avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,964 views

8,664 detections

Detects remote attempts to stop sensitive security, database, and system services using the SMB SVCCTL (Service Control Manager) interface. This is often associated with adversary attempts to disable defensive tools or prepare for destructive operations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects remote system shutdown attempts initiated via the MSRPC winreg named pipe over SMB. This behavior is indicative of an attacker attempting to shut down or reboot a target system remotely to interrupt availability, often as a prelude to or consequence of destructive actions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects rapid, successive TCP connection attempts directed to port 3389 (RDP) from a single external source IP within a short timeframe. This behavior is indicative of a brute force attack or automated credential guessing activity targeting remote desktop services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects HTTP POST requests containing a Content-Length header value indicating a body size exceeding 10MB. Large POST requests may indicate data exfiltration, large file uploads, or misuse of HTTP channels for data transfer to external destinations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects HTTP traffic containing a specific session cookie pattern characteristic of PowerShell Empire C2 agent communication, utilizing regex to identify base64-encoded session identifiers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects repeated inbound TCP connection attempts to port 3389 (RDP) from a single source address within a short timeframe. This behavior is indicative of an RDP brute-force or password spraying attack targeting remote desktop services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects outbound FTP STOR (Store) commands directed to external networks. This indicates that a host inside the local network is attempting to upload data to an external server. The rule uses a threshold to filter out isolated commands, triggering when 3 or more STOR commands are detected within 120 seconds, which is characteristic of data exfiltration or staging behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential DNS exfiltration attempts by identifying DNS queries containing high-entropy subdomains of 51 characters or more, encoded in Base64. Adversaries may use long, encoded subdomains to tunnel data out of a network through the DNS protocol, bypassing traditional security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects high-frequency DNS query patterns characterized by long, potentially encoded, subdomain labels (exceeding 40 characters) that are indicative of DNS-based command and control (C2) beaconing activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects outbound ICMP Type 8 (Echo Request) packets that contain an abnormally large payload (greater than 64 bytes). This behavior is characteristic of ICMP tunneling, where attackers encapsulate data within the payload of ICMP packets to bypass network security controls or establish covert command and control communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103