
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects attempts to perform Local File Inclusion (LFI) via path traversal sequences (../) in HTTP URIs, specifically targeting sensitive files like /etc/passwd or windows/win.ini.
Detects attempts to exploit the ProxyShell vulnerability (CVE-2021-34473) in Microsoft Exchange servers. The rule identifies malicious path traversal sequences, specifically utilizing encoding techniques like double URL encoding (%25) or dot-dot-slash characters within requests to the Autodiscover service, aimed at bypassing security controls.
This rule detects HTTP requests attempting to perform Local File Inclusion (LFI) or path traversal attacks by searching for patterns such as '/../' sequences and common sensitive file paths like /etc/passwd, /etc/shadow, or /proc/self/environ in the URI.
This rule monitors incoming HTTP requests for classic SQL injection patterns, such as UNION SELECT, SLEEP, BENCHMARK, and various SQL commands like DROP or ALTER. These signatures are commonly associated with attempts to gain unauthorized access to database contents, exfiltrate data, or compromise the database integrity via web applications.
Detects outbound HTTP POST requests to suspicious URIs and subsequent inbound responses containing executable binary (PE) signatures, characteristic of Emotet malware command-and-control (C2) activity.
This rule detects multiple Network Level Authentication (NLA) negotiation attempts targeting port 3389 from a single source within a 60-second window, which is indicative of an RDP brute-force attack.
Detects remote execution of WMI commands over DCOM by identifying the specific IWbemServices UUID (8BC3F05E-D86B-11D0-A075-00C04FB68820) in RPC traffic. The rule triggers on inbound TCP traffic on port 135 where the payload size exceeds 500 bytes, which is consistent with the initiation of WMI remote process creation.
Detects HTTP traffic patterns characteristic of Emotet malware command and control (C2) beaconing, specifically looking for POST requests with random alphanumeric URIs (4-16 characters) and a specific Accept-Encoding header (gzip, deflate).
Detects common SQL injection attack patterns within HTTP URI or POST body traffic, such as UNION SELECT, tautologies (e.g., OR 1=1), schema enumeration, and database functions like benchmark or sleep.
This rule detects potential command and control (C2) activity leveraging DNS tunneling. It identifies high-frequency DNS queries that contain unusually long subdomain labels (51 characters or more), which is a common technique used to encode data or commands within DNS protocol traffic to bypass network security controls.
