
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,964 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects remote attempts to stop sensitive security, database, and system services using the SMB SVCCTL (Service Control Manager) interface. This is often associated with adversary attempts to disable defensive tools or prepare for destructive operations.
Detects remote system shutdown attempts initiated via the MSRPC winreg named pipe over SMB. This behavior is indicative of an attacker attempting to shut down or reboot a target system remotely to interrupt availability, often as a prelude to or consequence of destructive actions.
This rule detects rapid, successive TCP connection attempts directed to port 3389 (RDP) from a single external source IP within a short timeframe. This behavior is indicative of a brute force attack or automated credential guessing activity targeting remote desktop services.
This rule detects HTTP POST requests containing a Content-Length header value indicating a body size exceeding 10MB. Large POST requests may indicate data exfiltration, large file uploads, or misuse of HTTP channels for data transfer to external destinations.
Detects HTTP traffic containing a specific session cookie pattern characteristic of PowerShell Empire C2 agent communication, utilizing regex to identify base64-encoded session identifiers.
Detects repeated inbound TCP connection attempts to port 3389 (RDP) from a single source address within a short timeframe. This behavior is indicative of an RDP brute-force or password spraying attack targeting remote desktop services.
Detects outbound FTP STOR (Store) commands directed to external networks. This indicates that a host inside the local network is attempting to upload data to an external server. The rule uses a threshold to filter out isolated commands, triggering when 3 or more STOR commands are detected within 120 seconds, which is characteristic of data exfiltration or staging behavior.
This rule detects potential DNS exfiltration attempts by identifying DNS queries containing high-entropy subdomains of 51 characters or more, encoded in Base64. Adversaries may use long, encoded subdomains to tunnel data out of a network through the DNS protocol, bypassing traditional security controls.
Detects high-frequency DNS query patterns characterized by long, potentially encoded, subdomain labels (exceeding 40 characters) that are indicative of DNS-based command and control (C2) beaconing activity.
Detects outbound ICMP Type 8 (Echo Request) packets that contain an abnormally large payload (greater than 64 bytes). This behavior is characteristic of ICMP tunneling, where attackers encapsulate data within the payload of ICMP packets to bypass network security controls or establish covert command and control communication.
