
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
Detects the execution of common command-line utilities (net.exe, dsquery.exe, AdFind.exe) used to query Active Directory for user information. This pattern is characteristic of adversary discovery activities targeting domain user accounts and group memberships. The rule filters out processes launched by Microsoft-signed binaries to reduce noise.
The rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or the use of its specific command-line arguments (e.g., sekurlsa::logonpasswords, /ntlm:). It also monitors for suspicious, unauthorized processes attempting to open a handle to the LSASS process to access its memory, a common technique for dumping credentials.
Detects the use of the BITSAdmin utility to transfer files or set notification command lines. BITSAdmin is a legitimate Windows utility often abused by adversaries to download malicious files or achieve persistence/execution via BITS jobs.
This rule detects modifications to Windows Registry keys related to COM object handlers (InprocServer32/LocalServer32) within User registry hives. It specifically identifies when a COM object is registered to point to a file path residing in suspicious, user-writable directories (e.g., Temp, AppData, Downloads) or arbitrary user directories, which is a common indicator of COM hijacking for persistence or privilege escalation.
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
Detects the execution of common command-line utilities (net.exe, dsquery.exe, AdFind.exe) used to query Active Directory for user information. This pattern is characteristic of adversary discovery activities targeting domain user accounts and group memberships. The rule filters out processes launched by Microsoft-signed binaries to reduce noise.
Detects the creation or modification of WMI event subscriptions via EventID 5861 from the Microsoft-Windows-WMI-Activity log. This activity, involving EventFilters, EventConsumers, or FilterToConsumerBindings, is a well-known technique used by adversaries to establish persistence and achieve execution triggered by system events, often resulting in elevated SYSTEM privileges.
