
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of known Kerberoasting tools such as Rubeus and Impacket (GetST, GetTGT, asktgs) or command-line arguments indicative of Kerberoasting, specifically targeting RC4/ETYPE-23 ticket requests that are often used to crack service account passwords offline.
Detects common lateral movement patterns associated with Pass-the-Hash (PtH) attacks, specifically identifying remote execution via WMI/services, the use of explicit credentials in management utilities (wmic/net), and suspicious network connections from known administration tools over lateral movement ports.
This rule detects anomalous high-volume file download activities from Microsoft SharePoint and OneDrive for Business, which may indicate data exfiltration. The rule aggregates download events by user and IP address over 10-minute intervals and triggers when the download count exceeds 200, excluding known service/backup accounts.
Detects the execution of known network exploitation tools like Responder.py or MultiRelay.py, as well as unauthorized processes binding to ports used for LLMNR (UDP 5355) and NBT-NS (UDP 137), which are classic indicators of potential adversary-in-the-middle attacks.
Detects when a single user account performs 3 or more Privileged Identity Management (PIM) role activations within a 30-minute window. This behavior may indicate an attacker who has compromised a privileged account and is rapidly assuming multiple roles to perform lateral movement or privilege escalation.
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
Detects high-volume failed authentication attempts targeting a specific user account from a source IP address, indicative of 'MFA fatigue' or 'push bombing' attacks. This rule monitors endpoint-visible logon failure events as captured by EDR telemetry to identify potential attempts to circumvent multi-factor authentication by spamming the user with requests.
This rule detects indicators of WMI event subscription persistence, including the creation of WMI event filters, consumers, and bindings. It monitors for the use of command-line tools like wmic, powershell, or mofcomp to manipulate WMI objects, and identifies suspicious process activity originating from WMI provider host or consumer processes.
Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) when initialized with an INF file from potentially suspicious directories (e.g., Temp, AppData), or when cmstp.exe is observed spawning common command-line shells (cmd.exe, powershell.exe) or rundll32.exe, which is indicative of potential proxy execution or UAC bypass techniques.
This rule detects when users access or download suspicious file types (specifically .xlsm, .docm, or .ics) from Microsoft SharePoint, Teams, or Exchange, where the filenames contain keywords associated with common phishing lures such as credentials, invoices, payroll, or password resets. This monitors for indicators of potential spearphishing attempts involving malicious documents or calendar invites within the M365 environment.
