avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views

8,664 detections

Detects unauthorized or non-standard attempts to replicate directory data from a Domain Controller, specifically looking for Directory Replication Service (DRS) GetChanges and GetChangesAll access requests. This behavior is indicative of a DCSync attack, often used by adversaries to dump credentials from the NTDS.dit database.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects high-volume, multi-port connections from a single source to a domain controller, which is indicative of vulnerability scanning activity such as Nessus. The rule monitors for a large volume of connection attempts across multiple sensitive ports (e.g., 88, 135, 389, 445, 464, 636, 3268, 3269) within a short 5-minute window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects successful network or explicit credential logons (4624/4648) on Windows workstations where the username or workstation name contains keywords associated with Tenable Nessus scanning activity, indicating an authenticated vulnerability scan.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects high-frequency enumeration of privileged roles or role assignments within Azure AD (Entra ID) by a single user or IP address within a short time window. This activity often precedes more targeted attacks aimed at compromising highly privileged identities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential password spraying attacks against Azure Active Directory by identifying sign-in failures from a single source IP address targeting a large number of distinct user accounts within a short time window. It specifically filters for common authentication failure codes and checks for low volume of failures per account, which is characteristic of password spraying behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects MFA push bombing attacks by identifying a high volume of MFA challenge failures (errorCode 500121) associated with a single user account within a short time window. This activity often indicates an attempt to overwhelm or fatigue a user into inadvertently approving an MFA request.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects successful logon events (4624) or special logon attempts (4648) associated with accounts or workstations identified as Qualys scanner agents. This is typically used to identify or baseline vulnerability scanning activity across the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-volume LDAP queries or specific expensive LDAP search events (Event ID 1644) on Domain Controllers, which are often indicative of reconnaissance activities such as domain environment mapping or user/group enumeration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
This rule detects potential container escape attempts on Linux systems by monitoring suspicious file system access patterns to the host's root directory or process creation events involving 'mount', 'nsenter', or 'chroot' commands with parameters indicative of host interaction. Specifically, it looks for file operations on '/proc/1/root', '/proc/1/cwd', '/proc/1/exe', '/proc/1/fd', '/proc/1/ns', '/proc/1/environ', '/proc/1/mounts' or paths starting with '/host', '/hostroot', '/host-root', '/node-root'. It also flags 'mount' commands targeting '/proc/1/root', '/proc/1', 'nsenter', '--target 1', 'hostpath', or '/host', 'nsenter' commands with namespace manipulation arguments, and 'chroot' commands targeting '/proc/1/root', '/host', or '/hostroot'. These activities are commonly associated with adversaries trying to break out of a containerized environment to gain access to the underlying host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
008
Detects Kerberos service ticket requests (TGS) where the encryption type is set to 0x17 (RC4-HMAC). This is commonly used in Kerberoasting attacks to capture service ticket hashes for offline brute-force attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
702