avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

Detects the creation or modification of inbox rules in Exchange/Office 365 that both apply an email suppression action (move to folder, delete, or mark as read) and filter for security-themed keywords (e.g., 'phish', 'MFA', 'SOC'). This behavior is commonly used by adversaries to hide security alerts, multi-factor authentication (MFA) prompts, or phishing incident notifications from a compromised user's mailbox.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
Detects the clearing of Windows Security and System event logs, or Defender XDR audit logs, indicating potential adversary activity to remove traces of their actions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potentially malicious activity within Azure Automation by monitoring for the creation or modification of runbooks and jobs, combined with the presence of suspicious command-line or script patterns in job stream output, such as credential harvesting (e.g., Get-AutomationPSCredential) or execution of web-based payloads (e.g., IEX, Invoke-WebRequest).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of certutil.exe to download files from remote URLs using the -urlcache flag or decode files using the -decode flag. This behavior is indicative of a living-off-the-land technique used by adversaries to fetch or prepare malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of living-off-the-land tools like plink.exe, netsh.exe, and ssh.exe to create tunnels that forward RDP traffic (port 3389). This behavior is often indicative of an adversary attempting to bypass network controls or hide RDP sessions by tunneling them through other protocols or non-standard port configurations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential Active Directory Certificate Services (AD CS) abuse (specifically ESC1 and ESC8 patterns) by monitoring command-line executions of 'certreq.exe' and 'certutil.exe' that utilize suspicious flags or originate from non-standard administrative processes. This activity is indicative of an attacker attempting to enroll certificates for unauthorized entities or escalate privileges within a Windows domain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where a guest user is invited to the organization using an email address from potentially malicious TLDs (e.g., .ru, .cn, .ir, .kp) or a domain structure that is represented as an IP address. These patterns are often associated with phishing, reconnaissance, or adversary attempts to gain a foothold in an environment by inviting external identities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
201
Detects potential Pass-the-Hash lateral movement where a single account uses NTLM authentication as a local administrator to access three or more distinct devices within a 30-minute window, a pattern often indicative of automated credential propagation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the creation or modification of inbox rules in Exchange/Office 365 that both apply an email suppression action (move to folder, delete, or mark as read) and filter for security-themed keywords (e.g., 'phish', 'MFA', 'SOC'). This behavior is commonly used by adversaries to hide security alerts, multi-factor authentication (MFA) prompts, or phishing incident notifications from a compromised user's mailbox.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects any modification (add, update, or delete) to Entra ID cross-tenant access settings. Adversaries may manipulate these trust configurations to weaken inbound security restrictions, establish unauthorized access between tenants, or facilitate cross-tenant impersonation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Page 555 of 867