avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views

8,664 detections

This rule detects HTTP POST requests containing a Content-Length header value indicating a body size exceeding 10MB. Large POST requests may indicate data exfiltration, large file uploads, or misuse of HTTP channels for data transfer to external destinations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects network traffic indicative of the NjRAT (Bladabindi) remote access trojan, specifically identifying its pipe-delimited command-and-control protocol patterns (e.g., '|ll|' or '|kl|').
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic containing 'Active Setup', 'Installed Components', and 'StubPath' strings, which are indicative of a potential attempt to reference or trigger a malicious StubPath registry key for persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the transmission of a Portable Executable (PE) file header ('MZ' and 'PE' magic bytes) within an HTTP response stream, which is a common indicator of a staged file download or process injection payload being delivered over the network.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic attempting to modify SSH authorized_keys or the sshd_config file using SCP or SFTP protocols, which is a common technique used by attackers to maintain persistence on compromised systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects suspicious SMB traffic targeting raw disk volumes (e.g., PhysicalDrive, C:) or sensitive Windows files such as NTDS.dit and SYSTEM hive files. This behavior is indicative of credential dumping attempts, often performed using tools like secretsdump.py or Invoke-NinjaCopy, which bypass standard file system access controls to exfiltrate critical system credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic attempting to access sensitive Windows Registry keys (SAM, SECURITY, LSA Secrets, winlogon DefaultPassword) over the SMB protocol, which is indicative of credential harvesting activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects signs of access token manipulation and impersonation, including the use of 'runas' with saved credentials, suspicious PowerShell API calls for identity management, usage of known token-manipulation tools (e.g., incognito), and reconnaissance using 'whoami /priv'. These activities are indicative of privilege escalation attempts or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of native Windows utilities such as shutdown.exe, wmic, powershell, and rundll32 to trigger an immediate system shutdown or restart, which may be indicative of unauthorized system disruption or malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential credential dumping activities and unauthorized access to sensitive system files. The rule monitors for three primary indicators: raw disk device access (often associated with volume shadow copy dumping), suspicious DiskShadow utility execution, and NTDS.dit extraction using ntdsutil. Known administrative and backup software processes are excluded to minimize noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001