avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views

8,664 detections

This rule detects potential command and control (C2) activity leveraging DNS tunneling. It identifies high-frequency DNS queries that contain unusually long subdomain labels (51 characters or more), which is a common technique used to encode data or commands within DNS protocol traffic to bypass network security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects multiple SSH authentication attempts from a single source IP address within a short timeframe, which is indicative of a brute force or password guessing attack against SSH services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects ICMP Type 8 (Echo Request) packets with a payload size exceeding 1000 bytes. This is a common indicator of ICMP tunneling, where attackers encapsulate data within ICMP packets to bypass network security controls for command and control or data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects repeated RDP connection attempts to port 3389 from a single source within a short timeframe, characteristic of brute force or password spraying activity. The rule monitors for consecutive TLS ClientHello or MCS Connect-Initial packets.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects incoming HTTP traffic attempting to exploit the Apache Struts2 vulnerability CVE-2017-5638. The rule monitors the Content-Type HTTP header for OGNL (Object-Graph Navigation Language) expressions containing known exploitation markers like ClassLoader, getRuntime, or .exec(), which indicate an attempt to achieve Remote Code Execution (RCE).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects high-frequency TCP SYN scanning behavior targeting Telnet (port 23) and SSH (port 22) ports, characteristic of Mirai botnet propagation and reconnaissance activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP beaconing activity indicative of Cobalt Strike Malleable C2 communication. The rule monitors for specific URI patterns ('/updates', '/pixel', '/submit.php') in combination with a default User-Agent string commonly used by Cobalt Strike malleable profiles.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic associated with PsExec lateral movement activity, specifically looking for the creation of the PSEXESVC named pipe over SMB/ADMIN$ shares, which is commonly used by PsExec to remotely execute services and commands on target systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects multiple SSH authentication attempts from a single source IP address within a short timeframe, which is indicative of a brute force or password guessing attack against SSH services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects attempts to inject malicious JavaScript code via HTTP URI requests. It uses PCRE pattern matching to identify common XSS indicators such as <script> tags, JavaScript event handlers (onerror, onload), and attempts to access document.cookie, which are indicative of stored or reflected Cross-Site Scripting (XSS) attack patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001