avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,015 views

8,664 detections

Detects network traffic consistent with the Metasploit Meterpreter reverse HTTPS payload, specifically looking for the default 'CN=metasploit' certificate subject name used by the framework in SSL/TLS handshakes, or connections targeting default Meterpreter ports like 4444.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors for FTP 'STOR' commands followed by large data transfers (exceeding 64KB) initiated from internal hosts to external destinations. This pattern is often indicative of data exfiltration using the File Transfer Protocol (FTP).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors DNS query traffic for unusually long, encoded subdomain labels (50 characters or more). Such patterns are indicative of data exfiltration or command-and-control (C2) communication using DNS tunneling tools like iodine or dnscat2, which encapsulate non-DNS protocols within the DNS query structure to evade network inspection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of the HTTP CONNECT method on non-standard ports (8888, 9999, 4444). The CONNECT method is frequently used by HTTP proxies to establish TCP tunnels; unauthorized use of this method on uncommon ports is a common indicator of protocol tunneling used to bypass network egress filtering or for command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects outbound HTTP POST requests with specific URI patterns (/rob/ or /ins/) that are indicative of TrickBot malware command and control (C2) check-in activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects DNS query traffic where the subdomain label length exceeds 50 characters and contains patterns consistent with Base64 or Hexadecimal encoding. This behavior is indicative of potential data exfiltration or command-and-control communication performed over the DNS protocol by tunneling data within query labels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects ICMP Echo Request (type 8) packets with an unusually large payload (greater than 64 bytes). Such anomalies often indicate that an adversary is using ICMP as a covert channel for command-and-control (C2) communications or data exfiltration, by embedding arbitrary data within the ICMP payload fields.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network traffic associated with PsExec lateral movement activity, specifically looking for the creation of the PSEXESVC named pipe over SMB/ADMIN$ shares, which is commonly used by PsExec to remotely execute services and commands on target systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects outbound HTTPS traffic on high ports where the TLS SNI header consists of a 8-20 character random alphanumeric string. This pattern is indicative of default configurations for Metasploit Meterpreter Reverse HTTPS payloads attempting to establish a Command and Control connection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects HTTP requests containing directory traversal patterns (e.g., ../, %2e%2e/) combined with attempts to access sensitive system files like /etc/passwd, shadow files, or Windows system configuration files (boot.ini, win.ini).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002