avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,015 views

8,664 detections

This rule detects the use of the 'msiexec.exe' utility to fetch and potentially execute an '.msi' installer package directly from a remote source via HTTP. This behavior is a known technique for bypassing application control by abusing a signed system binary to download and install malicious packages.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects DNS queries containing an exceptionally long subdomain label (50 or more characters). Such patterns are often indicative of DNS tunneling techniques where data is encoded within the subdomain portion of a DNS query to bypass network security controls or establish command-and-control channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects HTTP directory traversal attempts by inspecting incoming URI requests for common path traversal sequences such as '../', '..%2F', '..%2f', '..%5C', or '..%5c'. Attackers use these sequences to escape the web root directory and access unauthorized files on the server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects classic SQL injection attack patterns within incoming HTTP requests, such as UNION SELECT statements, boolean-based tautologies (1=1), table dropping commands, or common URL-encoded quote characters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects multiple failed SSH authentication attempts against a server from a single source within a short timeframe, which is indicative of a brute force password attack.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects incoming HTTP POST requests directed at PHP, ASPX, or JSP files that contain suspicious command execution patterns (such as cmd=, exec=, system(, or eval()). This behavior is highly indicative of an attacker interacting with a web shell to execute unauthorized commands on the server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects outgoing TCP traffic that initiates a SOCKS5 handshake (indicated by the byte sequence |05 01 00|) on destination ports other than standard web ports (80, 443, 8080, 8443). This behavior is characteristic of TOR client traffic attempting to establish an anonymous connection to an external TOR relay or node via non-standard network ports.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects outbound FTP traffic containing the 'STOR' command, which is used in the FTP protocol to upload files to a remote server. This behavior is a common indicator of unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the presence of the 'PSEXESVC' named pipe activity over SMB, which is a hallmark indicator of the PsExec tool being used to facilitate remote execution and lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects DNS queries containing unusually long subdomains (50+ characters) encoded in Base64, which is a common technique used for command-and-control (C2) communication or data exfiltration via DNS tunneling.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002