
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes281 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Detects multiple Kerberos pre-authentication failures (Event ID 4771) with failure code 0x18, indicating incorrect passwords, originating from the same source address for a specific user account within a ten-minute window, which may suggest brute-force or credential-stuffing activity.
This rule detects potential password spraying activity by monitoring Microsoft Entra sign-in logs for multiple failed authentication attempts originating from the same source IP address targeting ten or more distinct user accounts within a ten-minute time window.
Generic rule content from file: MS_Entra_ID_Protection_Anomalous_Token_Risk.txt
Detects successful Microsoft Entra RoleManagement activity where a member is assigned permanently to a role outside of Privileged Identity Management (PIM). This is flagged as a privileged access risk because it bypasses just-in-time eligibility and activation controls.
Windows AD User Added to Monitored Group
Cortex XDR
Detects Windows Security events (Event IDs 4728 and 4756) where a member is added to a sensitive or privileged Active Directory domain global or universal security group. The rule compares the target group against a locally maintained inventory of monitored groups to identify potential unauthorized privilege escalation or persistence.
Detects modifications to Windows user accounts where the 'Password Never Expires' flag is enabled. This modification, often represented by the DONT_EXPIRE_PASSWORD userAccountControl flag (Event ID 4738), may indicate an attempt to establish persistence or weaken credential lifecycle security by bypassing password rotation requirements.
Detects the execution of the Cortex XDR agent administration tool (Cytool) with the 'protect disable' command line argument. This indicates an attempt to manually disable the security agent's protective features on an endpoint, which is a common technique used by adversaries to impair security controls.
Detects instances where users successfully access websites categorized by FortiGuard as 'Artificial Intelligence Technology' without being blocked by the web filtering policy. This rule is intended to support organizational AI governance, data loss prevention, and intellectual property protection policies.
Detects ten or more Microsoft Entra sign-in failures for the same user from the same source IP within a five-minute window, identifying potential password guessing (brute force) activity against a single account.
Detects sign-in activity within Microsoft Entra ID characterized by User-Agent strings indicative of automated tools, command-line HTTP clients, and security testing software. This rule is designed for anomaly detection and necessitates correlation with other context such as source IP, authentication results, and user behavior to identify potential malicious activity.
Page 1 of 7
