
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects suspicious activity involving multiple password resets for different users initiated by a single user within a one-hour timeframe in Azure AD. This could indicate an attacker attempting to gain control over multiple accounts.
This rule detects potential Kerberos Golden Ticket attacks by identifying Kerberos authentication service (AS) request events (EventID 4768) where the ticket encryption type is 0x17 (RC4-HMAC) and the difference between the event generation time and the ticket's start time is greater than one day. This large time difference can indicate a forged ticket with an invalid timestamp, a common characteristic of Golden Tickets. The rule then summarizes these events by target username and computer, flagging instances where three or more such events occur.
This rule detects attempts to access the Local Security Authority Subsystem Service (LSASS) process memory or the NTDS.dit file, which are common targets for credential dumping. It specifically looks for Security Event ID 4656 (A handle to an object was requested) where the ObjectName is either 'lsass.exe' or 'ntds.dit' and the AccessMask indicates read or all access permissions. The rule then summarizes these events by user, computer, and IP address, flagging if two or more such events occur.
This rule detects suspicious changes to account delegation settings by monitoring Security Event ID 5136 for modifications to the 'msDS-AllowedToDelegateTo' attribute. It specifically looks for instances where an account's delegation settings are changed two or more times within an hour, which could indicate an adversary attempting to establish persistence or elevate privileges through constrained delegation.
Detects multiple failed Kerberos pre-authentication attempts (EventID 4771 with status codes 0x18 or 0x1f) from a single IP address against a target user within a short timeframe (20 attempts in 5 minutes). This pattern is indicative of a brute-force attack against Kerberos accounts.
This rule detects potential abuse of Group Policy Objects (GPOs) by identifying multiple changes (3 or more) to GPO-related objects within a short timeframe. It specifically looks for Event ID 5136 (Directory Service Changes) where the ObjectClass is either 'groupPolicyContainer' or 'gPCFileSysPath'. This could indicate an adversary modifying GPOs to achieve persistence, privilege escalation, or other malicious objectives.
This rule detects an unusual frequency of command-line executions containing the terms 'compliance' or 'audit' on a single computer within a one-hour window. This activity could indicate an adversary performing reconnaissance or discovery to understand system configurations, security policies, or auditing mechanisms.
This rule detects an unusual number of process creations (Event ID 4688) containing both 'security' and 'patch' in their command line within a one-hour window on a single computer. This could indicate automated patching activity, but a high volume might also suggest suspicious system modifications or an attempt to disguise malicious activity as legitimate patching.
This rule detects suspicious activity related to OpenSSL or certificate manipulation by identifying processes that execute commands containing 'openssl' or 'certificate' keywords. It aggregates these activities by computer and account within one-hour bins and flags if three or more such activities occur, which could indicate credential access attempts or system misconfiguration.
Detects the creation of processes where the command line contains keywords such as 'cve' or 'vulnerability'. This could indicate attempts to exploit known vulnerabilities, perform vulnerability research, or execute tools related to vulnerability assessment.
