avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,230 views

8,664 detections

Detects the use of the Windows certutil.exe utility for potentially suspicious file operations, including downloading files from remote URLs via 'urlcache' or 'split', or encoding/decoding files. This is a common Living-off-the-Land (LotL) technique used by attackers to stage malicious payloads or deobfuscate malicious content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized or suspicious use of virtualization management tools (e.g., esxcli, vim-cmd, PowerShell cmdlets for vSphere/Hyper-V) to perform disruptive actions such as powering off VMs, removing snapshots, or modifying firewall configurations. The rule excludes activity originating from standard management processes and trusted VMware/Microsoft signed processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of common Windows system administration tools (cmd, powershell, net, sc, taskkill, wmic) to stop, delete, or terminate known backup software agents. This behavior is highly characteristic of ransomware or destructive attacks attempting to inhibit system recovery by destroying backup infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of a new local account using the 'net' utility, followed immediately by that account being added to the local administrators group on the same endpoint. This behavior is a common indicator of persistence or privilege escalation attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where common Windows processes (svchost.exe, explorer.exe, or notepad.exe) spawn suspicious child processes (such as cmd.exe, powershell.exe, or wscript.exe). The rule identifies potential process hollowing or living-off-the-land techniques by correlating parent-child relationships with suspicious command-line parameters (encoding, hidden execution, or in-memory execution) or anomalous file paths (running from user-writable directories).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects MFA fatigue attacks where a user receives more than 10 MFA push denials within a 10-minute window, followed immediately by a successful authentication from a different IP address. This behavior is indicative of an adversary bombarding a user with push notifications until they are approved, followed by account takeover.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects when a non-administrative user grants an application high-privilege OAuth scopes (such as mail reading, file access, or directory management) within an Azure/Microsoft 365 environment. Such consent grants can be used by attackers to maintain persistence and bypass MFA by gaining delegated access to sensitive resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects potential container breakout attempts on Windows systems by monitoring for the launch of privileged containers with sensitive host paths mounted, the execution of host-level processes directly spawned by container runtime binaries (docker.exe, containerd.exe), and direct access to sensitive host filesystems (e.g., C:\windows, C:\etc, C:\programdata) by container runtimes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects successful sign-ins using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, ROPC) for user accounts that are in scope of a Conditional Access policy requiring multi-factor authentication (MFA). Legacy protocols do not support modern authentication flows, effectively bypassing configured MFA requirements and increasing the risk of credential-based attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
Page 568 of 867