
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects anomalous ICMP Echo Request packets (Type 8) directed towards external networks that contain a payload size greater than 128 bytes. Such anomalies are often indicative of ICMP tunneling, which may be leveraged by adversaries for command and control (C2) communication or data exfiltration.
Detects changes to Microsoft Entra (formerly Azure AD) Conditional Access policies. This includes additions, updates, or deletions of these security policies, which could indicate an attacker attempting to weaken authentication requirements, bypass multi-factor authentication, or establish persistence within the identity environment.
Detects user sign-in activity originating from more than two distinct countries within the same hour, which is often indicative of impossible travel or compromised credentials.
Detects instances where the Active Directory domain database file (ntds.dit) is accessed by processes other than known legitimate tools such as lsass.exe or ntdsutil.exe. This activity is a strong indicator of credential dumping attempts to extract Active Directory hashes.
Detects successful assignment of highly privileged roles (Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator) to a user in Microsoft Entra ID (formerly Azure AD). This is often a sign of privilege escalation or persistence establishment by an attacker.
Detects user sign-in activity originating from more than two distinct countries within the same hour, which is often indicative of impossible travel or compromised credentials.
Detects the creation of a file named 'NTDS.zip', which is a common naming convention used by adversaries when compressing the Active Directory database (NTDS.dit) for staging and subsequent exfiltration.
Detects sign-in events using the device code authentication flow (OAuth 2.0 device authorization grant) where the originating IP address is external to the organization's private network. This flow is often abused by attackers to bypass traditional MFA or interact with headless environments via common HTTP client libraries like Python requests, Go-http, or Axios.
This rule monitors for additions of users to highly sensitive Active Directory groups, such as Domain Admins or Enterprise Admins, by tracking specific Windows security events (4728, 4732, 4756). Unauthorized membership changes in these groups are a classic indicator of privilege escalation or persistence maintenance by an adversary.
Detects specific object access (EventID 4662) targeting sensitive Active Directory objects, including Domain Admin, Enterprise Admin, or other high-value security principal containers. These GUIDs are associated with common Active Directory enumeration or exploitation techniques used to identify critical infrastructure or perform reconnaissance.
