
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
KQL Query from file: INC Ransomware Command Execution
Detects processes making HTTP/HTTPS requests to localhost on ports 40341 or 40342 for '/metadata'. This pattern can indicate local service discovery, inter-process communication, or potentially malicious activity attempting to interact with local services, possibly for credential access or privilege escalation.
This rule detects attempts to authenticate to SSH using GSSAPI (Generic Security Service Application Programming Interface). While GSSAPI can be used for legitimate authentication, its presence in logs might indicate an attacker attempting to use alternative authentication methods, potentially for lateral movement or privilege escalation, especially if unexpected in the environment.
This rule detects network connections to a predefined list of known Microstealer malicious domains. These domains are often associated with malware command and control (C2) infrastructure, phishing, or other malicious activities. Monitoring connections to such domains can help identify compromised systems or active malware infections.
This rule detects potential DCSync replication abuse by monitoring Security Event ID 4662, specifically looking for access to 'domainDNS' or user objects with the GUID '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2', which is associated with Directory Replication Service (DRS) permissions. It filters out machine accounts to reduce false positives.
This rule detects potential brute force or credential stuffing attacks against Azure AD by identifying multiple failed sign-in attempts followed by a successful sign-in from the same user and IP address within a short time frame (1 minute). It specifically looks for scenarios where the successful sign-in occurs after the failed attempts and involves different applications, excluding common Office 365 services to reduce noise.
This rule detects interactive logons (LogonType 10) where a single account from the same domain logs into multiple distinct devices. This could indicate an attacker using compromised credentials to move laterally within the network or access multiple systems.
Detect traffic to the C2 server used by the backdoor linked to MuddyWater.
Detects PowerShell processes launched by web browsers (Chrome, Edge, Firefox, Internet Explorer) or Windows Explorer, especially when using suspicious command-line arguments like encoded commands, Invoke-Expression, or web download functions. This behavior can indicate an attempt to execute malicious scripts, often initiated through user interaction (e.g., clicking a malicious link or opening a crafted file).
This rule detects network connections from devices to a predefined list of known malicious domains. It identifies attempts by internal systems to communicate with command and control servers, phishing sites, or other infrastructure associated with threat actors.
