avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

Detects modifications to COM object InProcServer32 registry keys within the user's registry hive (HKEY_USERS). Attackers often hijack COM objects to achieve persistence by pointing them to malicious DLLs or OCX files. This rule specifically filters out common legitimate paths (Windows directories, Program Files) and known installers to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105
Detects successful OAuth application consent events where the requested permissions include sensitive scopes such as Mail, Files, or User profile access. This is a common indicator of OAuth application-based phishing or persistence attempts, often referred to as 'Illicit Consent Grant' attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects various methods used to extract credentials protected by the Windows Data Protection API (DPAPI). It covers multiple vectors, including Mimikatz DPAPI module usage, unauthorized loading of the dpapi.dll library, suspicious access to browser or WiFi credential stores, and cross-process memory access to the LSASS process to extract DPAPI master keys.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects indicators of Adversary-in-the-Middle (AiTM) phishing infrastructure, specifically targeting Evilginx2 and similar proxy frameworks. It identifies unauthorized execution of Evilginx2 binaries, the presence of specific session and configuration files (.evilginx/, phishlets, session databases), unauthorized modifications to Nginx configurations, and the dropping of suspicious HTML lure files into web document roots by scripting interpreters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of native Windows utilities (vssadmin, wbadmin, bcdedit, diskshadow) configured to delete volume shadow copies, remove backup catalogs, or disable automatic recovery features. This activity is a common indicator of ransomware preparation to prevent data recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications to the Windows Defender exclusion list via registry keys. Adding exclusions can be used by attackers to hide malicious files, processes, or directories from antivirus scanning.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects when sensitive administrative roles are assigned directly to users in Microsoft Entra ID (formerly Azure AD) without utilizing the Privileged Identity Management (PIM) service. Direct assignment of these roles bypasses the security controls and JIT (Just-In-Time) access workflows enforced by PIM, potentially indicating unauthorized privilege escalation or a misconfiguration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects unauthorized or suspicious modifications to Microsoft Sentinel alert rules. It specifically monitors for the deletion of alert rules or the disabling of existing rules via the Azure activity logs. Such actions may indicate an attempt by an adversary to impair security monitoring and defensive capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101