avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

Detects mshta.exe spawning from archive utilities (winrar.exe, 7z.exe) or Windows Explorer, or executing HTA files directly from common user-writable temporary or download directories. This pattern is commonly associated with the execution of malicious payloads delivered via compressed archives, a technique observed in campaigns attributed to the Turla threat group.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects outbound network connections initiated by common AI agent runtime processes (Python, Node.js, OpenClaw) to external destinations that are not identified as known AI service providers, specifically focusing on non-standard ports or the use of WebSocket protocols. This behavior may indicate an AI agent being used for unauthorized data exfiltration, command-and-control communication, or interaction with an unverified external service.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
603
This rule detects shell commands (bash, sh, zsh) initiated by AI-agent or development-related processes (e.g., Python, Claude Desktop, openclaw) that target sensitive macOS paths associated with credentials, SSH keys, crypto wallets, and browser cookies, a technique characteristic of the Atomic Stealer (AMOS) malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where a process obtains a handle with PROCESS_VM_WRITE access to another process, followed shortly thereafter by a WriteProcessMemory operation into that same target process. This behavior is indicative of potential process injection, such as hooking remote GUI processes or other memory-based manipulation techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Modular remote access trojan associated with long-term espionage intrusions
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
IoT botnet malware family used for DDoS and proxy infrastructure
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Stealthy backdoor MLTBackdoor linked to KongTuke ClickFix and ModeloRAT campaigns
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
502
High-velocity ransomware-as-a-service with aggressive leak-site extortion
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
USB worm and loader leveraging living-off-the-land binaries
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002