avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,087 views

8,664 detections

Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects Kerberos Authentication Service Requests (AS-REQ) resulting in a ticket granting ticket (TGT) where the TicketOptions field is set to '0x40810010'. This specific combination is often associated with the behavior of tools performing Kerberoasting or specific types of ticket-based attacks, as it indicates a TGT request that may bypass standard pre-authentication or follow non-standard flow patterns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects modifications to a computer account (Event ID 4742) that involve the addition or modification of Service Principal Names (SPNs) containing sensitive strings such as 'GC/' (Global Catalog), 'DRS' (Directory Replication Service), or specific GUIDs. These activities are often associated with techniques to facilitate Kerberoasting, domain trust exploitation, or unauthorized service manipulation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects modifications to Windows domain trusts (Event ID 4706) or changes to domain security policies (Event ID 4716). These events are critical as they can indicate attempts to modify domain-level trust relationships or alter auditing and security settings.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of native Windows utilities such as nltest.exe, netdom.exe, and PowerShell to enumerate Active Directory domain trust relationships. Attackers commonly perform this discovery to map out target environments, identify lateral movement opportunities, or plan further exploitation in multi-domain or forest environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects Kerberos Authentication Service Requests (AS-REQ) resulting in a ticket granting ticket (TGT) where the TicketOptions field is set to '0x40810010'. This specific combination is often associated with the behavior of tools performing Kerberoasting or specific types of ticket-based attacks, as it indicates a TGT request that may bypass standard pre-authentication or follow non-standard flow patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential Active Directory enumeration attempts by monitoring for the execution of common command-line tools and PowerShell cmdlets used to query domain information, such as users, groups, and domain controllers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the deletion of directory service objects such as users, groups, organizational units, computers, or trusted domains. This is identified via Windows Security Event ID 5141, which tracks when a directory object is deleted.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications to a computer account (Event ID 4742) that involve the addition or modification of Service Principal Names (SPNs) containing sensitive strings such as 'GC/' (Global Catalog), 'DRS' (Directory Replication Service), or specific GUIDs. These activities are often associated with techniques to facilitate Kerberoasting, domain trust exploitation, or unauthorized service manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002