
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,957 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects repeated use of the FTP 'STOR' command to transmit data to an external host within a short timeframe. The STOR command is used in the File Transfer Protocol (FTP) to upload a file to the server. An unusual frequency of this command toward external destinations may indicate data exfiltration.
Detects incoming HTTP traffic attempting to exploit the Apache Struts2 vulnerability CVE-2017-5638. The rule monitors the Content-Type HTTP header for OGNL (Object-Graph Navigation Language) expressions containing known exploitation markers like ClassLoader, getRuntime, or .exec(), which indicate an attempt to achieve Remote Code Execution (RCE).
This rule detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers (User-Agent, X-Forwarded-For, Referer) for JNDI lookup strings. The JNDI lookup mechanism in vulnerable Log4j libraries allows an attacker to execute arbitrary code by pointing the lookup to a malicious LDAP, RMI, or DNS server.
This rule detects potential lateral movement attempts using DCOM-based WMI calls to the remote OXID Resolver on port 135. Attackers often abuse DCOM to remotely trigger WMI methods, enabling remote code execution, discovery, or other malicious activities. The rule triggers on the characteristic DCOM OXID Resolve packet structure associated with this activity.
This rule detects ICMP Echo Request (type 8) packets with an unusually large payload (greater than 64 bytes). Such anomalies often indicate that an adversary is using ICMP as a covert channel for command-and-control (C2) communications or data exfiltration, by embedding arbitrary data within the ICMP payload fields.
Detects attempts to exploit the Shellshock vulnerability (CVE-2014-6271) by inspecting HTTP request headers for the characteristic function definition syntax '() { :;'. This pattern is commonly used in malicious payloads to trigger command execution via environment variables in CGI scripts.
Detects multiple TCP connection attempts to port 22 (SSH) from the same source within a 60-second window, which is indicative of a brute-force or password guessing attack against SSH services.
Detects attempts to perform Local File Inclusion (LFI) via path traversal sequences (../) in HTTP URIs, specifically targeting sensitive files like /etc/passwd or windows/win.ini.
Detects Server-Side Request Forgery (SSRF) attempts targeting Microsoft Exchange via the /autodiscover/ endpoint. The attack leverages a specifically crafted X-BEResource header containing an internal IP address, which is indicative of the CVE-2021-26855 vulnerability used in ProxyLogon exploitation.
This rule detects SMB traffic indicative of remote service creation over the SVCCTL named pipe, a pattern characteristic of tools like PsExec used for lateral movement and remote code execution.
