avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,582 copies160 likes52,383 views

8,664 detections

This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential reconnaissance activities directed at a domain controller, specifically monitoring for DNS zone transfer (AXFR) requests or unusually high volumes of DNS 'ANY' queries. These behaviors are often associated with adversaries attempting to map network infrastructure or discover internal resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the invitation of an external user to the Azure AD tenant. This activity often results in the creation of a guest account with the '#EXT#' suffix in the User Principal Name (UPN). Monitoring this event is critical for identifying potential unauthorized external access or social engineering attempts aimed at gaining persistence within the environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects access to sensitive Domain DNS objects in Active Directory, specifically targeting properties associated with domain controller replication metadata or sensitive object attributes. This activity is often used for reconnaissance or to facilitate further attacks against domain infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Kerberos service ticket requests (TGS) where the encryption type is set to 0x17 (RC4-HMAC). This is commonly used in Kerberoasting attacks to capture service ticket hashes for offline brute-force attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects changes to Microsoft Entra (formerly Azure AD) Conditional Access policies. This includes additions, updates, or deletions of these security policies, which could indicate an attacker attempting to weaken authentication requirements, bypass multi-factor authentication, or establish persistence within the identity environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects high-volume connection requests to LDAP services (default ports 389, 636, 3268, 3269). A high number of connections from a single source to a destination within a short time window may indicate automated reconnaissance, LDAP enumeration, or brute-force attempts against domain services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation or modification of Windows scheduled tasks using Security Event IDs 4698 and 4702. This rule parses the event data to extract key task information such as task name, command, arguments, and the author of the task.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects potential cleartext leakage of usernames and passwords over FTP (port 21) by identifying HTTP requests containing common credential-related keywords in the URL, while explicitly excluding HTTPS traffic. This could indicate sensitive information being transmitted insecurely.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
405
Detects the creation of a file named 'NTDS.zip', which is a common naming convention used by adversaries when compressing the Active Directory database (NTDS.dit) for staging and subsequent exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Page 548 of 867