
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,015 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the use of the 'msiexec.exe' utility to fetch and potentially execute an '.msi' installer package directly from a remote source via HTTP. This behavior is a known technique for bypassing application control by abusing a signed system binary to download and install malicious packages.
This rule detects DNS queries containing an exceptionally long subdomain label (50 or more characters). Such patterns are often indicative of DNS tunneling techniques where data is encoded within the subdomain portion of a DNS query to bypass network security controls or establish command-and-control channels.
This rule detects HTTP directory traversal attempts by inspecting incoming URI requests for common path traversal sequences such as '../', '..%2F', '..%2f', '..%5C', or '..%5c'. Attackers use these sequences to escape the web root directory and access unauthorized files on the server.
Detects classic SQL injection attack patterns within incoming HTTP requests, such as UNION SELECT statements, boolean-based tautologies (1=1), table dropping commands, or common URL-encoded quote characters.
Detects multiple failed SSH authentication attempts against a server from a single source within a short timeframe, which is indicative of a brute force password attack.
Detects incoming HTTP POST requests directed at PHP, ASPX, or JSP files that contain suspicious command execution patterns (such as cmd=, exec=, system(, or eval()). This behavior is highly indicative of an attacker interacting with a web shell to execute unauthorized commands on the server.
This rule detects outgoing TCP traffic that initiates a SOCKS5 handshake (indicated by the byte sequence |05 01 00|) on destination ports other than standard web ports (80, 443, 8080, 8443). This behavior is characteristic of TOR client traffic attempting to establish an anonymous connection to an external TOR relay or node via non-standard network ports.
This rule detects outbound FTP traffic containing the 'STOR' command, which is used in the FTP protocol to upload files to a remote server. This behavior is a common indicator of unauthorized data exfiltration.
Detects the presence of the 'PSEXESVC' named pipe activity over SMB, which is a hallmark indicator of the PsExec tool being used to facilitate remote execution and lateral movement.
Detects DNS queries containing unusually long subdomains (50+ characters) encoded in Base64, which is a common technique used for command-and-control (C2) communication or data exfiltration via DNS tunneling.
