avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views

8,664 detections

This rule monitors for unauthorized deletion or modification of Microsoft Sentinel alert rules and automation rules. Such actions are indicative of an attacker attempting to impair security monitoring, silence alerts, or disable automated responses to maintain persistence and evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of 'net.exe' or 'net1.exe' with arguments 'view', 'share', or 'use' that appear in rapid succession or are initiated by potentially suspicious parent processes. This behavior is often associated with network enumeration and reconnaissance activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects instances where processes other than legitimate browser components attempt to access, read, or copy the browser 'Login Data' file. This file stores credentials used by Google Chrome and Microsoft Edge, and unauthorized access is a common technique used by credential-stealing malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the creation of named pipes with names commonly utilized by offensive C2 frameworks such as Cobalt Strike, Metasploit, and Covenant. By monitoring for specific pipe naming patterns created by non-system processes, this rule aims to identify potential post-exploitation activity, C2 beacons, or lateral movement tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
401
Detects successful logon events (4624) or special logon attempts (4648) associated with accounts or workstations identified as Qualys scanner agents. This is typically used to identify or baseline vulnerability scanning activity across the environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects unauthorized or non-standard attempts to replicate directory data from a Domain Controller, specifically looking for Directory Replication Service (DRS) GetChanges and GetChangesAll access requests. This behavior is indicative of a DCSync attack, often used by adversaries to dump credentials from the NTDS.dit database.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high-frequency failed logon attempts (Event ID 4625) from a single IP address within a short time window, indicating potential brute force or password spraying activity targeting Windows systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high volumes of sign-in failures or instances where Conditional Access policies are not applied, particularly for unregistered devices, indicating potential attempts to bypass security controls or perform brute-force attacks against cloud authentication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
301
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001