
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network traffic containing 'Active Setup', 'Installed Components', and 'StubPath' strings, which are indicative of a potential attempt to reference or trigger a malicious StubPath registry key for persistence.
This rule detects potential lateral movement attempts using Windows Remote Management (WinRM) by monitoring for specific WSMan SOAP protocol headers in HTTP traffic. It specifically looks for POST requests to the WSMan endpoint that contain suspicious keywords like 'winrs', 'MSRPC', or 's:Envelope', which are commonly associated with remote command execution via winrs or PSSession.
Detects HTTP traffic where the User-Agent header references Regasm or Regsvcs, which are trusted Windows utilities often abused by attackers to proxy execution of malicious code (Living-off-the-Land Binary technique).
Detects HTTP traffic patterns consistent with data exfiltration to major cloud storage providers (AWS S3, Azure Blob Storage, Google Cloud Storage) using common command-line interface tools like rclone, aws-cli, and AzCopy.
Detects anomalous SMB traffic indicating potential ransomware activity. The rule monitors for file operations associated with known ransomware naming conventions (e.g., README.txt, DECRYPT_INSTRUCTIONS) or common ransomware-related extensions. It uses a threshold to identify high-frequency occurrences within a short timeframe, suggesting bulk file renaming or ransom note creation typical of encryption phases.
This rule detects suspicious HTTP request bodies containing the 'LD_PRELOAD' environment variable assignment, targeting common temporary or writable directories. This behavior is indicative of an attempt to perform dynamic linker hijacking on a Linux system to inject malicious shared libraries into target processes.
Detects outbound HTTP POST requests characterized by a specific URL pattern consisting of two segments of 4-16 alphanumeric characters, typically observed in Emotet C2 traffic. The rule specifically matches requests with a Content-Type header set to application/octet-stream, which is indicative of malicious binary payload transfer or communication.
This rule detects network traffic originating from internal hosts to external destinations consistent with default Cobalt Strike HTTP Beacon communication patterns. It specifically looks for GET requests containing URI paths commonly associated with default Cobalt Strike profiles (ca, submit.php, updates.rss) combined with a specific, hardcoded User-Agent string associated with Cobalt Strike's default configuration.
This rule detects network traffic indicative of the NjRAT (Bladabindi) remote access trojan, specifically identifying its pipe-delimited command-and-control protocol patterns (e.g., '|ll|' or '|kl|').
Detects outbound HTTP POST requests where the Content-Length header indicates a data transfer of 5MB or greater. This pattern is indicative of potential unauthorized data exfiltration over the web protocol.
