avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views

8,664 detections

Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
macOS malware used by JINX-0164 against cryptocurrency developers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential lateral movement by identifying users who, within a short timeframe (90 seconds) of their first recorded network logon (EventID 4624, Logon Type 3), perform suspicious follow-up activities such as explicit credentials usage (4648), network share access (5140), or remote service installation (7045).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
This rule detects the execution of common archival utilities (7-Zip, WinRAR, RAR, ZIP) with parameters indicative of password-protected archive creation. It specifically flags instances where a user account, with no recorded prior history of running these utilities in the last 30 days, creates a large archive (exceeding 1GB) spanning multiple directories. This pattern is commonly used for data staging and preparation prior to exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects scenarios where common administrative or attack tools (e.g., whoami, net, ipconfig, psexec) are used within the same 5-minute window as network communication to known Large Language Model (LLM) service providers. This pattern may indicate an attacker using LLMs to assist with post-exploitation discovery, script generation, or data analysis based on local system reconnaissance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors Sysmon Event ID 11 (FileCreate) to detect high-volume file creation activity across multiple unique directories. By filtering out common file types, it identifies potential signs of mass file modification, staging for exfiltration, or malicious encryption characteristic of ransomware or data destructive operations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects scenarios where a common web browser (Chrome, Firefox, Edge, IE, Opera, or Brave) connects to an external destination not on a known allow-list, followed shortly (within 30 seconds) by the execution of a script-based binary (wscript.exe or mshta.exe) on the same host. This is a common pattern for initial access where a user downloads a malicious script from an unknown source via a browser and subsequently executes it.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects instances where the Node.js runtime (node.exe) spawns a command shell or scripting interpreter (cmd.exe, powershell.exe, or wscript.exe). The detection specifically looks for these processes being initiated from directories commonly associated with Node.js package management (npm) or local module installations, which may indicate malicious activity such as software supply chain attacks or execution of obfuscated scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002