avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,957 views

8,664 detections

Detects repeated use of the FTP 'STOR' command to transmit data to an external host within a short timeframe. The STOR command is used in the File Transfer Protocol (FTP) to upload a file to the server. An unusual frequency of this command toward external destinations may indicate data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects incoming HTTP traffic attempting to exploit the Apache Struts2 vulnerability CVE-2017-5638. The rule monitors the Content-Type HTTP header for OGNL (Object-Graph Navigation Language) expressions containing known exploitation markers like ClassLoader, getRuntime, or .exec(), which indicate an attempt to achieve Remote Code Execution (RCE).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers (User-Agent, X-Forwarded-For, Referer) for JNDI lookup strings. The JNDI lookup mechanism in vulnerable Log4j libraries allows an attacker to execute arbitrary code by pointing the lookup to a malicious LDAP, RMI, or DNS server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects potential lateral movement attempts using DCOM-based WMI calls to the remote OXID Resolver on port 135. Attackers often abuse DCOM to remotely trigger WMI methods, enabling remote code execution, discovery, or other malicious activities. The rule triggers on the characteristic DCOM OXID Resolve packet structure associated with this activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects ICMP Echo Request (type 8) packets with an unusually large payload (greater than 64 bytes). Such anomalies often indicate that an adversary is using ICMP as a covert channel for command-and-control (C2) communications or data exfiltration, by embedding arbitrary data within the ICMP payload fields.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to exploit the Shellshock vulnerability (CVE-2014-6271) by inspecting HTTP request headers for the characteristic function definition syntax '() { :;'. This pattern is commonly used in malicious payloads to trigger command execution via environment variables in CGI scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects multiple TCP connection attempts to port 22 (SSH) from the same source within a 60-second window, which is indicative of a brute-force or password guessing attack against SSH services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to perform Local File Inclusion (LFI) via path traversal sequences (../) in HTTP URIs, specifically targeting sensitive files like /etc/passwd or windows/win.ini.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects Server-Side Request Forgery (SSRF) attempts targeting Microsoft Exchange via the /autodiscover/ endpoint. The attack leverages a specifically crafted X-BEResource header containing an internal IP address, which is indicative of the CVE-2021-26855 vulnerability used in ProxyLogon exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects SMB traffic indicative of remote service creation over the SVCCTL named pipe, a pattern characteristic of tools like PsExec used for lateral movement and remote code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003