Browse Rules

Search and filter across all detection sources

337 rules

mdecrevoisier high sigma

Account accessed to attributes related to DCshadow

Detects scenarios where an attacker accessed attributes related to DCshadow attack in order to create a fake domain controller.

mdecrevoisier high sigma

Account marked as sensitive and cannot be delegated had its protection removed (weakness introduction)

Detects scenarios where an attacker removes security protection from a sensitive account to escalate privileges

mdecrevoisier medium sigma

Account password set to never expire.

Detects scenarios where an account password is set to never expire.

mdecrevoisier high sigma

Account renamed to admin (or likely) account to evade defense

Detects scenarios where an attacker rename a non admin account in order to evade SOC & operations vigilance

mdecrevoisier high sigma

Account set with Kerberos DES encryption activated (weakness introduction)

Detects scenarios where an attacker set an account with DES Kerberos encryption to perform ticket brutforce.

mdecrevoisier high sigma

Account set with Kerberos pre-authentication not required (AS-REP Roasting)

Detects scenarios where an attacker set an account with Kerberos pre-authentication not required to perform offline brutforce. Account with this status can be checked with the following command > "Get-ADUser -Filter 'useraccountcontrol -band 4194304' -Properties useraccountcontrol".

mdecrevoisier medium sigma

Account set with password not required (weakness introduction)

Detects scenarios where an attacker set an account with password not required to perform privilege escalation attack.

mdecrevoisier high sigma

Account set with reversible encryption (weakness introduction)

Detects scenarios where an attacker set an account with reversible encryption to facilitate brutforce or cracking operations.

mdecrevoisier high sigma

Active Directory federated trust added

Detects scenarios where an federated trust is added by an attacker.

mdecrevoisier medium sigma

Active Directory Forest PowerShell class called from a non administrative host

Detects scenarios where an attacker attempts to call the Active Directory Forest PowerShell class on a non administrative host in order to enumerate trusts, forests, domains, sites and subnet information.

mdecrevoisier high sigma

Active Directory honeypot enumerated by a suspicious host (Bloodhound)

Detects scenarios where an attacker is attempting to discover sensitive accounts using tools like Bloodhound. To find out the source of the enumeration, correlate the SubjectLogonId from ID 4662 with TargetLogonId from ID 4624.

mdecrevoisier high sigma

Active Directory honeypot used for lateral movement

Detects scenarios where an attacker is using

mdecrevoisier medium sigma

Active Directory PowerShell module called from a non administrative host

Detects scenarios where an attacker attempts to load the Active Directory PowerShell module on a non administrative host in order to enumerate users, groups, ... Also note that no user information is reported by this event ID and that some correation would be required.

mdecrevoisier high sigma

Administrator login impersonation with forged Golden ticket

Detects scenarios where an attacker used a forged Golden ticket to login on a remote host. Per default or if specified, the ticket will be forged using the builtin administrator account (SID *-500). However, and it frequent cases, a non suspicious user name will be specificied during the forge in order to evade security monitoring. The rule works based on this trick.

mdecrevoisier high sigma

AdminSDHolder permissions changed for persistence

Detects scenarios where an attacker changes permissions on the AdminSDHolder container to establish persistence.

mdecrevoisier high sigma

Anonymous access performed to multiple targets

Detects scenarios where an attacker would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.

mdecrevoisier high sigma

Anonymous login (RottenPotatoNG)

Detects scenarios where an attacker abuse RPC, NTLM relay and others components to escalate privileges.

mdecrevoisier high sigma

Audit policy disabled by command line

Detects scenarios where an attacker attempts to disbale or clear the audit policy for defense evasion purposes.

mdecrevoisier high sigma

Audit policy disabled by command line

Detects scenarios where an attacker attempts disbaled the audit policy for defense evasion purposes.

mdecrevoisier high sigma

Audit policy enumerated

Detects scenarios where an attacker attempts enumerate the audit policy in place.

mdecrevoisier high sigma

Azure Active Directory Connect credentials dump via network share

Detects scenarios where an attacker attempt to dump Azure Active Directory Connect credentials via network share.

mdecrevoisier high sigma

Azure Windows virtual machine login via serial console

Detects if an attacker logs on using the serial console.

mdecrevoisier high sigma

Backdoor introduction via registry permission change through WMI (DAMP)

Detects scenarios where an attacker modifies registry permissions on a local or remote target in order to introduce a backdoor and dump hashes and credentials.

mdecrevoisier high sigma

BitLocker feature activation on multiple hosts (native)

Detects scenarios where an attacker enable or reconfigure BitLocker on multiple hosts for ransomware purposes.

mdecrevoisier high sigma

BitLocker feature configuration (Reg via command)

Detects scenarios where an attacker configures BitLocker for ransomware purposes.