
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,043 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the execution of the Rubeus tool or the usage of common command-line arguments associated with Kerberoasting activities (e.g., GetUserSPNs, Request-SPNTicket). Kerberoasting is a technique used to extract service account password hashes from Active Directory by requesting service tickets for accounts with Service Principal Names (SPNs). These hashes can then be cracked offline to obtain cleartext credentials.
Detects outbound network connections from devices to known FortiBleed command and control (C2) servers and sniffer infrastructure IP addresses. This rule helps identify potential compromises involving the FortiBleed vulnerability exploitation.
Detects instances where the Squid proxy application is used to establish network connections over ports 21 (FTP) or 22 (SSH) to specific external IP ranges. This behavior may indicate an attacker using the internal proxy server to anonymize command-and-control (C2) traffic or perform unauthorized external reconnaissance.
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
This rule monitors file system events for the creation of files with common web shell names (e.g., shell.php, cmd.php) within known web server directory paths (e.g., wwwroot, inetpub). The detection of these specific file names in directories typically used for serving web content is a strong indicator of a potential web shell deployment.
Detects anomalous authentication patterns where a single source IP address exhibits multiple failed login attempts followed by at least one successful login within a 10-minute time window, indicative of credential stuffing or password spraying.
This rule detects when a non-administrative user grants an application high-privilege OAuth scopes (such as mail reading, file access, or directory management) within an Azure/Microsoft 365 environment. Such consent grants can be used by attackers to maintain persistence and bypass MFA by gaining delegated access to sensitive resources.
This rule detects the use of PowerShell or Command Prompt to execute commands related to Remote Monitoring and Management (RMM) software or remote management tools such as IDrive or TeamViewer. It specifically looks for command-line arguments involving RMM-related keywords combined with execution flags or piping operators, which is a common pattern for automating the deployment, configuration, or malicious use of these remote access tools.
Detects when a new federated identity credential is successfully added to an Azure Active Directory (Entra ID) application. This activity is a common method for attackers to establish persistent access to cloud resources by bypassing password-based authentication.
Detects changes to SharePoint tenant-level or site-level sharing policies that expand external access to 'Anyone' (anonymous links) or 'ExternalUserAndGuestSharing'. Such modifications represent a significant security posture regression that may facilitate unauthorized data access or facilitate exfiltration pathways.
