
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
Detects instances where a user or service principal is assigned to high-privilege roles (e.g., Global Administrator, Owner) without utilizing the Microsoft Entra Privileged Identity Management (PIM) service. This is indicated by the absence of 'PIM' in the LoggedByService field for a successful 'Add member to role' operation, which could signify an attempt to bypass established access controls and gain unauthorized elevated persistence.
This rule detects potentially malicious modification or configuration changes to Azure Function Apps. It monitors for operations such as creation, updates, and configuration changes that contain suspicious indicators like hardcoded credentials (TOKEN, SECRET, PASS), potential reverse shell patterns, or large Base64 encoded payloads. The rule specifically excludes known CI/CD pipeline callers to minimize false positives.
Detects network traffic on port 443 originating from non-browser processes destined for known DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9). This behavior can indicate an attempt to bypass standard network DNS filtering or to establish Command and Control (C2) communication channels using the DoH protocol.
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
Detects instances where processes other than legitimate browser-related binaries access sensitive SQLite database files (Login Data and Cookies) associated with Google Chrome or Microsoft Edge. This activity is a common indicator of credential theft by malicious tools or scripts attempting to extract stored passwords or session cookies.
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
Detects instances where a non-SYSTEM parent process spawns a child process running as SYSTEM, characteristic of 'Potato' family exploits (e.g., JuicyPotato, PrintSpoofer) leveraging SeImpersonatePrivilege to elevate privileges. The rule specifically filters for known legitimate SYSTEM process spawners while highlighting suspicious parent-child process relationships.
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
