avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

This rule detects the modification of the SID History attribute on Active Directory accounts (Event ID 4765) or failed attempts to do so (Event ID 4766). The SID History attribute can be abused to gain unauthorized access and escalate privileges across domain boundaries by injecting well-known or administrative SIDs, a technique known as SID-History Injection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the configuration of 'Trusted for Delegation' on a computer or user account, followed by a modification to the Active Directory nTDSDSA object on the same host. This combination is a classic indicator of setting up an account for Kerberos delegation attacks, often related to the creation of rogue domain controllers or setting up pivot points for lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects unauthorized modifications to sensitive Group Policy Object (GPO) attributes, such as file system paths, version numbers, or extension settings. It monitors Security Event 5136 for changes targeting GPO containers by non-standard administrative accounts, flagging potential attempts to persist access or escalate privileges via GPO tampering.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects reconnaissance activity targeting Active Directory group structures and membership, utilizing common administrative tools such as net.exe, PowerShell, and dsquery. This rule identifies patterns associated with domain group discovery and identification of privileged accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects AS-REQ requests for accounts where Kerberos pre-authentication is disabled (PreAuthType 0) and insecure ticket encryption types (0x17, 0x18, 0x1) are used. This behavior is indicative of an AS-REP Roasting attack, where an adversary attempts to obtain the encrypted AS-REP response for an account to perform offline brute-force password cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors for suspicious child processes (like cmd.exe, powershell.exe, wscript.exe, or rundll32.exe) spawned by dllhost.exe. Dllhost.exe is typically a legitimate Windows process for COM object hosting, and it spawning command-line interpreters or administrative utilities is often indicative of malicious activity, such as process injection or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects when a single user initiates a high volume (5 or more) of external guest user invitations within a one-hour window. This behavior can be indicative of reconnaissance or attempts to establish persistence by an compromised account by inviting external identities into the tenant.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the execution of PowerShell commands used to initiate remote sessions (e.g., New-PSSession, Invoke-Command) targeting specific remote hosts, excluding localhost connections and common system processes. This behavior is often associated with lateral movement or remote administration activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects modifications to Windows Registry keys commonly associated with COM hijacking. Attackers modify these keys to redirect legitimate system calls to malicious executables, achieving persistence and potential privilege escalation. This rule monitors for registry value creation or modification in keys related to shell open commands for MS-settings, MSC files, or executables.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of PowerShell commands that modify file system metadata (e.g., CreationTime, LastWriteTime, LastAccessTime). This technique, often referred to as 'timestomping', is used by adversaries to manipulate file timestamps to evade detection or hide activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Page 553 of 867