
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects reconnaissance activity where adversaries enumerate domain user accounts using standard Windows command-line tools, PowerShell Active Directory modules, and direct LDAP queries. This behavior is commonly performed to identify user accounts for subsequent password spraying, brute force attacks, or privilege escalation.
Detects users who modify their MFA settings (registration/update/delete) and subsequently perform privileged actions (such as adding role members or service principal credentials) within a short timeframe, while simultaneously observed active in communication applications like Teams, Zoom, or Webex. This behavior is indicative of potential account takeover where an adversary modifies authentication methods to gain persistent access, followed by privilege escalation.
Detects modifications to COM object InProcServer32 registry keys within the user's registry hive (HKEY_USERS). Attackers often hijack COM objects to achieve persistence by pointing them to malicious DLLs or OCX files. This rule specifically filters out common legitimate paths (Windows directories, Program Files) and known installers to reduce noise.
Detects unauthorized processes attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data' in Google Chrome, Microsoft Edge, or Brave. These files contain stored credentials and session information that are frequent targets for credential theft malware and post-exploitation activity.
Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.
Detects changes to the attributes of the AdminSDHolder object in Active Directory. The AdminSDHolder object is a template used by the Active Directory security descriptor propagator (SDProp) to enforce permissions on protected administrative groups. Modification of this object is a highly suspicious activity that can be used to establish persistence or grant excessive privileges by poisoning the security descriptors of all protected objects within the domain.
Detects AS-REQ requests for accounts where Kerberos pre-authentication is disabled (PreAuthType 0) and insecure ticket encryption types (0x17, 0x18, 0x1) are used. This behavior is indicative of an AS-REP Roasting attack, where an adversary attempts to obtain the encrypted AS-REP response for an account to perform offline brute-force password cracking.
Detects unauthorized processes attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data' in Google Chrome, Microsoft Edge, or Brave. These files contain stored credentials and session information that are frequent targets for credential theft malware and post-exploitation activity.
Detects a high volume of file uploads (greater than 50) to OneDrive or SharePoint by a single user within a 5-minute window, potentially indicating bulk exfiltration of data.
Detects modifications to Windows Defender registry keys responsible for defining file, path, process, or extension exclusions. Adversaries often modify these settings to prevent security software from scanning their malicious artifacts.
