
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of the FTP STOR command to transfer files with sensitive extensions (.docx, .pdf, .xlsx, .zip, .7z) to external networks. This behavior is indicative of potential data exfiltration via an unencrypted alternative protocol.
Detects high-volume, established TLS connections to common public DNS-over-HTTPS (DoH) providers (Google, Cloudflare, OpenDNS). Persistent high-frequency connections to these resolvers can be indicative of DNS tunneling, where an adversary encapsulates command-and-control or data exfiltration traffic within encrypted DNS queries to bypass network monitoring.
Detects HTTP GET requests originating from internal network hosts to external destinations that match known Emotet C2 communication patterns, specifically those using hardcoded URI paths such as '/wp-content/', '/wp-admin/', or '/tmp/' combined with the 'Accept-Encoding: identity' header.
Detects a high frequency of incoming TCP SYN packets targeting port 3389 (RDP) from a single source within a short time window. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
Detects outbound HTTPS traffic on non-standard ports that matches a specific JA3 fingerprint associated with the Sliver command and control framework. This indicates potential beaconing or C2 communication from a compromised host.
Detects HTTP POST requests characteristic of QakBot command-and-control check-ins. The rule looks for an 'established' flow to an external network using a POST method, with a request body containing 'qbot' followed by a version string pattern, which is indicative of the malware reporting system info to its C2 server.
Detects outbound HTTP POST requests where the Content-Length is at least 10MB and the Content-Type header indicates the transfer of archived data (zip or x-tar). This pattern is often associated with the staging and exfiltration of compressed sensitive data from an internal host to an external network destination.
Detects HTTP requests attempting to access sensitive internal IP addresses (RFC-1918) or cloud metadata services (e.g., 169.254.169.254) which are common indicators of Server-Side Request Forgery (SSRF) exploitation attempts.
This rule detects potential command and control (C2) beaconing activity using DNS by identifying high-frequency, long, and random subdomain queries. It monitors for DNS requests that exceed 40 bytes in size, feature complex alphanumeric subdomains, and exceed a defined threshold of 10 requests within a 60-second window, which is indicative of DNS tunneling or command-and-control exfiltration.
This rule detects network traffic indicative of PsExec lateral movement, specifically identifying the authentication or access to the hidden 'ADMIN$' network share followed by the transfer or execution of the 'PSEXESVC' service binary, a hallmark of the PsExec tool.
