avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views

8,664 detections

Detects attempts to perform Local File Inclusion (LFI) via path traversal sequences (../) in HTTP URIs, specifically targeting sensitive files like /etc/passwd or windows/win.ini.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects attempts to exploit the ProxyShell vulnerability (CVE-2021-34473) in Microsoft Exchange servers. The rule identifies malicious path traversal sequences, specifically utilizing encoding techniques like double URL encoding (%25) or dot-dot-slash characters within requests to the Autodiscover service, aimed at bypassing security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects HTTP requests attempting to perform Local File Inclusion (LFI) or path traversal attacks by searching for patterns such as '/../' sequences and common sensitive file paths like /etc/passwd, /etc/shadow, or /proc/self/environ in the URI.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule monitors incoming HTTP requests for classic SQL injection patterns, such as UNION SELECT, SLEEP, BENCHMARK, and various SQL commands like DROP or ALTER. These signatures are commonly associated with attempts to gain unauthorized access to database contents, exfiltrate data, or compromise the database integrity via web applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects outbound HTTP POST requests to suspicious URIs and subsequent inbound responses containing executable binary (PE) signatures, characteristic of Emotet malware command-and-control (C2) activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects multiple Network Level Authentication (NLA) negotiation attempts targeting port 3389 from a single source within a 60-second window, which is indicative of an RDP brute-force attack.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects remote execution of WMI commands over DCOM by identifying the specific IWbemServices UUID (8BC3F05E-D86B-11D0-A075-00C04FB68820) in RPC traffic. The rule triggers on inbound TCP traffic on port 135 where the payload size exceeds 500 bytes, which is consistent with the initiation of WMI remote process creation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects HTTP traffic patterns characteristic of Emotet malware command and control (C2) beaconing, specifically looking for POST requests with random alphanumeric URIs (4-16 characters) and a specific Accept-Encoding header (gzip, deflate).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects common SQL injection attack patterns within HTTP URI or POST body traffic, such as UNION SELECT, tautologies (e.g., OR 1=1), schema enumeration, and database functions like benchmark or sleep.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential command and control (C2) activity leveraging DNS tunneling. It identifies high-frequency DNS queries that contain unusually long subdomain labels (51 characters or more), which is a common technique used to encode data or commands within DNS protocol traffic to bypass network security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003