avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

Rust-based ransomware family targeting enterprise environments
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Ransomware group exploiting edge devices and managed file transfer software
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Rust-based ransomware family targeting enterprise environments
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Loader malware delivering follow-on ransomware payloads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Loader malware delivering follow-on ransomware payloads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Rust-based ransomware family targeting enterprise environments
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Ransomware group exploiting edge devices and managed file transfer software
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Loader malware delivering follow-on ransomware payloads
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects common Kerberoasting activities by monitoring for the execution of 'Rubeus' or 'GetUserSPNs' (often associated with Impacket) in process command lines. These tools are commonly used by attackers to request service tickets for service accounts, which can then be cracked offline to recover passwords.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1103
Detects unsigned or non-Microsoft processes attempting to access sensitive system process memory (lsass.exe, winlogon.exe, services.exe) or processes attempting to enable SeDebugPrivilege, which are common indicators of credential dumping or process injection attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003