
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,120 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects attempts to perform directory traversal attacks by monitoring incoming HTTP requests for repetitive directory navigation sequences (e.g., ../, .., %2F, %5C). Such sequences are often used to bypass security controls and access unauthorized files or directories on the web server.
Detects HTTP POST requests characteristic of Emotet Epoch 4 and 5 C2 communication. The rule monitors for specific URI patterns, the presence of a 'Cookie' header, and a base64-encoded request body exceeding 80 characters, which are indicative of Emotet malware beaconing activity.
This rule detects potential command and control (C2) activity related to the Qakbot malware. It specifically monitors for established outbound TLS traffic over non-standard ports (ports other than 443) where the Server Name Indication (SNI) field contains a numeric IPv4 address instead of a domain name, which is a characteristic behavior of Qakbot C2 infrastructure.
Detects TLS/SSL traffic patterns characteristic of Metasploit Meterpreter reverse HTTPS command-and-control communication, specifically targeting the use of default, self-signed certificates with a subject line containing a bare wildcard (CN=*) in the common name field, a common artifact of unconfigured Metasploit payloads.
This rule detects potential Cross-Site Scripting (XSS) attack attempts by inspecting HTTP requests for common malicious patterns, such as embedded script tags, JavaScript URIs, or HTML event handlers like 'onload' and 'onerror'. These payloads are often used by attackers to execute arbitrary code within a user's browser session.
Detects a high frequency of incoming TCP SYN packets targeting port 3389 (RDP) from a single source within a short time window. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
Detects the initial handshake communication pattern associated with AsyncRAT, characterized by a specific base64-encoded configuration blob sent to external non-standard ports (6606, 7707, 8808) as identified by the Snort rule logic.
Detects HTTP requests attempting to access sensitive internal IP addresses (RFC-1918) or cloud metadata services (e.g., 169.254.169.254) which are common indicators of Server-Side Request Forgery (SSRF) exploitation attempts.
This rule detects SMB traffic indicative of remote service creation over the SVCCTL named pipe, a pattern characteristic of tools like PsExec used for lateral movement and remote code execution.
Detects DNS TXT query responses containing anomalously large RDATA payloads (exceeding 100 bytes). Large TXT records are frequently used in DNS tunneling or data exfiltration scenarios to smuggle data out of a network while bypassing traditional network security controls. The rule applies a threshold limit to identify persistent, potentially malicious exfiltration activity from a specific source over a 60-second window.
