avatar

Lucas Pinho

@lucaslapinho
Completionist
0 followers9 downloads111 copies0 likes281 views

62 detections

Detects multiple Kerberos pre-authentication failures (Event ID 4771) with failure code 0x18, indicating incorrect passwords, originating from the same source address for a specific user account within a ten-minute window, which may suggest brute-force or credential-stuffing activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
3011
This rule detects potential password spraying activity by monitoring Microsoft Entra sign-in logs for multiple failed authentication attempts originating from the same source IP address targeting ten or more distinct user accounts within a ten-minute time window.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
3011
Generic rule content from file: MS_Entra_ID_Protection_Anomalous_Token_Risk.txt
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
5010
Detects successful Microsoft Entra RoleManagement activity where a member is assigned permanently to a role outside of Privileged Identity Management (PIM). This is flagged as a privileged access risk because it bypasses just-in-time eligibility and activation controls.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
10010
Detects Windows Security events (Event IDs 4728 and 4756) where a member is added to a sensitive or privileged Active Directory domain global or universal security group. The rule compares the target group against a locally maintained inventory of monitored groups to identify potential unauthorized privilege escalation or persistence.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
1010
Detects modifications to Windows user accounts where the 'Password Never Expires' flag is enabled. This modification, often represented by the DONT_EXPIRE_PASSWORD userAccountControl flag (Event ID 4738), may indicate an attempt to establish persistence or weaken credential lifecycle security by bypassing password rotation requirements.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
4010
Detects the execution of the Cortex XDR agent administration tool (Cytool) with the 'protect disable' command line argument. This indicates an attempt to manually disable the security agent's protective features on an endpoint, which is a common technique used by adversaries to impair security controls.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
3010
Detects instances where users successfully access websites categorized by FortiGuard as 'Artificial Intelligence Technology' without being blocked by the web filtering policy. This rule is intended to support organizational AI governance, data loss prevention, and intellectual property protection policies.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
209
Detects ten or more Microsoft Entra sign-in failures for the same user from the same source IP within a five-minute window, identifying potential password guessing (brute force) activity against a single account.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
307
Detects sign-in activity within Microsoft Entra ID characterized by User-Agent strings indicative of automated tools, command-line HTTP clients, and security testing software. This rule is designed for anomaly detection and necessitates correlation with other context such as source IP, authentication results, and user behavior to identify potential malicious activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
507
Page 1 of 7