avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views

8,664 detections

Detects network traffic containing 'Active Setup', 'Installed Components', and 'StubPath' strings, which are indicative of a potential attempt to reference or trigger a malicious StubPath registry key for persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential lateral movement attempts using Windows Remote Management (WinRM) by monitoring for specific WSMan SOAP protocol headers in HTTP traffic. It specifically looks for POST requests to the WSMan endpoint that contain suspicious keywords like 'winrs', 'MSRPC', or 's:Envelope', which are commonly associated with remote command execution via winrs or PSSession.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP traffic where the User-Agent header references Regasm or Regsvcs, which are trusted Windows utilities often abused by attackers to proxy execution of malicious code (Living-off-the-Land Binary technique).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP traffic patterns consistent with data exfiltration to major cloud storage providers (AWS S3, Azure Blob Storage, Google Cloud Storage) using common command-line interface tools like rclone, aws-cli, and AzCopy.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects anomalous SMB traffic indicating potential ransomware activity. The rule monitors for file operations associated with known ransomware naming conventions (e.g., README.txt, DECRYPT_INSTRUCTIONS) or common ransomware-related extensions. It uses a threshold to identify high-frequency occurrences within a short timeframe, suggesting bulk file renaming or ransom note creation typical of encryption phases.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious HTTP request bodies containing the 'LD_PRELOAD' environment variable assignment, targeting common temporary or writable directories. This behavior is indicative of an attempt to perform dynamic linker hijacking on a Linux system to inject malicious shared libraries into target processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound HTTP POST requests characterized by a specific URL pattern consisting of two segments of 4-16 alphanumeric characters, typically observed in Emotet C2 traffic. The rule specifically matches requests with a Content-Type header set to application/octet-stream, which is indicative of malicious binary payload transfer or communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects network traffic originating from internal hosts to external destinations consistent with default Cobalt Strike HTTP Beacon communication patterns. It specifically looks for GET requests containing URI paths commonly associated with default Cobalt Strike profiles (ca, submit.php, updates.rss) combined with a specific, hardcoded User-Agent string associated with Cobalt Strike's default configuration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects network traffic indicative of the NjRAT (Bladabindi) remote access trojan, specifically identifying its pipe-delimited command-and-control protocol patterns (e.g., '|ll|' or '|kl|').
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound HTTP POST requests where the Content-Length header indicates a data transfer of 5MB or greater. This pattern is indicative of potential unauthorized data exfiltration over the web protocol.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001