
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,028 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects multiple failed SSH authentication attempts originating from a single source IP within a short timeframe, which is indicative of a brute-force or credential-stuffing attack against SSH services.
This rule detects the use of the PSEXESVC named pipe during a write operation over the SMB protocol, which is indicative of lateral movement using the PsExec tool.
Detects outbound HTTP POST requests where the Content-Length header indicates a transfer size exceeding 10MB to external (non-HOME_NET) addresses. This pattern is indicative of potential data exfiltration via HTTP.
This rule detects the execution of common enumeration commands (net, dsquery) on systems identified as Domain Controllers. These commands are frequently used by adversaries for reconnaissance to identify local or domain users and groups after gaining access to a host.
Detects high-frequency SMB (Logon Type 3) authentication events targeting Domain Controllers, specifically involving suspicious or generic accounts such as 'ANONYMOUS LOGON', 'Guest', empty usernames, or machine accounts. This behavior is indicative of network reconnaissance, session enumeration, or brute-force attempts targeting the domain.
Detects high-frequency failed logon attempts (Event ID 4625) from a single IP address within a short time window, indicating potential brute force or password spraying activity targeting Windows systems.
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
This rule detects potential AS-REP Roasting activity by monitoring for a single source IP address requesting Kerberos TGTs (Event ID 4768) for multiple distinct user accounts within a 10-minute window. This behavior often indicates an attacker attempting to identify and harvest Kerberos pre-authentication hashes from accounts that do not require pre-authentication, which can then be cracked offline.
Detects high-frequency SMB (Logon Type 3) authentication events targeting Domain Controllers, specifically involving suspicious or generic accounts such as 'ANONYMOUS LOGON', 'Guest', empty usernames, or machine accounts. This behavior is indicative of network reconnaissance, session enumeration, or brute-force attempts targeting the domain.
Detects anomalous network scanning behavior from a Qualys scanner towards Domain Controller ports. The rule monitors CommonSecurityLog and NetworkSessions for high volumes of connection attempts (more than 50 within one hour) targeting critical Active Directory ports (88, 135, 389, 445, 636, 3268, 3269). This activity may indicate a scanner configuration error, a compromised scanner, or an adversary attempting to map the environment while masquerading as a security tool.
