
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,484 copies160 likes51,969 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
This rule identifies outbound network connections from devices to public IP addresses using ports commonly associated with the Tor network (9001, 9030, 9050, 9051). These ports are frequently used for Tor relay, bridge, and control functionality, and connections to them from managed endpoints may indicate unauthorized use of the Tor network for anonymity or malicious command-and-control communication.
Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection over SMB (port 445) to an external, non-private IP address. This behavior is highly suspicious as Microsoft Outlook should typically not be performing direct SMB connections to external systems, and this is often indicative of an adversary attempting to leverage malicious documents or templates to perform credential harvesting via NTLM relay or SMB authentication captures.
Detects Microsoft Office applications spawning suspicious child processes (e.g., cmd.exe, rundll32.exe) or initiating network connections to WebDAV paths, which may indicate exploitation of ActiveX OLE auto-execution vulnerabilities.
This rule detects activities associated with the NotDoor malware used by APT28 for email-based exfiltration. It specifically monitors for the creation of staging files in temporary directories, the use of Outlook.exe to establish external SMTP connections on common mail ports, and the transmission of emails to known adversary-controlled addresses.
Detects suspicious OpenProcess calls initiated by common user applications (explorer.exe, winword.exe, outlook.exe) targeting svchost.exe, followed by an outbound network connection from the target svchost.exe to the file sharing service filen.io within a 30-minute window. This behavior is indicative of process injection used to facilitate network communication or data exfiltration under the guise of a system process.
Detects network connections over port 3389 (RDP) initiated by processes other than standard Remote Desktop clients (mstsc.exe). This rule specifically looks for suspicious indicators such as execution from non-standard or temporary file paths, or the use of common living-off-the-land binaries (like powershell.exe, cmd.exe, rundll32.exe) that might be acting as a proxy for remote access or lateral movement.
Detects attempts to clear Windows Event Logs using either the native 'wevtutil.exe' utility or the 'Clear-EventLog' PowerShell cmdlet. Clearing event logs is a common technique used by adversaries to hide traces of their activities on a compromised host.
Detects potential credential harvesting attempts by monitoring for the usage of Windows credential management tools (cmdkey.exe and vaultcmd.exe) and the loading of sensitive DLLs (vaultcli.dll, dpapi.dll) by non-Microsoft signed processes, which is commonly used to access stored credentials in the Windows Vault or by DPAPI-protected stores.
Detects the execution of multimedia capturing utilities like ffmpeg or OBS Studio when spawned by common scripting or administrative processes. This pattern often indicates unauthorized screen, audio, or video recording potentially used in data exfiltration or reconnaissance.
