
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,126 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects attempts to exploit the Shellshock vulnerability (CVE-2014-6271) by inspecting HTTP request headers for the characteristic function definition syntax '() { :;'. This pattern is commonly used in malicious payloads to trigger command execution via environment variables in CGI scripts.
This rule detects the use of the PSEXESVC named pipe during a write operation over the SMB protocol, which is indicative of lateral movement using the PsExec tool.
Detects outbound HTTP POST requests characteristic of QakBot malware command and control (C2) activity. The rule identifies a specific combination of a hardcoded User-Agent string ('Trident/7.0') and a URI pattern consisting of 4 to 32 alphanumeric characters ending in .php.
Detects outbound HTTPS traffic containing TLS certificates with common names associated with known command-and-control (C2) frameworks like Metasploit and Empire. These frameworks often use self-signed certificates with default or easily identifiable issuer names when establishing C2 communication.
This rule detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers (User-Agent, X-Forwarded-For, Referer) for JNDI lookup strings. The JNDI lookup mechanism in vulnerable Log4j libraries allows an attacker to execute arbitrary code by pointing the lookup to a malicious LDAP, RMI, or DNS server.
Detects multiple failed SSH authentication attempts originating from a single source IP within a short timeframe, which is indicative of a brute-force or credential-stuffing attack against SSH services.
This rule detects common Cross-Site Scripting (XSS) patterns within the HTTP URI, specifically looking for script tags, javascript: URI handlers, and common event handlers (onerror/onload) that are frequently used in XSS injection attacks.
Detects network activity characteristic of the PsExec tool performing lateral movement. The rule monitors for SMB traffic directed at the ADMIN$ share, specifically looking for the creation or access of the 'PSEXESVC' service binary, combined with the use of the 'svcctl' named pipe, which is used by PsExec to remotely control services.
Detects SMB authentication attempts using NTLM with a blank Lan Manager (LM) hash. This specific pattern is often associated with Pass-the-Hash attacks where tools inject malformed or blank hashes to initiate authentication, a common indicator of lateral movement attempts.
This rule detects the outbound transmission of email attachments via SMTP (ports 25 and 587) that contain archived file formats (zip, 7z, tar.gz, tgz). Attackers often compress collected data into archives to facilitate exfiltration and minimize the time required for data transfer.
