
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects attempts to inject malicious JavaScript code via HTTP URI requests. It uses PCRE pattern matching to identify common XSS indicators such as <script> tags, JavaScript event handlers (onerror, onload), and attempts to access document.cookie, which are indicative of stored or reflected Cross-Site Scripting (XSS) attack patterns.
This rule detects large HTTP POST requests (greater than 10MB) originating from the internal network to external destinations, which may indicate bulk data exfiltration.
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) launch suspicious child processes often associated with malicious command execution, such as command shells, scripting interpreters, or system utilities.
Detects the use of BITSAdmin or the PowerShell Start-BitsTransfer cmdlet for downloading files from the internet or local network, often used by attackers to perform ingress tool transfer or to maintain persistence via BITS jobs.
Detects ICMP Type 8 (Echo Request) packets with a payload size exceeding 1000 bytes. This is a common indicator of ICMP tunneling, where attackers encapsulate data within ICMP packets to bypass network security controls for command and control or data exfiltration.
Detects the creation or modification of Power Automate Flows that utilize non-Microsoft domains for HTTP or webhook connectors. Adversaries may abuse Power Automate to automate exfiltration or command-and-control tasks by connecting workflows to external malicious endpoints.
Detects outbound HTTPS traffic on high ports where the TLS SNI header consists of a 8-20 character random alphanumeric string. This pattern is indicative of default configurations for Metasploit Meterpreter Reverse HTTPS payloads attempting to establish a Command and Control connection.
Detects network traffic attempting to exploit the SMBv1 vulnerability (CVE-2017-0144), commonly known as EternalBlue. The rule monitors for specific SMB Trans2 SESSION_SETUP packet structures associated with this remote code execution exploit.
Detects HTTP beaconing activity to a /submit.php URI with a default Cobalt Strike User-Agent string. This is indicative of a default or poorly customized Cobalt Strike malleable C2 profile being used for command and control communication.
Detects outbound HTTPS traffic containing TLS certificates with common names associated with known command-and-control (C2) frameworks like Metasploit and Empire. These frameworks often use self-signed certificates with default or easily identifiable issuer names when establishing C2 communication.
