avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects Kerberoasting attempts by identifying suspicious Ticket Granting Service (TGS) requests (Event ID 4769) for the 'krbtgt' service or other services where the ticket encryption type is RC4 (0x17) or older/weaker encryption types (0x18), especially when these requests are not preceded by a corresponding Ticket Granting Ticket (TGT) request (Event ID 4768).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects the use of legitimate Windows system utilities (ntdsutil.exe, vssadmin.exe, esentutl.exe) to interact with the Active Directory database file (ntds.dit). This behavior is commonly associated with offline credential harvesting, where an attacker attempts to create a copy of the database to extract hashes offline.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects high-volume authentication failures originating from a single IP address with a large number of unique target accounts within a 30-minute window, indicative of a password spraying or brute force attack against network services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
804
Detects Kerberoasting attempts by identifying suspicious Ticket Granting Service (TGS) requests (Event ID 4769) for the 'krbtgt' service or other services where the ticket encryption type is RC4 (0x17) or older/weaker encryption types (0x18), especially when these requests are not preceded by a corresponding Ticket Granting Ticket (TGT) request (Event ID 4768).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects network connections to phishing pages hosted on the workers.dev domain that are attempting to interact with EvilTokens device code API endpoints. These pages are known to implement developer hotkey prevention (F12 blocked, context menu disabled) to hinder in-browser analysis, indicating malicious intent.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
12015
This rule detects the execution of known remote access tools (such as AnyDesk, TeamViewer, or RustDesk) that are spawned as child processes from common web browsers. It correlates process creation events with subsequent network connections by these tools to public IP addresses over specific ports commonly used by remote access software, within a 30-minute timeframe of the process start.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects the execution of Dropbear SSH binaries (dropbear, dropbearkey, dropbearmulti) on identified OT, ICS, or SCADA assets. The rule flags suspicious configurations such as the use of non-standard ports (2222, 44818), remote port forwarding, or running in the foreground, which may indicate unauthorized remote access or tunneling on sensitive operational technology infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects successful configuration modifications to diagnostic settings or storage services where the destination resource is identified as being outside of the organization's trusted subscriptions or expected storage naming conventions. This activity may indicate an adversary attempting to exfiltrate logs or data to an attacker-controlled storage account.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects a sequence of suspicious activities on macOS: downloading a file from a potentially malicious source using curl, mounting a disk image using hdiutil, and subsequently opening files from the mounted volume. This pattern is commonly associated with the delivery and execution of malicious payloads, such as trojanized software or malware installers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
504