
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,582 copies160 likes52,383 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
Detects the invitation of an external user to the Azure AD tenant. This activity often results in the creation of a guest account with the '#EXT#' suffix in the User Principal Name (UPN). Monitoring this event is critical for identifying potential unauthorized external access or social engineering attempts aimed at gaining persistence within the environment.
Detects access to sensitive Domain DNS objects in Active Directory, specifically targeting properties associated with domain controller replication metadata or sensitive object attributes. This activity is often used for reconnaissance or to facilitate further attacks against domain infrastructure.
Detects Kerberos service ticket requests (TGS) where the encryption type is set to 0x17 (RC4-HMAC). This is commonly used in Kerberoasting attacks to capture service ticket hashes for offline brute-force attacks.
Detects changes to Microsoft Entra (formerly Azure AD) Conditional Access policies. This includes additions, updates, or deletions of these security policies, which could indicate an attacker attempting to weaken authentication requirements, bypass multi-factor authentication, or establish persistence within the identity environment.
This rule detects high-volume connection requests to LDAP services (default ports 389, 636, 3268, 3269). A high number of connections from a single source to a destination within a short time window may indicate automated reconnaissance, LDAP enumeration, or brute-force attempts against domain services.
Detects the creation or modification of Windows scheduled tasks using Security Event IDs 4698 and 4702. This rule parses the event data to extract key task information such as task name, command, arguments, and the author of the task.
This rule detects potential cleartext leakage of usernames and passwords over FTP (port 21) by identifying HTTP requests containing common credential-related keywords in the URL, while explicitly excluding HTTPS traffic. This could indicate sensitive information being transmitted insecurely.
Detects the creation of a file named 'NTDS.zip', which is a common naming convention used by adversaries when compressing the Active Directory database (NTDS.dit) for staging and subsequent exfiltration.
Page 548 of 867
