avatar

Lucas Pinho

@lucaslapinho
Completionist
0 followers9 downloads111 copies0 likes282 views

62 detections

Detects sign-in activity within Microsoft Entra ID characterized by User-Agent strings indicative of automated tools, command-line HTTP clients, and security testing software. This rule is designed for anomaly detection and necessitates correlation with other context such as source IP, authentication results, and user behavior to identify potential malicious activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
507
Detects five or more distinct Windows user-account disable events (Event ID 4725) performed by the same actor on the same host within a one-hour time bucket, which may indicate unauthorized account access removal.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
107
Detects instances where a non-root user process launches 'su' or a shell command executing 'su' from an unusual parent process (excluding standard shells like bash/sh/zsh/ksh or elevation tools like sudo/su). This is used to identify suspicious attempts to switch user context or escalate privileges.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
207
Detects network traffic identified by FortiGate as Remote Desktop Protocol (RDP) that has been explicitly permitted (Accept action) by the firewall policy. This rule monitors for successful packet flow through the firewall, providing visibility into potential lateral movement paths via RDP.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
007
Detects completed administrative actions within the Cortex management console that result in a pause of endpoint protection. This action reduces security coverage on the targeted host and requires validation to ensure it aligns with authorized maintenance, troubleshooting, or incident response activities.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
807
Detects the creation of a new role-based access control (RBAC) role within the Cortex management plane. This activity is significant as new roles can define access to sensitive administrative and security capabilities and should be reviewed to ensure alignment with least-privilege principles and authorized access-management requirements.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
007
Detects Microsoft Entra ID Protection risk telemetry for sign-ins with unfamiliar properties. Microsoft evaluates characteristics such as ASN, browser, device, and location against the user's historical behavior to identify anomalous sign-ins that may warrant investigation.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
306
Detects a user-session window titled 'Password Input' associated with PowerShell, PowerShell Core, or PowerShell ISE processes. This technique may be used for GUI-based credential capture or social engineering.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
206
Detects the creation of a new Group Policy Object (GPO) in Active Directory by monitoring Windows Security Event ID 5137 where the object class is 'groupPolicyContainer'. While typically an administrative task, the creation of new GPOs can be a precursor to malicious configuration changes or domain persistence via Group Policy modification.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
006
Detects five or more distinct Windows user-account deletion events (Event ID 4726) performed by the same actor on the same host within a one-hour time window, which may indicate unauthorized account access removal or malicious impact activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
406
Page 2 of 7