avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views

8,664 detections

Detects the transmission of a Metasploit Meterpreter stage over HTTP, identified by an application/octet-stream response containing the DOS MZ header signature.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors for HTTP POST requests containing 'class.module.classLoader', which is a characteristic payload component used to exploit the Spring4Shell vulnerability (CVE-2022-22965) in Spring Framework applications. This vulnerability allows for remote code execution (RCE) by manipulating class loader properties.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects a high frequency of incoming TCP synchronization (SYN) packets on port 3389 (RDP) from a single external source within a short timeframe. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors incoming TCP traffic on port 22 (SSH) and alerts when a single source IP address exhibits an excessive number of authentication attempts within a 60-second window, which is indicative of a brute-force attack against the SSH service.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP requests containing a UNION SELECT pattern in the URI query string, which is a common indicator of a SQL injection attempt aimed at exfiltrating data or manipulating database queries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects inbound HTTP requests containing common Cross-Site Scripting (XSS) patterns, such as the <script> HTML tag or the 'javascript:' URI scheme, which are indicative of attempts to execute arbitrary client-side code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network traffic consistent with the default Cobalt Strike Malleable C2 jQuery profile. The rule monitors for GET requests to the URI '/jquery-3.3.1.min.js' accompanied by a specific 'Accept' HTTP header, which is a known indicator of default Cobalt Strike beacon activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potentially malicious DNS traffic where queries contain exceptionally long, encoded, or randomized subdomains. Attackers often use these patterns to exfiltrate data from a target network, bypassing traditional security controls by encapsulating information within DNS requests (DNS tunneling). The detection looks for DNS queries exceeding 100 bytes in length with specific character patterns indicative of Base64 or similar encoding.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential command and control (C2) beaconing activity using DNS by identifying high-frequency, long, and random subdomain queries. It monitors for DNS requests that exceed 40 bytes in size, feature complex alphanumeric subdomains, and exceed a defined threshold of 10 requests within a 60-second window, which is indicative of DNS tunneling or command-and-control exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects incoming HTTP traffic targeting Apache Struts servers, attempting to exploit CVE-2017-5638 by injecting malicious OGNL (Object-Graph Navigation Language) expressions within the 'Content-Type' header.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001