avatar

Lucas Pinho

@lucaslapinho
Completionist
0 followers9 downloads111 copies0 likes282 views

62 detections

Detects five or more distinct Windows user-account creation events (Event ID 4720) associated with the same actor and host within a one-hour time bucket, which may indicate unauthorized account creation for persistence or mass provisioning.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
806
Detects the creation of a new locally defined user account on a FortiGate device by monitoring configuration change logs. Unauthorized local accounts can be used to establish persistent, unauthorized access to network infrastructure.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
106
Detects a successful Microsoft Entra audit event where a new partner tenant is added to cross-tenant access settings. This change impacts trust-related configuration and inter-tenant access policies, requiring validation against approved organizational changes.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
105
Detects successful creation of a new application registration in Microsoft Entra ID. Application creation is common in development and integration workflows, but unexpected registrations should be reviewed because later credential or permission grants can turn an application into a persistence or privilege path.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
205
Detects coordinated activity where a PowerShell process executes multiple distinct administrative utilities (such as wevtutil, vssadmin, wbadmin, or bcdedit) to perform destructive actions like clearing event logs, deleting shadow copies, or disabling system recovery settings. This rule uses correlation to identify sequences of at least three distinct commands and utilities, reducing false positives associated with single administrative tasks.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
005
Detects FortiGate devices whose average reported CPU utilization exceeds 90 percent during the correlation window. Sustained CPU pressure can degrade firewall throughput, session establishment, inspection performance, and management responsiveness and should be investigated as a device-health condition.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
105
Detects instances where FortiGate network security appliances report sustained high memory utilization exceeding a defined threshold. Elevated memory usage may indicate performance degradation, excessive traffic volume, or resource-intensive configuration, and can precede entering FortiOS conserve mode.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
205
Detects the execution of Windows processes where the file's web-origin metadata (Mark-of-the-Web) contains a referrer URL pointing to the public GitHub Desktop repository. This rule serves as a provenance and threat hunting signal to track the origin of binaries executed in the environment, identifying software potentially derived from this specific source repository.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
004
Detects audit events in Imperva Cloud WAF where SSL/TLS configuration has been explicitly removed from a protected site. This change impacts the security posture of HTTPS delivery and requires validation to ensure it was an authorized administrative action.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
004
Detects successful SSH authentication to a Linux system using public-key authentication by monitoring system logs for the 'Accepted publickey for' message. This rule identifies remote access attempts and serves as a foundation for monitoring lateral movement via SSH.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
104
Page 3 of 7