avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,484 copies160 likes51,969 views

8,664 detections

This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule identifies outbound network connections from devices to public IP addresses using ports commonly associated with the Tor network (9001, 9030, 9050, 9051). These ports are frequently used for Tor relay, bridge, and control functionality, and connections to them from managed endpoints may indicate unauthorized use of the Tor network for anonymity or malicious command-and-control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection over SMB (port 445) to an external, non-private IP address. This behavior is highly suspicious as Microsoft Outlook should typically not be performing direct SMB connections to external systems, and this is often indicative of an adversary attempting to leverage malicious documents or templates to perform credential harvesting via NTLM relay or SMB authentication captures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
404
Detects Microsoft Office applications spawning suspicious child processes (e.g., cmd.exe, rundll32.exe) or initiating network connections to WebDAV paths, which may indicate exploitation of ActiveX OLE auto-execution vulnerabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects activities associated with the NotDoor malware used by APT28 for email-based exfiltration. It specifically monitors for the creation of staging files in temporary directories, the use of Outlook.exe to establish external SMTP connections on common mail ports, and the transmission of emails to known adversary-controlled addresses.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects suspicious OpenProcess calls initiated by common user applications (explorer.exe, winword.exe, outlook.exe) targeting svchost.exe, followed by an outbound network connection from the target svchost.exe to the file sharing service filen.io within a 30-minute window. This behavior is indicative of process injection used to facilitate network communication or data exfiltration under the guise of a system process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network connections over port 3389 (RDP) initiated by processes other than standard Remote Desktop clients (mstsc.exe). This rule specifically looks for suspicious indicators such as execution from non-standard or temporary file paths, or the use of common living-off-the-land binaries (like powershell.exe, cmd.exe, rundll32.exe) that might be acting as a proxy for remote access or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects attempts to clear Windows Event Logs using either the native 'wevtutil.exe' utility or the 'Clear-EventLog' PowerShell cmdlet. Clearing event logs is a common technique used by adversaries to hide traces of their activities on a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects potential credential harvesting attempts by monitoring for the usage of Windows credential management tools (cmdkey.exe and vaultcmd.exe) and the loading of sensitive DLLs (vaultcli.dll, dpapi.dll) by non-Microsoft signed processes, which is commonly used to access stored credentials in the Windows Vault or by DPAPI-protected stores.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects the execution of multimedia capturing utilities like ffmpeg or OBS Studio when spawned by common scripting or administrative processes. This pattern often indicates unauthorized screen, audio, or video recording potentially used in data exfiltration or reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004