
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unauthorized or non-standard attempts to replicate directory data from a Domain Controller, specifically looking for Directory Replication Service (DRS) GetChanges and GetChangesAll access requests. This behavior is indicative of a DCSync attack, often used by adversaries to dump credentials from the NTDS.dit database.
Detects high-volume, multi-port connections from a single source to a domain controller, which is indicative of vulnerability scanning activity such as Nessus. The rule monitors for a large volume of connection attempts across multiple sensitive ports (e.g., 88, 135, 389, 445, 464, 636, 3268, 3269) within a short 5-minute window.
Detects successful network or explicit credential logons (4624/4648) on Windows workstations where the username or workstation name contains keywords associated with Tenable Nessus scanning activity, indicating an authenticated vulnerability scan.
Detects high-frequency enumeration of privileged roles or role assignments within Azure AD (Entra ID) by a single user or IP address within a short time window. This activity often precedes more targeted attacks aimed at compromising highly privileged identities.
This rule detects potential password spraying attacks against Azure Active Directory by identifying sign-in failures from a single source IP address targeting a large number of distinct user accounts within a short time window. It specifically filters for common authentication failure codes and checks for low volume of failures per account, which is characteristic of password spraying behavior.
Detects MFA push bombing attacks by identifying a high volume of MFA challenge failures (errorCode 500121) associated with a single user account within a short time window. This activity often indicates an attempt to overwhelm or fatigue a user into inadvertently approving an MFA request.
Detects successful logon events (4624) or special logon attempts (4648) associated with accounts or workstations identified as Qualys scanner agents. This is typically used to identify or baseline vulnerability scanning activity across the environment.
Detects high-volume LDAP queries or specific expensive LDAP search events (Event ID 1644) on Domain Controllers, which are often indicative of reconnaissance activities such as domain environment mapping or user/group enumeration.
This rule detects potential container escape attempts on Linux systems by monitoring suspicious file system access patterns to the host's root directory or process creation events involving 'mount', 'nsenter', or 'chroot' commands with parameters indicative of host interaction. Specifically, it looks for file operations on '/proc/1/root', '/proc/1/cwd', '/proc/1/exe', '/proc/1/fd', '/proc/1/ns', '/proc/1/environ', '/proc/1/mounts' or paths starting with '/host', '/hostroot', '/host-root', '/node-root'. It also flags 'mount' commands targeting '/proc/1/root', '/proc/1', 'nsenter', '--target 1', 'hostpath', or '/host', 'nsenter' commands with namespace manipulation arguments, and 'chroot' commands targeting '/proc/1/root', '/host', or '/hostroot'. These activities are commonly associated with adversaries trying to break out of a containerized environment to gain access to the underlying host.
Detects Kerberos service ticket requests (TGS) where the encryption type is set to 0x17 (RC4-HMAC). This is commonly used in Kerberoasting attacks to capture service ticket hashes for offline brute-force attacks.
