
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Rust-based ransomware family targeting enterprise environments
Ransomware group exploiting edge devices and managed file transfer software
Rust-based ransomware family targeting enterprise environments
Loader malware delivering follow-on ransomware payloads
Loader malware delivering follow-on ransomware payloads
Rust-based ransomware family targeting enterprise environments
Ransomware group exploiting edge devices and managed file transfer software
Loader malware delivering follow-on ransomware payloads
This rule detects common Kerberoasting activities by monitoring for the execution of 'Rubeus' or 'GetUserSPNs' (often associated with Impacket) in process command lines. These tools are commonly used by attackers to request service tickets for service accounts, which can then be cracked offline to recover passwords.
Detects unsigned or non-Microsoft processes attempting to access sensitive system process memory (lsass.exe, winlogon.exe, services.exe) or processes attempting to enable SeDebugPrivilege, which are common indicators of credential dumping or process injection attempts.
