avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views

8,664 detections

This rule detects attempts to inject malicious JavaScript code via HTTP URI requests. It uses PCRE pattern matching to identify common XSS indicators such as <script> tags, JavaScript event handlers (onerror, onload), and attempts to access document.cookie, which are indicative of stored or reflected Cross-Site Scripting (XSS) attack patterns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects large HTTP POST requests (greater than 10MB) originating from the internal network to external destinations, which may indicate bulk data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) launch suspicious child processes often associated with malicious command execution, such as command shells, scripting interpreters, or system utilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the use of BITSAdmin or the PowerShell Start-BitsTransfer cmdlet for downloading files from the internet or local network, often used by attackers to perform ingress tool transfer or to maintain persistence via BITS jobs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects ICMP Type 8 (Echo Request) packets with a payload size exceeding 1000 bytes. This is a common indicator of ICMP tunneling, where attackers encapsulate data within ICMP packets to bypass network security controls for command and control or data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation or modification of Power Automate Flows that utilize non-Microsoft domains for HTTP or webhook connectors. Adversaries may abuse Power Automate to automate exfiltration or command-and-control tasks by connecting workflows to external malicious endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects outbound HTTPS traffic on high ports where the TLS SNI header consists of a 8-20 character random alphanumeric string. This pattern is indicative of default configurations for Metasploit Meterpreter Reverse HTTPS payloads attempting to establish a Command and Control connection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects network traffic attempting to exploit the SMBv1 vulnerability (CVE-2017-0144), commonly known as EternalBlue. The rule monitors for specific SMB Trans2 SESSION_SETUP packet structures associated with this remote code execution exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP beaconing activity to a /submit.php URI with a default Cobalt Strike User-Agent string. This is indicative of a default or poorly customized Cobalt Strike malleable C2 profile being used for command and control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects outbound HTTPS traffic containing TLS certificates with common names associated with known command-and-control (C2) frameworks like Metasploit and Empire. These frameworks often use self-signed certificates with default or easily identifiable issuer names when establishing C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002