
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the modification of the SID History attribute on Active Directory accounts (Event ID 4765) or failed attempts to do so (Event ID 4766). The SID History attribute can be abused to gain unauthorized access and escalate privileges across domain boundaries by injecting well-known or administrative SIDs, a technique known as SID-History Injection.
This rule detects the configuration of 'Trusted for Delegation' on a computer or user account, followed by a modification to the Active Directory nTDSDSA object on the same host. This combination is a classic indicator of setting up an account for Kerberos delegation attacks, often related to the creation of rogue domain controllers or setting up pivot points for lateral movement.
This rule detects unauthorized modifications to sensitive Group Policy Object (GPO) attributes, such as file system paths, version numbers, or extension settings. It monitors Security Event 5136 for changes targeting GPO containers by non-standard administrative accounts, flagging potential attempts to persist access or escalate privileges via GPO tampering.
Detects reconnaissance activity targeting Active Directory group structures and membership, utilizing common administrative tools such as net.exe, PowerShell, and dsquery. This rule identifies patterns associated with domain group discovery and identification of privileged accounts.
Detects AS-REQ requests for accounts where Kerberos pre-authentication is disabled (PreAuthType 0) and insecure ticket encryption types (0x17, 0x18, 0x1) are used. This behavior is indicative of an AS-REP Roasting attack, where an adversary attempts to obtain the encrypted AS-REP response for an account to perform offline brute-force password cracking.
This rule monitors for suspicious child processes (like cmd.exe, powershell.exe, wscript.exe, or rundll32.exe) spawned by dllhost.exe. Dllhost.exe is typically a legitimate Windows process for COM object hosting, and it spawning command-line interpreters or administrative utilities is often indicative of malicious activity, such as process injection or lateral movement.
Detects when a single user initiates a high volume (5 or more) of external guest user invitations within a one-hour window. This behavior can be indicative of reconnaissance or attempts to establish persistence by an compromised account by inviting external identities into the tenant.
Detects the execution of PowerShell commands used to initiate remote sessions (e.g., New-PSSession, Invoke-Command) targeting specific remote hosts, excluding localhost connections and common system processes. This behavior is often associated with lateral movement or remote administration activities.
Detects modifications to Windows Registry keys commonly associated with COM hijacking. Attackers modify these keys to redirect legitimate system calls to malicious executables, achieving persistence and potential privilege escalation. This rule monitors for registry value creation or modification in keys related to shell open commands for MS-settings, MSC files, or executables.
Detects the use of PowerShell commands that modify file system metadata (e.g., CreationTime, LastWriteTime, LastAccessTime). This technique, often referred to as 'timestomping', is used by adversaries to manipulate file timestamps to evade detection or hide activity.
Page 553 of 867
