
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
Detects Kerberoasting attempts by identifying suspicious Ticket Granting Service (TGS) requests (Event ID 4769) for the 'krbtgt' service or other services where the ticket encryption type is RC4 (0x17) or older/weaker encryption types (0x18), especially when these requests are not preceded by a corresponding Ticket Granting Ticket (TGT) request (Event ID 4768).
Detects the use of legitimate Windows system utilities (ntdsutil.exe, vssadmin.exe, esentutl.exe) to interact with the Active Directory database file (ntds.dit). This behavior is commonly associated with offline credential harvesting, where an attacker attempts to create a copy of the database to extract hashes offline.
Detects high-volume authentication failures originating from a single IP address with a large number of unique target accounts within a 30-minute window, indicative of a password spraying or brute force attack against network services.
Detects Kerberoasting attempts by identifying suspicious Ticket Granting Service (TGS) requests (Event ID 4769) for the 'krbtgt' service or other services where the ticket encryption type is RC4 (0x17) or older/weaker encryption types (0x18), especially when these requests are not preceded by a corresponding Ticket Granting Ticket (TGT) request (Event ID 4768).
This rule detects network connections to phishing pages hosted on the workers.dev domain that are attempting to interact with EvilTokens device code API endpoints. These pages are known to implement developer hotkey prevention (F12 blocked, context menu disabled) to hinder in-browser analysis, indicating malicious intent.
This rule detects the execution of known remote access tools (such as AnyDesk, TeamViewer, or RustDesk) that are spawned as child processes from common web browsers. It correlates process creation events with subsequent network connections by these tools to public IP addresses over specific ports commonly used by remote access software, within a 30-minute timeframe of the process start.
Detects the execution of Dropbear SSH binaries (dropbear, dropbearkey, dropbearmulti) on identified OT, ICS, or SCADA assets. The rule flags suspicious configurations such as the use of non-standard ports (2222, 44818), remote port forwarding, or running in the foreground, which may indicate unauthorized remote access or tunneling on sensitive operational technology infrastructure.
This rule detects successful configuration modifications to diagnostic settings or storage services where the destination resource is identified as being outside of the organization's trusted subscriptions or expected storage naming conventions. This activity may indicate an adversary attempting to exfiltrate logs or data to an attacker-controlled storage account.
This rule detects a sequence of suspicious activities on macOS: downloading a file from a potentially malicious source using curl, mounting a disk image using hdiutil, and subsequently opening files from the mounted volume. This pattern is commonly associated with the delivery and execution of malicious payloads, such as trojanized software or malware installers.
