avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,530 copies160 likes52,244 views

8,664 detections

Detects suspicious activities within a Veeam backup environment, including unauthorized process spawning by Veeam services, LSASS memory access, destruction of backup catalogs or restore points via PowerShell, and unauthorized access to Veeam database files by non-Veeam processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects suspicious activity related to high-volume Server Message Block (SMB) share enumeration and the execution of a specific Python script named 'backup_dfs.py'. It combines three detection logics: identifying processes executing 'backup_dfs.py', detecting an unusual number of SMB network connections to common administrative shares (SYSVOL, NETLOGON, DFS), and flagging high-volume SMB-related identity directory events targeting SYSVOL or NETLOGON. This behavior could indicate an adversary performing discovery of network shares, collecting data, or preparing for data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
Detects successful non-interactive token acquisitions using specific Microsoft first-party application IDs known to bypass Entra Conditional Access Policies through Nested App Authentication (NAA/BroCI). The detection specifically targets sign-ins to the Microsoft Graph resource.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
Detects successful sign-ins to specific Azure AD applications known to bypass Conditional Access policies, where Conditional Access was not applied. This could indicate an attempt to circumvent security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
105
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential exploitation activity related to CVE-2026-45657 involving the Windows Kernel tcpip.sys driver. It monitors for a combination of system crashes (Kernel-Power 41 or EventLog 6008) correlated with Windows Error Reporting (WER) events referencing 'tcpip.sys', or significant spikes in external authentication attempts occurring shortly before a system crash. The rule aims to identify potential remote code execution attempts manifesting as kernel instability.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects processes that load sensitive Windows multimedia and graphics modules (mmdevapi.dll, avrt.dll, magnification.dll, dxgi.dll) which are commonly utilized for audio recording and screen capturing. The rule filters out known legitimate applications (e.g., Teams, Zoom, Web browsers) and trusted software publishers. It further identifies potential suspicious activity by flagging processes originating from common staging paths like 'Temp', 'Downloads', or 'ProgramData' and instances where the process image is unsigned.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects processes attempting to query the Cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) that are not recognized as legitimate cloud agent software (such as AWS, Azure, or Google cloud agents). This behavior is often indicative of SSRF or unauthorized discovery attempts by an adversary on a compromised cloud instance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects unauthorized access, creation, or modification of browser-specific sensitive credential files (such as 'Login Data' or 'cookies.sqlite') by processes that are not recognized web browsers or trusted update services. This behavior is a common indicator of information-stealer malware attempting to harvest session cookies and stored credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
302
This rule detects potential ransomware activity by identifying a combination of three distinct behaviors occurring on a single endpoint within a short window: high-volume file modifications (indicative of file encryption), deletion of system recovery resources (e.g., volume shadow copies, backup catalogs), and high-frequency network activity (indicative of data exfiltration). The rule uses cross-event correlation to reduce false positives by requiring all three signals to be present.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
302
Page 575 of 867