
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,972 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects Distributed Component Object Model (DCOM) lateral movement activity by monitoring for mmc.exe and dllhost.exe network connections to non-local endpoints or when these processes are spawned by suspicious parent processes typically associated with command execution or malicious behavior.
This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.
This rule detects potential password spraying attacks against Azure Active Directory by identifying sign-in failures from a single source IP address targeting a large number of distinct user accounts within a short time window. It specifically filters for common authentication failure codes and checks for low volume of failures per account, which is characteristic of password spraying behavior.
Detects MFA push bombing attacks by identifying a high volume of MFA challenge failures (errorCode 500121) associated with a single user account within a short time window. This activity often indicates an attempt to overwhelm or fatigue a user into inadvertently approving an MFA request.
Detects anomalous authentication failure patterns against Azure AD Service Principals from a single IP address. The rule identifies potential brute force attacks (high volume of failures) or service principal enumeration (multiple distinct service principals targeted).
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
Detects high-volume LDAP queries or specific expensive LDAP search events (Event ID 1644) on Domain Controllers, which are often indicative of reconnaissance activities such as domain environment mapping or user/group enumeration.
Detects the invitation of an external user to the Azure AD tenant. This activity often results in the creation of a guest account with the '#EXT#' suffix in the User Principal Name (UPN). Monitoring this event is critical for identifying potential unauthorized external access or social engineering attempts aimed at gaining persistence within the environment.
This rule detects network communication (connections, DNS queries, or proxy logs) between endpoints and a list of known malicious domains and IP addresses associated with Mistic and Woodgnat/KongTuke threat families. It identifies these activities across network event logs, DNS queries, and security logs.
Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
