
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,081 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications or renames to critical Windows accessibility feature binaries (sethc.exe, utilman.exe, osk.exe, magnify.exe) located in System32. Adversaries frequently replace these binaries with malicious counterparts or command shells to achieve persistence and gain SYSTEM-level execution via accessibility shortcuts at the logon screen.
Detects the execution of known AS-REP Roasting tools or commands (such as GetNPUsers) by suspicious processes or from suspicious paths, indicating an attempt to extract Kerberos TGTs for accounts without preauthentication.
Detects the execution of known command-line sync tools (Rclone, MEGAsync) or commands attempting to sync or move data to various cloud storage services (s3, gdrive, onedrive, mega, dropbox). The rule focuses on executions from suspicious or temporary directory paths and excludes processes signed by trusted publishers to minimize noise.
Detects the execution of known privilege escalation tools (JuicyPotato, RoguePotato, PrintSpoofer) or command-line arguments indicative of token impersonation attempts (e.g., usage of SeImpersonatePrivilege) to escalate privileges on Windows systems.
Detects the execution of known NTLM relay and credential harvesting tools such as Responder, Inveigh, and PetitPotam, or suspicious command-line patterns involving the use of 'net use' or common Windows binaries (e.g., powershell.exe, rundll32.exe) to access or force SMB authentication with remote IP addresses.
Detects the execution of known Kerberoasting tools or commands that indicate an attempt to request Kerberos service tickets for offline cracking. This activity is a core component of the Kerberoasting attack technique.
This rule detects potential brute force or password spraying attacks by monitoring high volumes of authentication failures on an endpoint within a 5-minute window. Additionally, it identifies the execution of processes associated with multi-factor authentication (MFA) or single sign-on (SSO) clients, which could indicate an adversary attempting to bypass or manipulate MFA mechanisms.
Detects the execution of known NTLM relay and credential harvesting tools such as Responder, Inveigh, and PetitPotam, or suspicious command-line patterns involving the use of 'net use' or common Windows binaries (e.g., powershell.exe, rundll32.exe) to access or force SMB authentication with remote IP addresses.
Detects the creation of a new scheduled task using the Windows native schtasks.exe command-line utility. This behavior is commonly associated with persistence mechanisms or lateral movement activities where attackers schedule tasks to execute malicious payloads.
Detects the use of bitsadmin.exe to create or modify BITS transfer jobs, a technique often used by adversaries to download payloads or exfiltrate data under the guise of background system tasks.
