avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,128 views

8,664 detections

Detects outbound HTTP POST requests characteristic of QakBot malware command and control (C2) activity. The rule identifies a specific combination of a hardcoded User-Agent string ('Trident/7.0') and a URI pattern consisting of 4 to 32 alphanumeric characters ending in .php.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially malicious activity leveraging the Windows Remote Management (WinRM) protocol over HTTP (ports 5985/5986). It specifically monitors for POST requests to the '/wsman' URI that contain the string 'powershell' in the request body, which is indicative of remote command execution via WinRM using PowerShell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP POST requests containing multipart form data that include suspicious PHP functions commonly associated with webshells, such as eval(), base64_decode(), system(), or passthru(). This indicates a potential attempt to upload or execute a malicious PHP script on a web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential DNS exfiltration attempts by identifying DNS queries containing high-entropy subdomains of 51 characters or more, encoded in Base64. Adversaries may use long, encoded subdomains to tunnel data out of a network through the DNS protocol, bypassing traditional security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects multiple TCP synchronization (SYN) packets targeting the SSH service (port 22) from a single source IP address within a short timeframe. This behavior is indicative of a brute-force or credential-guessing attack against the SSH service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous ICMP traffic patterns, specifically ICMP Echo Request packets with unusually large payload sizes (dsize > 64) and specific byte signatures consistent with known ICMP tunneling tools such as icmpsh or ptunnel, which are used to establish covert C2 channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects common SQL injection patterns within the HTTP URI query string. The rule monitors established network traffic to web servers and uses regex matching to identify attempts to use SQL keywords like UNION SELECT, OR 1=1 boolean-based attacks, blind SQL injection techniques (sleep/benchmark), and attempts to access information_schema metadata tables.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects repeated SSH connection attempts to a server over a short duration (10+ attempts in 60 seconds), which is characteristic of credential stuffing or brute-force password guessing attacks against the SSH service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP POST requests characteristic of Emotet Epoch 4 and 5 C2 communication. The rule monitors for specific URI patterns, the presence of a 'Cookie' header, and a base64-encoded request body exceeding 80 characters, which are indicative of Emotet malware beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network communication associated with AsyncRAT command-and-control activity. The rule identifies established outbound connections on non-standard ports (6606, 7707, 8808) containing a specific 3-byte null sequence header, which is indicative of AsyncRAT's communication protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001