avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

This rule detects the modification of the SID History attribute on Active Directory accounts (Event ID 4765) or failed attempts to do so (Event ID 4766). The SID History attribute can be abused to gain unauthorized access and escalate privileges across domain boundaries by injecting well-known or administrative SIDs, a technique known as SID-History Injection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects various methods used to copy or access the Active Directory database (NTDS.dit), a common technique used by attackers to dump domain credentials. The rule monitors for the use of ntdsutil with 'ifm' (install from media) arguments, vssadmin to create volume shadow copies of the NTDS file, esentutl directly interacting with the NTDS database path, and common file copy utilities attempting to copy the NTDS.dit file.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects various methods used to copy or access the Active Directory database (NTDS.dit), a common technique used by attackers to dump domain credentials. The rule monitors for the use of ntdsutil with 'ifm' (install from media) arguments, vssadmin to create volume shadow copies of the NTDS file, esentutl directly interacting with the NTDS database path, and common file copy utilities attempting to copy the NTDS.dit file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects Kerberos service tickets for the 'krbtgt' account that utilize RC4 encryption (0x17) or possess a suspiciously long lifetime (exceeding 10 hours). These conditions are common indicators of Golden Ticket attacks or potential credential manipulation, as legitimate TGTs should not typically exhibit these properties.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule monitors Active Directory Certificate Services (AD CS) event logs for signs of potential privilege escalation and credential abuse. It specifically targets indicators of ESC1 (AD CS misconfigurations allowing requester-supplied SANs), identifies requests for certificates by non-owners for privileged accounts, and monitors for the use of PKI-based Kerberos authentication against high-privilege targets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the execution of known LLMNR, NBT-NS, and SMB relaying tools such as Responder, Inveigh, and MultiRelay, or the use of their specific command-line arguments, which are commonly used by adversaries for adversary-in-the-middle attacks to capture or relay authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects instances where a guest user is invited to the organization using an email address from potentially malicious TLDs (e.g., .ru, .cn, .ir, .kp) or a domain structure that is represented as an IP address. These patterns are often associated with phishing, reconnaissance, or adversary attempts to gain a foothold in an environment by inviting external identities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
This rule detects potential Kerberoasting activity by monitoring Windows Event ID 4769 (Kerberos service ticket request). It identifies excessive requests for service tickets using RC4 encryption (0x17) by a single account within a 10-minute window, excluding common service accounts and krbtgt requests.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects bulk file access, download, or sync operations by a single user account within a 30-minute window in Microsoft SharePoint Online or OneDrive for Business. This behavior is indicative of potential data exfiltration or unauthorized mass collection of sensitive information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
Detects potential Windows privilege escalation attempts where a user account is assigned the SeImpersonatePrivilege and subsequently executes known exploitation tools (e.g., Potato-family exploits) within a short window. This pattern often indicates an attempt to escalate to SYSTEM privileges by abusing token impersonation vulnerabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204