avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of common command-line utilities (net.exe, dsquery.exe, AdFind.exe) used to query Active Directory for user information. This pattern is characteristic of adversary discovery activities targeting domain user accounts and group memberships. The rule filters out processes launched by Microsoft-signed binaries to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
The rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or the use of its specific command-line arguments (e.g., sekurlsa::logonpasswords, /ntlm:). It also monitors for suspicious, unauthorized processes attempting to open a handle to the LSASS process to access its memory, a common technique for dumping credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects the use of the BITSAdmin utility to transfer files or set notification command lines. BITSAdmin is a legitimate Windows utility often abused by adversaries to download malicious files or achieve persistence/execution via BITS jobs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects modifications to Windows Registry keys related to COM object handlers (InprocServer32/LocalServer32) within User registry hives. It specifically identifies when a COM object is registered to point to a file path residing in suspicious, user-writable directories (e.g., Temp, AppData, Downloads) or arbitrary user directories, which is a common indicator of COM hijacking for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
503
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
Detects the execution of common command-line utilities (net.exe, dsquery.exe, AdFind.exe) used to query Active Directory for user information. This pattern is characteristic of adversary discovery activities targeting domain user accounts and group memberships. The rule filters out processes launched by Microsoft-signed binaries to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the creation or modification of WMI event subscriptions via EventID 5861 from the Microsoft-Windows-WMI-Activity log. This activity, involving EventFilters, EventConsumers, or FilterToConsumerBindings, is a well-known technique used by adversaries to establish persistence and achieve execution triggered by system events, often resulting in elevated SYSTEM privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003