
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects mshta.exe spawning from archive utilities (winrar.exe, 7z.exe) or Windows Explorer, or executing HTA files directly from common user-writable temporary or download directories. This pattern is commonly associated with the execution of malicious payloads delivered via compressed archives, a technique observed in campaigns attributed to the Turla threat group.
Detects outbound network connections initiated by common AI agent runtime processes (Python, Node.js, OpenClaw) to external destinations that are not identified as known AI service providers, specifically focusing on non-standard ports or the use of WebSocket protocols. This behavior may indicate an AI agent being used for unauthorized data exfiltration, command-and-control communication, or interaction with an unverified external service.
This rule detects shell commands (bash, sh, zsh) initiated by AI-agent or development-related processes (e.g., Python, Claude Desktop, openclaw) that target sensitive macOS paths associated with credentials, SSH keys, crypto wallets, and browser cookies, a technique characteristic of the Atomic Stealer (AMOS) malware.
Detects instances where a process obtains a handle with PROCESS_VM_WRITE access to another process, followed shortly thereafter by a WriteProcessMemory operation into that same target process. This behavior is indicative of potential process injection, such as hooking remote GUI processes or other memory-based manipulation techniques.
Modular remote access trojan associated with long-term espionage intrusions
IoT botnet malware family used for DDoS and proxy infrastructure
Stealthy backdoor MLTBackdoor linked to KongTuke ClickFix and ModeloRAT campaigns
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
High-velocity ransomware-as-a-service with aggressive leak-site extortion
USB worm and loader leveraging living-off-the-land binaries
