
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,128 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
This rule detects potential data exfiltration by identifying devices that make a high number of network connections (3 or more within an hour) to various remote IPs using common file transfer and email protocols (FTP, SFTP, SMB, SMTP) on their standard ports (21, 22, 445, 25, 587). This pattern can indicate an adversary attempting to exfiltrate collected data from a compromised system.
Detects outbound HTTP POST requests where the Content-Length header indicates a data transfer of 5MB or greater. This pattern is indicative of potential unauthorized data exfiltration over the web protocol.
Detects HTTP requests containing a UNION SELECT pattern in the URI query string, which is a common indicator of a SQL injection attempt aimed at exfiltrating data or manipulating database queries.
Detects HTTP traffic containing a specific session cookie pattern characteristic of PowerShell Empire C2 agent communication, utilizing regex to identify base64-encoded session identifiers.
Detects anomalous DCOM RPC bind requests on port 135 targeting WMI-related interfaces, which is a common indicator of lateral movement using Windows Management Instrumentation (WMI) over DCOM.
This rule detects the execution of PowerShell or pwsh.exe with an encoded command. Adversaries often use encoded commands to obfuscate their malicious scripts and evade detection. The rule specifically looks for the '-EncodedCommand' or '-enc' parameter followed by a base64-encoded string of at least 20 characters.
This rule detects rapid, successive TCP connection attempts directed to port 3389 (RDP) from a single external source IP within a short timeframe. This behavior is indicative of a brute force attack or automated credential guessing activity targeting remote desktop services.
Detects classic SQL injection attack patterns within incoming HTTP requests, such as UNION SELECT statements, boolean-based tautologies (1=1), table dropping commands, or common URL-encoded quote characters.
Detects multiple FTP login failures ('530 Login incorrect') from a single source IP address within a short time window, indicating a potential brute force or password guessing attempt against an FTP service.
