
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the execution of processes with command-line arguments indicative of Mimikatz usage. It specifically looks for the strings 'mimikatz', 'sekurlsa', or 'privilege::debug' in the command line of newly created processes (EventID 4688). This activity is commonly associated with credential dumping.
Detects the creation of new members in the 'Domain Admins' or 'Enterprise Admins' groups by monitoring Windows Security Event ID 4728. This event indicates that a member was added to a security-enabled global group. The rule specifically looks for additions to highly privileged administrative groups, which could indicate unauthorized privilege escalation or persistence.
This rule detects a high volume (5 or more within an hour) of process creation events where the command line contains keywords associated with remote access protocols like DCOM, WMI, or RPC. This could indicate an adversary utilizing these protocols for lateral movement or remote execution.
This rule detects the creation or modification of user accounts on Windows systems by monitoring Security Event IDs 4741 (A security-enabled local group was created) and 4742 (A computer account was changed). It summarizes the count of such changes per hour by the subject user name, which can help identify unusual or excessive account management activities.
This rule detects an unusually high number of registry access events initiated by common Windows system utilities such as 'reg.exe', 'regsvcs.exe', or 'regasm.exe' within a one-hour window. A count of 5 or more registry access events from these processes is considered suspicious and may indicate malicious activity like persistence, defense evasion, or privilege escalation through registry modification.
This rule detects an unusually high number of file rename events (20 or more within a 1-hour window) initiated by a single process account. This behavior can be indicative of malicious activities such as data staging prior to exfiltration, ransomware encryption, or attempts to evade detection by renaming malicious files or legitimate system utilities.
This rule detects a high volume of activity (10 or more events within an hour) to Windows administrative shares (C$, IPC$, ADMIN$) from a single source IP address. This behavior can indicate lateral movement, data exfiltration, or other malicious activity using legitimate administrative functions.
This rule detects an unusually high volume of successful network connections over SMB (ports 135, 139, 445) originating from a single account within a one-hour window. This behavior can be indicative of lateral movement, reconnaissance, or data exfiltration activities using SMB/RPC.
This rule detects an unusually high volume of file deletion events on a device within a short time frame (100 or more files deleted within a 5-minute window). This activity can be indicative of malicious behaviors such as ransomware encrypting and deleting original files, data wiping attacks, or an adversary attempting to remove forensic evidence by deleting logs or other critical files.
This rule detects an unusually high volume of logon events (both successful and failed) or a large number of unique users attempting to log on within a 5-minute window. This behavior is indicative of potential brute-force attacks or credential stuffing attempts against Windows systems.
