Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

Detects logons using built-in default accounts (Administrator, Guest) or domain-admin accounts occurring outside an established baseline (new host, unusual time, first-ever interactive logon), repeated at least twice and excluding newly-provisioned accounts within their grace period or approved break-glass accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3027
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5012
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects pass-the-hash and pass-the-ticket lateral authentication using NTLM/Kerberos-ticket reuse across multiple hosts without a corresponding interactive logon, excluding known NTLM-by-design service accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108