
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,128 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects outbound HTTP POST requests characteristic of QakBot malware command and control (C2) activity. The rule identifies a specific combination of a hardcoded User-Agent string ('Trident/7.0') and a URI pattern consisting of 4 to 32 alphanumeric characters ending in .php.
This rule detects potentially malicious activity leveraging the Windows Remote Management (WinRM) protocol over HTTP (ports 5985/5986). It specifically monitors for POST requests to the '/wsman' URI that contain the string 'powershell' in the request body, which is indicative of remote command execution via WinRM using PowerShell.
Detects HTTP POST requests containing multipart form data that include suspicious PHP functions commonly associated with webshells, such as eval(), base64_decode(), system(), or passthru(). This indicates a potential attempt to upload or execute a malicious PHP script on a web server.
This rule detects potential DNS exfiltration attempts by identifying DNS queries containing high-entropy subdomains of 51 characters or more, encoded in Base64. Adversaries may use long, encoded subdomains to tunnel data out of a network through the DNS protocol, bypassing traditional security controls.
Detects multiple TCP synchronization (SYN) packets targeting the SSH service (port 22) from a single source IP address within a short timeframe. This behavior is indicative of a brute-force or credential-guessing attack against the SSH service.
Detects anomalous ICMP traffic patterns, specifically ICMP Echo Request packets with unusually large payload sizes (dsize > 64) and specific byte signatures consistent with known ICMP tunneling tools such as icmpsh or ptunnel, which are used to establish covert C2 channels.
Detects common SQL injection patterns within the HTTP URI query string. The rule monitors established network traffic to web servers and uses regex matching to identify attempts to use SQL keywords like UNION SELECT, OR 1=1 boolean-based attacks, blind SQL injection techniques (sleep/benchmark), and attempts to access information_schema metadata tables.
Detects repeated SSH connection attempts to a server over a short duration (10+ attempts in 60 seconds), which is characteristic of credential stuffing or brute-force password guessing attacks against the SSH service.
Detects HTTP POST requests characteristic of Emotet Epoch 4 and 5 C2 communication. The rule monitors for specific URI patterns, the presence of a 'Cookie' header, and a base64-encoded request body exceeding 80 characters, which are indicative of Emotet malware beaconing activity.
Detects network communication associated with AsyncRAT command-and-control activity. The rule identifies established outbound connections on non-standard ports (6606, 7707, 8808) containing a specific 3-byte null sequence header, which is indicative of AsyncRAT's communication protocol.
