
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential command and control (C2) activity leveraging DNS tunneling. It identifies high-frequency DNS queries that contain unusually long subdomain labels (51 characters or more), which is a common technique used to encode data or commands within DNS protocol traffic to bypass network security controls.
Detects multiple SSH authentication attempts from a single source IP address within a short timeframe, which is indicative of a brute force or password guessing attack against SSH services.
Detects ICMP Type 8 (Echo Request) packets with a payload size exceeding 1000 bytes. This is a common indicator of ICMP tunneling, where attackers encapsulate data within ICMP packets to bypass network security controls for command and control or data exfiltration.
Detects repeated RDP connection attempts to port 3389 from a single source within a short timeframe, characteristic of brute force or password spraying activity. The rule monitors for consecutive TLS ClientHello or MCS Connect-Initial packets.
Detects incoming HTTP traffic attempting to exploit the Apache Struts2 vulnerability CVE-2017-5638. The rule monitors the Content-Type HTTP header for OGNL (Object-Graph Navigation Language) expressions containing known exploitation markers like ClassLoader, getRuntime, or .exec(), which indicate an attempt to achieve Remote Code Execution (RCE).
Detects high-frequency TCP SYN scanning behavior targeting Telnet (port 23) and SSH (port 22) ports, characteristic of Mirai botnet propagation and reconnaissance activities.
Detects HTTP beaconing activity indicative of Cobalt Strike Malleable C2 communication. The rule monitors for specific URI patterns ('/updates', '/pixel', '/submit.php') in combination with a default User-Agent string commonly used by Cobalt Strike malleable profiles.
Detects network traffic associated with PsExec lateral movement activity, specifically looking for the creation of the PSEXESVC named pipe over SMB/ADMIN$ shares, which is commonly used by PsExec to remotely execute services and commands on target systems.
Detects multiple SSH authentication attempts from a single source IP address within a short timeframe, which is indicative of a brute force or password guessing attack against SSH services.
This rule detects attempts to inject malicious JavaScript code via HTTP URI requests. It uses PCRE pattern matching to identify common XSS indicators such as <script> tags, JavaScript event handlers (onerror, onload), and attempts to access document.cookie, which are indicative of stored or reflected Cross-Site Scripting (XSS) attack patterns.
