avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views

8,664 detections

Detects the use of the FTP STOR command to transfer files with sensitive extensions (.docx, .pdf, .xlsx, .zip, .7z) to external networks. This behavior is indicative of potential data exfiltration via an unencrypted alternative protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-volume, established TLS connections to common public DNS-over-HTTPS (DoH) providers (Google, Cloudflare, OpenDNS). Persistent high-frequency connections to these resolvers can be indicative of DNS tunneling, where an adversary encapsulates command-and-control or data exfiltration traffic within encrypted DNS queries to bypass network monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP GET requests originating from internal network hosts to external destinations that match known Emotet C2 communication patterns, specifically those using hardcoded URI paths such as '/wp-content/', '/wp-admin/', or '/tmp/' combined with the 'Accept-Encoding: identity' header.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects a high frequency of incoming TCP SYN packets targeting port 3389 (RDP) from a single source within a short time window. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects outbound HTTPS traffic on non-standard ports that matches a specific JA3 fingerprint associated with the Sliver command and control framework. This indicates potential beaconing or C2 communication from a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP POST requests characteristic of QakBot command-and-control check-ins. The rule looks for an 'established' flow to an external network using a POST method, with a request body containing 'qbot' followed by a version string pattern, which is indicative of the malware reporting system info to its C2 server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects outbound HTTP POST requests where the Content-Length is at least 10MB and the Content-Type header indicates the transfer of archived data (zip or x-tar). This pattern is often associated with the staging and exfiltration of compressed sensitive data from an internal host to an external network destination.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP requests attempting to access sensitive internal IP addresses (RFC-1918) or cloud metadata services (e.g., 169.254.169.254) which are common indicators of Server-Side Request Forgery (SSRF) exploitation attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential command and control (C2) beaconing activity using DNS by identifying high-frequency, long, and random subdomain queries. It monitors for DNS requests that exceed 40 bytes in size, feature complex alphanumeric subdomains, and exceed a defined threshold of 10 requests within a 60-second window, which is indicative of DNS tunneling or command-and-control exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects network traffic indicative of PsExec lateral movement, specifically identifying the authentication or access to the hidden 'ADMIN$' network share followed by the transfer or execution of the 'PSEXESVC' service binary, a hallmark of the PsExec tool.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002