avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views

8,664 detections

This rule detects potential command and control (C2) beaconing activity using DNS tunneling. It monitors for a high frequency of DNS TXT record queries to long subdomains (exceeding 50 characters), which is a common characteristic of tools like DNScat and iodine that encode data within DNS requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects HTTP requests attempting to perform Local File Inclusion (LFI) or path traversal attacks by searching for patterns such as '/../' sequences and common sensitive file paths like /etc/passwd, /etc/shadow, or /proc/self/environ in the URI.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects large HTTP POST requests (over 5MB) directed at external hosts that utilize multipart or chunked encoding, which are commonly used to obfuscate or stream large volumes of data during an exfiltration event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects outbound HTTP POST requests to suspicious URIs and subsequent inbound responses containing executable binary (PE) signatures, characteristic of Emotet malware command-and-control (C2) activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network activity characteristic of the PsExec tool performing lateral movement. The rule monitors for SMB traffic directed at the ADMIN$ share, specifically looking for the creation or access of the 'PSEXESVC' service binary, combined with the use of the 'svcctl' named pipe, which is used by PsExec to remotely control services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the outbound transmission of email attachments via SMTP (ports 25 and 587) that contain archived file formats (zip, 7z, tar.gz, tgz). Attackers often compress collected data into archives to facilitate exfiltration and minimize the time required for data transfer.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects network activity associated with lateral movement using Windows Management Instrumentation (WMI). It specifically looks for a DCE/RPC Bind request that targets the IWbemServices interface UUID, a common method for initializing remote WMI connections to execute commands on remote systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects outbound HTTP POST requests to external networks that match a known Emotet C2 traffic pattern. The rule specifically looks for HTTP POST requests using an 'application/x-www-form-urlencoded' Content-Type and a URI structure consisting of randomized alphanumeric segments (4-20 characters long). This structure is characteristic of Emotet's communication with its command-and-control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high-frequency HTTP 401 Unauthorized responses associated with Basic Authentication attempts within a short timeframe, indicating a potential credential brute-force attack.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors for FTP 'STOR' commands followed by large data transfers (exceeding 64KB) initiated from internal hosts to external destinations. This pattern is often indicative of data exfiltration using the File Transfer Protocol (FTP).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001