
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation or modification of inbox rules in Exchange/Office 365 that both apply an email suppression action (move to folder, delete, or mark as read) and filter for security-themed keywords (e.g., 'phish', 'MFA', 'SOC'). This behavior is commonly used by adversaries to hide security alerts, multi-factor authentication (MFA) prompts, or phishing incident notifications from a compromised user's mailbox.
Detects the clearing of Windows Security and System event logs, or Defender XDR audit logs, indicating potential adversary activity to remove traces of their actions.
This rule detects potentially malicious activity within Azure Automation by monitoring for the creation or modification of runbooks and jobs, combined with the presence of suspicious command-line or script patterns in job stream output, such as credential harvesting (e.g., Get-AutomationPSCredential) or execution of web-based payloads (e.g., IEX, Invoke-WebRequest).
Detects the use of certutil.exe to download files from remote URLs using the -urlcache flag or decode files using the -decode flag. This behavior is indicative of a living-off-the-land technique used by adversaries to fetch or prepare malicious payloads.
Detects the use of living-off-the-land tools like plink.exe, netsh.exe, and ssh.exe to create tunnels that forward RDP traffic (port 3389). This behavior is often indicative of an adversary attempting to bypass network controls or hide RDP sessions by tunneling them through other protocols or non-standard port configurations.
This rule detects potential Active Directory Certificate Services (AD CS) abuse (specifically ESC1 and ESC8 patterns) by monitoring command-line executions of 'certreq.exe' and 'certutil.exe' that utilize suspicious flags or originate from non-standard administrative processes. This activity is indicative of an attacker attempting to enroll certificates for unauthorized entities or escalate privileges within a Windows domain.
Detects instances where a guest user is invited to the organization using an email address from potentially malicious TLDs (e.g., .ru, .cn, .ir, .kp) or a domain structure that is represented as an IP address. These patterns are often associated with phishing, reconnaissance, or adversary attempts to gain a foothold in an environment by inviting external identities.
Detects potential Pass-the-Hash lateral movement where a single account uses NTLM authentication as a local administrator to access three or more distinct devices within a 30-minute window, a pattern often indicative of automated credential propagation.
Detects the creation or modification of inbox rules in Exchange/Office 365 that both apply an email suppression action (move to folder, delete, or mark as read) and filter for security-themed keywords (e.g., 'phish', 'MFA', 'SOC'). This behavior is commonly used by adversaries to hide security alerts, multi-factor authentication (MFA) prompts, or phishing incident notifications from a compromised user's mailbox.
Detects any modification (add, update, or delete) to Entra ID cross-tenant access settings. Adversaries may manipulate these trust configurations to weaken inbound security restrictions, establish unauthorized access between tenants, or facilitate cross-tenant impersonation.
Page 555 of 867
