avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,980 views

8,664 detections

Phishing-as-a-Service kit abusing OAuth device code flow against Microsoft 365
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Campaign converting compromised FortiGate firewalls into credential stealers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Campaign converting compromised FortiGate firewalls into credential stealers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Cloud extortion group exploiting exposed credentials and storage
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Campaign converting compromised FortiGate firewalls into credential stealers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Cloud extortion group exploiting exposed credentials and storage
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the execution of command-line tools associated with Kerberoasting and Kerberos ticket manipulation techniques, such as requesting TGS tickets or targeting specific user accounts for ticket extraction.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the use of icacls.exe or cacls.exe to modify access control lists (ACLs) on sensitive Windows system directories and files. The rule specifically alerts when these commands are executed by non-Microsoft signed processes, which is a common indicator of unauthorized privilege escalation or persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
403
AI-powered phishing-as-a-service abusing device-code authentication
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Banking trojan and loader using malicious Office macro delivery
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002