avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views

8,664 detections

This rule detects the execution of processes with command-line arguments indicative of Mimikatz usage. It specifically looks for the strings 'mimikatz', 'sekurlsa', or 'privilege::debug' in the command line of newly created processes (EventID 4688). This activity is commonly associated with credential dumping.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of new members in the 'Domain Admins' or 'Enterprise Admins' groups by monitoring Windows Security Event ID 4728. This event indicates that a member was added to a security-enabled global group. The rule specifically looks for additions to highly privileged administrative groups, which could indicate unauthorized privilege escalation or persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects a high volume (5 or more within an hour) of process creation events where the command line contains keywords associated with remote access protocols like DCOM, WMI, or RPC. This could indicate an adversary utilizing these protocols for lateral movement or remote execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the creation or modification of user accounts on Windows systems by monitoring Security Event IDs 4741 (A security-enabled local group was created) and 4742 (A computer account was changed). It summarizes the count of such changes per hour by the subject user name, which can help identify unusual or excessive account management activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects an unusually high number of registry access events initiated by common Windows system utilities such as 'reg.exe', 'regsvcs.exe', or 'regasm.exe' within a one-hour window. A count of 5 or more registry access events from these processes is considered suspicious and may indicate malicious activity like persistence, defense evasion, or privilege escalation through registry modification.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects an unusually high number of file rename events (20 or more within a 1-hour window) initiated by a single process account. This behavior can be indicative of malicious activities such as data staging prior to exfiltration, ransomware encryption, or attempts to evade detection by renaming malicious files or legitimate system utilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects a high volume of activity (10 or more events within an hour) to Windows administrative shares (C$, IPC$, ADMIN$) from a single source IP address. This behavior can indicate lateral movement, data exfiltration, or other malicious activity using legitimate administrative functions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects an unusually high volume of successful network connections over SMB (ports 135, 139, 445) originating from a single account within a one-hour window. This behavior can be indicative of lateral movement, reconnaissance, or data exfiltration activities using SMB/RPC.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule detects an unusually high volume of file deletion events on a device within a short time frame (100 or more files deleted within a 5-minute window). This activity can be indicative of malicious behaviors such as ransomware encrypting and deleting original files, data wiping attacks, or an adversary attempting to remove forensic evidence by deleting logs or other critical files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects an unusually high volume of logon events (both successful and failed) or a large number of unique users attempting to log on within a 5-minute window. This behavior is indicative of potential brute-force attacks or credential stuffing attempts against Windows systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002