avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

KQL Query from file: INC Ransomware Command Execution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects processes making HTTP/HTTPS requests to localhost on ports 40341 or 40342 for '/metadata'. This pattern can indicate local service discovery, inter-process communication, or potentially malicious activity attempting to interact with local services, possibly for credential access or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
This rule detects attempts to authenticate to SSH using GSSAPI (Generic Security Service Application Programming Interface). While GSSAPI can be used for legitimate authentication, its presence in logs might indicate an attacker attempting to use alternative authentication methods, potentially for lateral movement or privilege escalation, especially if unexpected in the environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects network connections to a predefined list of known Microstealer malicious domains. These domains are often associated with malware command and control (C2) infrastructure, phishing, or other malicious activities. Monitoring connections to such domains can help identify compromised systems or active malware infections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects potential DCSync replication abuse by monitoring Security Event ID 4662, specifically looking for access to 'domainDNS' or user objects with the GUID '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2', which is associated with Directory Replication Service (DRS) permissions. It filters out machine accounts to reduce false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential brute force or credential stuffing attacks against Azure AD by identifying multiple failed sign-in attempts followed by a successful sign-in from the same user and IP address within a short time frame (1 minute). It specifically looks for scenarios where the successful sign-in occurs after the failed attempts and involves different applications, excluding common Office 365 services to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects interactive logons (LogonType 10) where a single account from the same domain logs into multiple distinct devices. This could indicate an attacker using compromised credentials to move laterally within the network or access multiple systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detect traffic to the C2 server used by the backdoor linked to MuddyWater.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects PowerShell processes launched by web browsers (Chrome, Edge, Firefox, Internet Explorer) or Windows Explorer, especially when using suspicious command-line arguments like encoded commands, Invoke-Expression, or web download functions. This behavior can indicate an attempt to execute malicious scripts, often initiated through user interaction (e.g., clicking a malicious link or opening a crafted file).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects network connections from devices to a predefined list of known malicious domains. It identifies attempts by internal systems to communicate with command and control servers, phishing sites, or other infrastructure associated with threat actors.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103