avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

This rule detects successful sign-ins using OAuth from residential IP addresses. It joins `SigninLogs` with `IdentityLogonEvents` to correlate successful OAuth authentications with user logon events. The intent is to identify potentially suspicious access, possibly indicating credential abuse or unauthorized access attempts from non-corporate or unexpected locations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
15050
Detects outbound network connections to major Large Language Model (LLM) API endpoints (OpenAI, Google, Anthropic) initiated by processes not explicitly identified as standard web browsers or command-line utilities. This pattern may indicate automated data exfiltration ('prompt stealing' or unauthorized access to corporate data) using custom or malicious tools executing from suspicious directories like temp, appdata, or public folders.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule monitors for administrative VMware operations (cloning, snapshotting, or process manipulation) performed on sensitive infrastructure servers (such as Domain Controllers, PKI, Vault, or ADFS) that occur outside of a designated maintenance window by non-authorized accounts. It leverages tools like vim-cmd, esxcli, or govc to detect potential unauthorized VM manipulation that could lead to data theft, snapshot-based credential extraction, or unauthorized system changes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects suspicious execution of MSBuild.exe originating from non-standard parent processes or loading project/xml files from unconventional directories such as user-writable or temporary locations. This behavior is indicative of an attempt to bypass application whitelisting and execute arbitrary inline C# code via MSBuild's task functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects high-volume failed authentication attempts targeting a specific user account from a source IP address, indicative of 'MFA fatigue' or 'push bombing' attacks. This rule monitors endpoint-visible logon failure events as captured by EDR telemetry to identify potential attempts to circumvent multi-factor authentication by spamming the user with requests.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the creation, reading, or execution of payloads stored within NTFS Alternate Data Streams (ADS). This technique is commonly used by adversaries to hide malicious content within file metadata to evade security tools. The rule monitors process command-line arguments for ADS syntax, identifies usage of utilities like type, Get-Content, wmic, or various LOLBins (e.g., regsvr32, rundll32) interacting with ADS paths, and flags anomalous file creation/modification events that involve ADS, excluding known system-generated streams.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of known AI/LLM command-line interface tools (such as Ollama, OpenAI, or Claude) when spawned by command shells (cmd.exe, powershell.exe) or executed from suspicious locations like user profiles or temporary directories. This pattern is indicative of potential use of LLMs for generating malicious code, analyzing data, or assisting in post-exploitation activities within a compromised environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of scheduled tasks using schtasks.exe, where the command line arguments reference known LOLBins (Living Off the Land Binaries) such as certutil, regsvr32, mshta, wscript, cscript, rundll32, or encoded command execution via cmd.exe. This activity often indicates an attempt to establish persistence or execute malicious code using trusted system binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
402
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by searching for common memory patching techniques, such as modifying AmsiUtils, AmsiScanBuffer, or related reflection-based obfuscation in process command lines.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects instances where PowerShell or PowerShell Core (pwsh.exe) are spawned as child processes of common COM object host processes (e.g., wscript.exe, mshta.exe, rundll32.exe). The detection specifically looks for command-line arguments containing encoded commands or indicators of download cradles (e.g., IEX, Net.WebClient, DownloadString), which are common patterns for fileless execution and malicious script staging.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Page 557 of 867