avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views

8,664 detections

Detects high-frequency ICMP Echo Requests (Type 8) directed from internal networks to external destinations with oversized payloads (greater than 200 bytes). This pattern is indicative of ICMP tunneling, which is often used by adversaries for covert command-and-control (C2) communications or data exfiltration, bypassing standard filtering or monitoring.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network traffic containing the Java Serialization magic header 'AC ED 00 05'. This sequence is commonly used to initiate Java deserialization attacks, which can lead to remote code execution if the application insecurely deserializes untrusted data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network traffic indicative of the EternalBlue (MS17-010) exploit attempt against SMBv1 services. The rule specifically looks for SMB packets with transaction command patterns associated with this exploit, which was commonly used by the WannaCry ransomware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers for JNDI lookup strings. The rule inspects traffic for malicious patterns like '${jndi:ldap://', '${jndi:rmi://', or '${jndi:dns://', which are used to trigger remote code execution in vulnerable Java applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects repeated SSH connection attempts to a server over a short duration (10+ attempts in 60 seconds), which is characteristic of credential stuffing or brute-force password guessing attacks against the SSH service.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects anomalous ICMP traffic patterns, specifically ICMP Echo Request packets with unusually large payload sizes (dsize > 64) and specific byte signatures consistent with known ICMP tunneling tools such as icmpsh or ptunnel, which are used to establish covert C2 channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects common SQL injection patterns within the HTTP URI query string. The rule monitors established network traffic to web servers and uses regex matching to identify attempts to use SQL keywords like UNION SELECT, OR 1=1 boolean-based attacks, blind SQL injection techniques (sleep/benchmark), and attempts to access information_schema metadata tables.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects multiple TCP connection attempts to port 22 (SSH) from the same source within a 60-second window, which is indicative of a brute-force or password guessing attack against SSH services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects common XSS attack patterns within HTTP URI requests, specifically monitoring for script tags or event handler attributes such as 'onerror' and 'onload' which are used to execute malicious JavaScript in a user's browser.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects outbound HTTP POST requests to external networks that match a known Emotet C2 traffic pattern. The rule specifically looks for HTTP POST requests using an 'application/x-www-form-urlencoded' Content-Type and a URI structure consisting of randomized alphanumeric segments (4-20 characters long). This structure is characteristic of Emotet's communication with its command-and-control infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002