
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the transmission of a Metasploit Meterpreter stage over HTTP, identified by an application/octet-stream response containing the DOS MZ header signature.
This rule monitors for HTTP POST requests containing 'class.module.classLoader', which is a characteristic payload component used to exploit the Spring4Shell vulnerability (CVE-2022-22965) in Spring Framework applications. This vulnerability allows for remote code execution (RCE) by manipulating class loader properties.
This rule detects a high frequency of incoming TCP synchronization (SYN) packets on port 3389 (RDP) from a single external source within a short timeframe. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
This rule monitors incoming TCP traffic on port 22 (SSH) and alerts when a single source IP address exhibits an excessive number of authentication attempts within a 60-second window, which is indicative of a brute-force attack against the SSH service.
Detects HTTP requests containing a UNION SELECT pattern in the URI query string, which is a common indicator of a SQL injection attempt aimed at exfiltrating data or manipulating database queries.
Detects inbound HTTP requests containing common Cross-Site Scripting (XSS) patterns, such as the <script> HTML tag or the 'javascript:' URI scheme, which are indicative of attempts to execute arbitrary client-side code.
Detects network traffic consistent with the default Cobalt Strike Malleable C2 jQuery profile. The rule monitors for GET requests to the URI '/jquery-3.3.1.min.js' accompanied by a specific 'Accept' HTTP header, which is a known indicator of default Cobalt Strike beacon activity.
This rule detects potentially malicious DNS traffic where queries contain exceptionally long, encoded, or randomized subdomains. Attackers often use these patterns to exfiltrate data from a target network, bypassing traditional security controls by encapsulating information within DNS requests (DNS tunneling). The detection looks for DNS queries exceeding 100 bytes in length with specific character patterns indicative of Base64 or similar encoding.
This rule detects potential command and control (C2) beaconing activity using DNS by identifying high-frequency, long, and random subdomain queries. It monitors for DNS requests that exceed 40 bytes in size, feature complex alphanumeric subdomains, and exceed a defined threshold of 10 requests within a 60-second window, which is indicative of DNS tunneling or command-and-control exfiltration.
Detects incoming HTTP traffic targeting Apache Struts servers, attempting to exploit CVE-2017-5638 by injecting malicious OGNL (Object-Graph Navigation Language) expressions within the 'Content-Type' header.
