
Goksel Atakan
@gokselatakanIstanbulTrusted contributorCompletionist
0 followers8 downloads348 copies9 likes688 views
45 detections
Filters
Last updated
All Time
Detection languages
36
9
Categories
13
8
8
7
6
Platforms
18
16
15
10
7
Products / Services
12
11
8
6
6
MITRE Techniques
22
12
7
6
6
CVEs
1
This rule detects the addition of a user to a security-enabled global group in Active Directory by monitoring Windows Security Event ID 4728. This event occurs when an account is added to a security-enabled global group, which is a common action during privilege escalation or persistence phases.
This rule identifies devices with a high concentration (5 or more) of local AI agents reported within a 30-day period. This could indicate potentially unauthorized mass deployment or misconfiguration of AI agent software on specific endpoints.
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
This rule monitors Windows Security Event Logs for Event IDs 4728 and 4729, which indicate that a security-enabled global group has had a member added or removed, respectively. By aggregating these changes by group name and event action, it provides a summary of administrative activity regarding Active Directory group membership changes over a 365-day period.
This rule identifies accounts (by SID) that have registered multiple local AI agent instances. It aggregates agent registration information over a 30-day period, summarizing the total count of agents and listing specific device names and IDs associated with each account to identify potential anomalous behavior, such as credential abuse or unauthorized mass deployment of local AI tools.
This rule analyzes recent agent telemetry to identify and summarize the distribution of local agent vendors present in the environment over a 30-day lookback period. It extracts vendor information from agent metadata and provides a frequency count to assist in auditing deployed infrastructure agents.
Disabled User Monitoring For On-Prem
Cortex XDR
This rule detects Windows Security Event ID 4725, which indicates that a user account has been disabled. It extracts relevant details such as the target user account, domain, and the user who performed the action to provide context for potential account-based denial-of-service or unauthorized access removal attempts.
Device Name Search
Cortex XDR
This rule performs a telemetry data retrieval query for a specific agent hostname. It outputs detailed fields related to network connections and process executions (including command lines, user context, and process image names) from the XDR dataset for auditing or investigative purposes.
AD Group Changes and Membership Activity
Cortex XDR
This rule monitors Active Directory security event logs for modifications to local, global, and universal groups. It specifically tracks events related to the creation, deletion, and membership changes of AD groups, providing visibility into potential privilege escalation or unauthorized administrative activity within the domain.
Published Agent Without Instructions
Cortex XDR
This rule identifies 'Agent' entities that are marked as 'Published' but lack associated instructions (either empty or 'N/A'). In many agentic or orchestration frameworks, a published agent without instructions may indicate a misconfiguration, a stalled deployment, or a potential security risk where a functional component exists in the environment without defined operational parameters or guardrails.
