avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views

8,664 detections

Detects suspicious activity involving multiple password resets for different users initiated by a single user within a one-hour timeframe in Azure AD. This could indicate an attacker attempting to gain control over multiple accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects potential Kerberos Golden Ticket attacks by identifying Kerberos authentication service (AS) request events (EventID 4768) where the ticket encryption type is 0x17 (RC4-HMAC) and the difference between the event generation time and the ticket's start time is greater than one day. This large time difference can indicate a forged ticket with an invalid timestamp, a common characteristic of Golden Tickets. The rule then summarizes these events by target username and computer, flagging instances where three or more such events occur.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects attempts to access the Local Security Authority Subsystem Service (LSASS) process memory or the NTDS.dit file, which are common targets for credential dumping. It specifically looks for Security Event ID 4656 (A handle to an object was requested) where the ObjectName is either 'lsass.exe' or 'ntds.dit' and the AccessMask indicates read or all access permissions. The rule then summarizes these events by user, computer, and IP address, flagging if two or more such events occur.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious changes to account delegation settings by monitoring Security Event ID 5136 for modifications to the 'msDS-AllowedToDelegateTo' attribute. It specifically looks for instances where an account's delegation settings are changed two or more times within an hour, which could indicate an adversary attempting to establish persistence or elevate privileges through constrained delegation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects multiple failed Kerberos pre-authentication attempts (EventID 4771 with status codes 0x18 or 0x1f) from a single IP address against a target user within a short timeframe (20 attempts in 5 minutes). This pattern is indicative of a brute-force attack against Kerberos accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential abuse of Group Policy Objects (GPOs) by identifying multiple changes (3 or more) to GPO-related objects within a short timeframe. It specifically looks for Event ID 5136 (Directory Service Changes) where the ObjectClass is either 'groupPolicyContainer' or 'gPCFileSysPath'. This could indicate an adversary modifying GPOs to achieve persistence, privilege escalation, or other malicious objectives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects an unusual frequency of command-line executions containing the terms 'compliance' or 'audit' on a single computer within a one-hour window. This activity could indicate an adversary performing reconnaissance or discovery to understand system configurations, security policies, or auditing mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects an unusual number of process creations (Event ID 4688) containing both 'security' and 'patch' in their command line within a one-hour window on a single computer. This could indicate automated patching activity, but a high volume might also suggest suspicious system modifications or an attempt to disguise malicious activity as legitimate patching.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious activity related to OpenSSL or certificate manipulation by identifying processes that execute commands containing 'openssl' or 'certificate' keywords. It aggregates these activities by computer and account within one-hour bins and flags if three or more such activities occur, which could indicate credential access attempts or system misconfiguration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of processes where the command line contains keywords such as 'cve' or 'vulnerability'. This could indicate attempts to exploit known vulnerabilities, perform vulnerability research, or execute tools related to vulnerability assessment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001