
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects suspicious activity related to accessing or dumping the NTDS.dit file, which contains Active Directory credential information. It looks for process creation events involving tools commonly used for NTDS.dit extraction (e.g., ntdsutil, secretsdump), file access events on NTDS.dit paths, and privilege use (SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege) often associated with credential dumping.
Detects PowerShell processes executing with command-line arguments that suggest the use of 'Get-Alias' (gal) or 'Get-Command' (gcm) followed by suspicious patterns. This could indicate an adversary attempting to discover system capabilities or installed modules.
Detects suspicious network connections to 'outlook-one.vercel.app' or 'api.telegram.org' when initiated by common web browsers (msedge.exe, chrome.exe, firefox.exe) or Outlook (outlook.exe). This pattern can indicate phishing attempts, credential harvesting, or data exfiltration via Telegram bots.
Detects when fodhelper.exe, a legitimate Windows utility, is used to spawn processes other than cmd.exe or conhost.exe. This behavior is commonly associated with UAC bypass techniques where fodhelper.exe is abused to execute arbitrary commands with elevated privileges without a UAC prompt.
This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.
Detects the creation or update of an Azure Sentinel analytics rule. This can indicate administrative activity related to security monitoring configuration. Monitoring these changes is crucial for detecting potential tampering with detection capabilities or the introduction of malicious rules.
This rule detects instances where a user clicks on a URL identified as potentially malicious (phishing-related) and subsequently has a risky sign-in event in Azure AD. The rule correlates URL click events from email with Azure AD sign-in logs, specifically looking for sign-ins marked as risky or originating from suspicious user agents (e.g., specific axios versions). The phishing URLs are identified by keywords such as 'azureapplicationregistration.pages.dev', 'chrnobinson.com', 'workers.dev', '.pages.dev', '.web.core.windows.net', '/oauth2/v2.0/authorize', 'client_id=', and 'scope=openid'.
This rule detects the presence of known Chaos ransomware samples by matching their SHA256 hashes against process execution events and file events. If a process with a matching hash is executed or a file with a matching hash is observed, an alert will be triggered.
Detects the addition of users to specific high-value or sensitive groups in Microsoft Entra ID (Azure AD), which could indicate potential unauthorized privilege escalation or persistence attempts by an attacker.
Detects the creation of .ics calendar invitation files in common user download and temporary directories when originated by web browsers or Microsoft Outlook. This pattern is often indicative of spearphishing campaigns where attackers use weaponized calendar files to deliver malicious payloads or links, attempting to exploit users through social engineering.
