avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,028 views

8,664 detections

Detects multiple failed SSH authentication attempts originating from a single source IP within a short timeframe, which is indicative of a brute-force or credential-stuffing attack against SSH services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of the PSEXESVC named pipe during a write operation over the SMB protocol, which is indicative of lateral movement using the PsExec tool.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects outbound HTTP POST requests where the Content-Length header indicates a transfer size exceeding 10MB to external (non-HOME_NET) addresses. This pattern is indicative of potential data exfiltration via HTTP.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the execution of common enumeration commands (net, dsquery) on systems identified as Domain Controllers. These commands are frequently used by adversaries for reconnaissance to identify local or domain users and groups after gaining access to a host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects high-frequency SMB (Logon Type 3) authentication events targeting Domain Controllers, specifically involving suspicious or generic accounts such as 'ANONYMOUS LOGON', 'Guest', empty usernames, or machine accounts. This behavior is indicative of network reconnaissance, session enumeration, or brute-force attempts targeting the domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
403
Detects high-frequency failed logon attempts (Event ID 4625) from a single IP address within a short time window, indicating potential brute force or password spraying activity targeting Windows systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential AS-REP Roasting activity by monitoring for a single source IP address requesting Kerberos TGTs (Event ID 4768) for multiple distinct user accounts within a 10-minute window. This behavior often indicates an attacker attempting to identify and harvest Kerberos pre-authentication hashes from accounts that do not require pre-authentication, which can then be cracked offline.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects high-frequency SMB (Logon Type 3) authentication events targeting Domain Controllers, specifically involving suspicious or generic accounts such as 'ANONYMOUS LOGON', 'Guest', empty usernames, or machine accounts. This behavior is indicative of network reconnaissance, session enumeration, or brute-force attempts targeting the domain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects anomalous network scanning behavior from a Qualys scanner towards Domain Controller ports. The rule monitors CommonSecurityLog and NetworkSessions for high volumes of connection attempts (more than 50 within one hour) targeting critical Active Directory ports (88, 135, 389, 445, 636, 3268, 3269). This activity may indicate a scanner configuration error, a compromised scanner, or an adversary attempting to map the environment while masquerading as a security tool.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003