
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,015 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network traffic consistent with the Metasploit Meterpreter reverse HTTPS payload, specifically looking for the default 'CN=metasploit' certificate subject name used by the framework in SSL/TLS handshakes, or connections targeting default Meterpreter ports like 4444.
This rule monitors for FTP 'STOR' commands followed by large data transfers (exceeding 64KB) initiated from internal hosts to external destinations. This pattern is often indicative of data exfiltration using the File Transfer Protocol (FTP).
This rule monitors DNS query traffic for unusually long, encoded subdomain labels (50 characters or more). Such patterns are indicative of data exfiltration or command-and-control (C2) communication using DNS tunneling tools like iodine or dnscat2, which encapsulate non-DNS protocols within the DNS query structure to evade network inspection.
Detects the use of the HTTP CONNECT method on non-standard ports (8888, 9999, 4444). The CONNECT method is frequently used by HTTP proxies to establish TCP tunnels; unauthorized use of this method on uncommon ports is a common indicator of protocol tunneling used to bypass network egress filtering or for command and control (C2) communication.
Detects outbound HTTP POST requests with specific URI patterns (/rob/ or /ins/) that are indicative of TrickBot malware command and control (C2) check-in activity.
Detects DNS query traffic where the subdomain label length exceeds 50 characters and contains patterns consistent with Base64 or Hexadecimal encoding. This behavior is indicative of potential data exfiltration or command-and-control communication performed over the DNS protocol by tunneling data within query labels.
This rule detects ICMP Echo Request (type 8) packets with an unusually large payload (greater than 64 bytes). Such anomalies often indicate that an adversary is using ICMP as a covert channel for command-and-control (C2) communications or data exfiltration, by embedding arbitrary data within the ICMP payload fields.
Detects network traffic associated with PsExec lateral movement activity, specifically looking for the creation of the PSEXESVC named pipe over SMB/ADMIN$ shares, which is commonly used by PsExec to remotely execute services and commands on target systems.
Detects outbound HTTPS traffic on high ports where the TLS SNI header consists of a 8-20 character random alphanumeric string. This pattern is indicative of default configurations for Metasploit Meterpreter Reverse HTTPS payloads attempting to establish a Command and Control connection.
Detects HTTP requests containing directory traversal patterns (e.g., ../, %2e%2e/) combined with attempts to access sensitive system files like /etc/passwd, shadow files, or Windows system configuration files (boot.ini, win.ini).
