avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,081 views

8,664 detections

Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. The rule excludes common non-user account ticket requests (machine accounts and krbtgt) to reduce noise, focusing on potential service account targeting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects attempts by non-system user accounts to access the SAM or SECURITY registry hives. These hives contain sensitive credential material, and unauthorized access is a common indicator of credential dumping activities, often associated with tools like Mimikatz or scripts attempting to extract local account hashes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. The rule excludes common non-user account ticket requests (machine accounts and krbtgt) to reduce noise, focusing on potential service account targeting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the execution of common remote administration tools (PsExec, PaExec, RemCom) specifically on devices identified as domain controllers based on their naming convention.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects an abnormally high volume of connections to the hidden IPC$ administrative share on a Windows host within a short time window. This activity is often associated with lateral movement techniques, scanning, or brute-forcing attempts where adversaries interact with SMB shares for reconnaissance or remote execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects attempts by non-system user accounts to access the SAM or SECURITY registry hives. These hives contain sensitive credential material, and unauthorized access is a common indicator of credential dumping activities, often associated with tools like Mimikatz or scripts attempting to extract local account hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule monitors DNS queries and network connections for access to a set of known domain names associated with Adversary-in-the-Middle (AiTM) phishing infrastructure. It correlates data from DNS events, device network logs, and virtual machine network connections to identify potential interactions with malicious phishing sites typically used to capture user credentials or session tokens.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects post-compromise Active Directory reconnaissance activities using net.exe or wmic.exe to enumerate domain users, groups, computers, and sessions. The rule identifies anomalous behavior by monitoring for at least 3 distinct reconnaissance categories triggered by common scripting interpreters (PowerShell, cmd, pythonw, or node.exe) within a 5-minute window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors for the creation of .exe or .msi files within common user-writable directories (Downloads, Temp, AppData) initiated by web browser processes (Chrome, Edge, Firefox, Brave). This behavior is often indicative of drive-by downloads or users interacting with malicious web content that delivers installers to the host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002