
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,081 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. The rule excludes common non-user account ticket requests (machine accounts and krbtgt) to reduce noise, focusing on potential service account targeting.
Detects attempts by non-system user accounts to access the SAM or SECURITY registry hives. These hives contain sensitive credential material, and unauthorized access is a common indicator of credential dumping activities, often associated with tools like Mimikatz or scripts attempting to extract local account hashes.
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. The rule excludes common non-user account ticket requests (machine accounts and krbtgt) to reduce noise, focusing on potential service account targeting.
This rule detects the execution of common remote administration tools (PsExec, PaExec, RemCom) specifically on devices identified as domain controllers based on their naming convention.
Detects an abnormally high volume of connections to the hidden IPC$ administrative share on a Windows host within a short time window. This activity is often associated with lateral movement techniques, scanning, or brute-forcing attempts where adversaries interact with SMB shares for reconnaissance or remote execution.
Detects attempts by non-system user accounts to access the SAM or SECURITY registry hives. These hives contain sensitive credential material, and unauthorized access is a common indicator of credential dumping activities, often associated with tools like Mimikatz or scripts attempting to extract local account hashes.
This rule monitors DNS queries and network connections for access to a set of known domain names associated with Adversary-in-the-Middle (AiTM) phishing infrastructure. It correlates data from DNS events, device network logs, and virtual machine network connections to identify potential interactions with malicious phishing sites typically used to capture user credentials or session tokens.
Detects post-compromise Active Directory reconnaissance activities using net.exe or wmic.exe to enumerate domain users, groups, computers, and sessions. The rule identifies anomalous behavior by monitoring for at least 3 distinct reconnaissance categories triggered by common scripting interpreters (PowerShell, cmd, pythonw, or node.exe) within a 5-minute window.
This rule monitors for the creation of .exe or .msi files within common user-writable directories (Downloads, Temp, AppData) initiated by web browser processes (Chrome, Edge, Firefox, Brave). This behavior is often indicative of drive-by downloads or users interacting with malicious web content that delivers installers to the host.
This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.
