote systems by monitoring for the '/node:' flag in command lines. The rule excludes local host references (localhost, 127.0.0.1) to focus on remote management activity that may indicate lateral movement or remote code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of rundll32.exe to execute code via remote URLs, JavaScript, or specific DLL functions known to be abused for proxy execution. This behavior is commonly associated with fileless malware and living-off-the-land techniques to bypass security controls by utilizing legitimate Windows binaries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects potential credential dumping attempts against the Local Security Authority Subsystem Service (LSASS). It monitors two distinct suspicious behaviors: 1) The enablement of 'SeDebugPrivilege' by non-system processes via Windows security event 4703, and 2) Suspicious OpenProcess calls targeting sensitive Windows processes (lsass.exe, csrss.exe, winlogon.exe, services.exe, smss.exe) initiated by non-system accounts with high-level access rights.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001