avatar

Goksel Atakan

@gokselatakan
IstanbulTrusted contributorCompletionist
0 followers8 downloads348 copies9 likes688 views

45 detections

This rule detects the addition of a user to a security-enabled global group in Active Directory by monitoring Windows Security Event ID 4728. This event occurs when an account is added to a security-enabled global group, which is a common action during privilege escalation or persistence phases.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
205
This rule identifies devices with a high concentration (5 or more) of local AI agents reported within a 30-day period. This could indicate potentially unauthorized mass deployment or misconfiguration of AI agent software on specific endpoints.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
205
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
505
This rule monitors Windows Security Event Logs for Event IDs 4728 and 4729, which indicate that a security-enabled global group has had a member added or removed, respectively. By aggregating these changes by group name and event action, it provides a summary of administrative activity regarding Active Directory group membership changes over a 365-day period.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
104
This rule identifies accounts (by SID) that have registered multiple local AI agent instances. It aggregates agent registration information over a 30-day period, summarizing the total count of agents and listing specific device names and IDs associated with each account to identify potential anomalous behavior, such as credential abuse or unauthorized mass deployment of local AI tools.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
2 months ago
104
This rule analyzes recent agent telemetry to identify and summarize the distribution of local agent vendors present in the environment over a 30-day lookback period. It extracts vendor information from agent metadata and provides a frequency count to assist in auditing deployed infrastructure agents.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
304
This rule detects Windows Security Event ID 4725, which indicates that a user account has been disabled. It extracts relevant details such as the target user account, domain, and the user who performed the action to provide context for potential account-based denial-of-service or unauthorized access removal attempts.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
103
This rule performs a telemetry data retrieval query for a specific agent hostname. It outputs detailed fields related to network connections and process executions (including command lines, user context, and process image names) from the XDR dataset for auditing or investigative purposes.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
002
This rule monitors Active Directory security event logs for modifications to local, global, and universal groups. It specifically tracks events related to the creation, deletion, and membership changes of AD groups, providing visibility into potential privilege escalation or unauthorized administrative activity within the domain.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
102
This rule identifies 'Agent' entities that are marked as 'Published' but lack associated instructions (either empty or 'N/A'). In many agentic or orchestration frameworks, a published agent without instructions may indicate a misconfiguration, a stalled deployment, or a potential security risk where a functional component exists in the environment without defined operational parameters or guardrails.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
001