avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,514 copies160 likes52,128 views

8,664 detections

This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
This rule detects potential data exfiltration by identifying devices that make a high number of network connections (3 or more within an hour) to various remote IPs using common file transfer and email protocols (FTP, SFTP, SMB, SMTP) on their standard ports (21, 22, 445, 25, 587). This pattern can indicate an adversary attempting to exfiltrate collected data from a compromised system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
109
Detects outbound HTTP POST requests where the Content-Length header indicates a data transfer of 5MB or greater. This pattern is indicative of potential unauthorized data exfiltration over the web protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP requests containing a UNION SELECT pattern in the URI query string, which is a common indicator of a SQL injection attempt aimed at exfiltrating data or manipulating database queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP traffic containing a specific session cookie pattern characteristic of PowerShell Empire C2 agent communication, utilizing regex to identify base64-encoded session identifiers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous DCOM RPC bind requests on port 135 targeting WMI-related interfaces, which is a common indicator of lateral movement using Windows Management Instrumentation (WMI) over DCOM.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the execution of PowerShell or pwsh.exe with an encoded command. Adversaries often use encoded commands to obfuscate their malicious scripts and evade detection. The rule specifically looks for the '-EncodedCommand' or '-enc' parameter followed by a base64-encoded string of at least 20 characters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
This rule detects rapid, successive TCP connection attempts directed to port 3389 (RDP) from a single external source IP within a short timeframe. This behavior is indicative of a brute force attack or automated credential guessing activity targeting remote desktop services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects classic SQL injection attack patterns within incoming HTTP requests, such as UNION SELECT statements, boolean-based tautologies (1=1), table dropping commands, or common URL-encoded quote characters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects multiple FTP login failures ('530 Login incorrect') from a single source IP address within a short time window, indicating a potential brute force or password guessing attempt against an FTP service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001