
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for unauthorized deletion or modification of Microsoft Sentinel alert rules and automation rules. Such actions are indicative of an attacker attempting to impair security monitoring, silence alerts, or disable automated responses to maintain persistence and evade detection.
Detects the use of 'net.exe' or 'net1.exe' with arguments 'view', 'share', or 'use' that appear in rapid succession or are initiated by potentially suspicious parent processes. This behavior is often associated with network enumeration and reconnaissance activities.
Detects instances where processes other than legitimate browser components attempt to access, read, or copy the browser 'Login Data' file. This file stores credentials used by Google Chrome and Microsoft Edge, and unauthorized access is a common technique used by credential-stealing malware.
Detects the creation of named pipes with names commonly utilized by offensive C2 frameworks such as Cobalt Strike, Metasploit, and Covenant. By monitoring for specific pipe naming patterns created by non-system processes, this rule aims to identify potential post-exploitation activity, C2 beacons, or lateral movement tools.
Detects successful logon events (4624) or special logon attempts (4648) associated with accounts or workstations identified as Qualys scanner agents. This is typically used to identify or baseline vulnerability scanning activity across the environment.
Detects unauthorized or non-standard attempts to replicate directory data from a Domain Controller, specifically looking for Directory Replication Service (DRS) GetChanges and GetChangesAll access requests. This behavior is indicative of a DCSync attack, often used by adversaries to dump credentials from the NTDS.dit database.
Detects high-frequency failed logon attempts (Event ID 4625) from a single IP address within a short time window, indicating potential brute force or password spraying activity targeting Windows systems.
Detects high volumes of sign-in failures or instances where Conditional Access policies are not applied, particularly for unregistered devices, indicating potential attempts to bypass security controls or perform brute-force attacks against cloud authentication.
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
