
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,087 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.
Detects Kerberos Authentication Service Requests (AS-REQ) resulting in a ticket granting ticket (TGT) where the TicketOptions field is set to '0x40810010'. This specific combination is often associated with the behavior of tools performing Kerberoasting or specific types of ticket-based attacks, as it indicates a TGT request that may bypass standard pre-authentication or follow non-standard flow patterns.
Detects modifications to a computer account (Event ID 4742) that involve the addition or modification of Service Principal Names (SPNs) containing sensitive strings such as 'GC/' (Global Catalog), 'DRS' (Directory Replication Service), or specific GUIDs. These activities are often associated with techniques to facilitate Kerberoasting, domain trust exploitation, or unauthorized service manipulation.
Detects modifications to Windows domain trusts (Event ID 4706) or changes to domain security policies (Event ID 4716). These events are critical as they can indicate attempts to modify domain-level trust relationships or alter auditing and security settings.
This rule detects the use of native Windows utilities such as nltest.exe, netdom.exe, and PowerShell to enumerate Active Directory domain trust relationships. Attackers commonly perform this discovery to map out target environments, identify lateral movement opportunities, or plan further exploitation in multi-domain or forest environments.
Detects Kerberos Authentication Service Requests (AS-REQ) resulting in a ticket granting ticket (TGT) where the TicketOptions field is set to '0x40810010'. This specific combination is often associated with the behavior of tools performing Kerberoasting or specific types of ticket-based attacks, as it indicates a TGT request that may bypass standard pre-authentication or follow non-standard flow patterns.
Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
This rule detects potential Active Directory enumeration attempts by monitoring for the execution of common command-line tools and PowerShell cmdlets used to query domain information, such as users, groups, and domain controllers.
Detects the deletion of directory service objects such as users, groups, organizational units, computers, or trusted domains. This is identified via Windows Security Event ID 5141, which tracks when a directory object is deleted.
Detects modifications to a computer account (Event ID 4742) that involve the addition or modification of Service Principal Names (SPNs) containing sensitive strings such as 'GC/' (Global Catalog), 'DRS' (Directory Replication Service), or specific GUIDs. These activities are often associated with techniques to facilitate Kerberoasting, domain trust exploitation, or unauthorized service manipulation.
