avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,126 views

8,664 detections

Detects attempts to exploit the Shellshock vulnerability (CVE-2014-6271) by inspecting HTTP request headers for the characteristic function definition syntax '() { :;'. This pattern is commonly used in malicious payloads to trigger command execution via environment variables in CGI scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the use of the PSEXESVC named pipe during a write operation over the SMB protocol, which is indicative of lateral movement using the PsExec tool.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound HTTP POST requests characteristic of QakBot malware command and control (C2) activity. The rule identifies a specific combination of a hardcoded User-Agent string ('Trident/7.0') and a URI pattern consisting of 4 to 32 alphanumeric characters ending in .php.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound HTTPS traffic containing TLS certificates with common names associated with known command-and-control (C2) frameworks like Metasploit and Empire. These frameworks often use self-signed certificates with default or easily identifiable issuer names when establishing C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers (User-Agent, X-Forwarded-For, Referer) for JNDI lookup strings. The JNDI lookup mechanism in vulnerable Log4j libraries allows an attacker to execute arbitrary code by pointing the lookup to a malicious LDAP, RMI, or DNS server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects multiple failed SSH authentication attempts originating from a single source IP within a short timeframe, which is indicative of a brute-force or credential-stuffing attack against SSH services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects common Cross-Site Scripting (XSS) patterns within the HTTP URI, specifically looking for script tags, javascript: URI handlers, and common event handlers (onerror/onload) that are frequently used in XSS injection attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network activity characteristic of the PsExec tool performing lateral movement. The rule monitors for SMB traffic directed at the ADMIN$ share, specifically looking for the creation or access of the 'PSEXESVC' service binary, combined with the use of the 'svcctl' named pipe, which is used by PsExec to remotely control services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects SMB authentication attempts using NTLM with a blank Lan Manager (LM) hash. This specific pattern is often associated with Pass-the-Hash attacks where tools inject malformed or blank hashes to initiate authentication, a common indicator of lateral movement attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the outbound transmission of email attachments via SMTP (ports 25 and 587) that contain archived file formats (zip, 7z, tar.gz, tgz). Attackers often compress collected data into archives to facilitate exfiltration and minimize the time required for data transfer.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001