Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
4 detections
Filters
Last updated
All Time
Detection languages
4
Contributors
4
Categories
4
2
Platforms
4
Products / Services
10,371
9,516
6,509
4,371
3,687
Detects logons using built-in default accounts (Administrator, Guest) or domain-admin accounts occurring outside an established baseline (new host, unusual time, first-ever interactive logon), repeated at least twice and excluding newly-provisioned accounts within their grace period or approved break-glass accounts.
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
Detects pass-the-hash and pass-the-ticket lateral authentication using NTLM/Kerberos-ticket reuse across multiple hosts without a corresponding interactive logon, excluding known NTLM-by-design service accounts.
