avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,087 views

8,664 detections

This rule detects potential wiper activity by monitoring for high-frequency deletion or modification of specific file types (e.g., .docx, .xlsx, .pdf, .db, .bak) within a short window. It triggers when a process like PowerShell or Cmd is observed executing destructive commands (e.g., 'del', 'erase', 'Remove-Item') on a large number of files across multiple directories, which is a common behavior of malware attempting to destroy data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of NTFS Alternate Data Streams (ADS) by monitoring process command lines, initiating process command lines, and folder paths for patterns indicative of ADS notation. The rule specifically flags potential execution or access patterns involving common script interpreters (wscript, cscript, powershell, pwsh) combined with ADS, as well as general ADS usage in file paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the creation of .lnk files in common suspicious directories (such as startup folders, Temp, or Downloads) followed by the execution of common scripting or command interpreters (powershell.exe, mshta.exe, wscript.exe, cmd.exe) with long command lines within a 10-minute window. This behavior is often indicative of an adversary attempting to achieve persistence or execute malicious payloads via user interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Loader used in click-hijacking traffic distribution scheme
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
ClickFix style social engineering cluster delivering Mistic and ModeloRAT
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Malvertising loader delivering CastleStealer via malicious Google Ads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
USB worm and loader leveraging living-off-the-land binaries
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Modular remote access trojan associated with long-term espionage intrusions
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Malvertising loader delivering CastleStealer via malicious Google Ads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Modular remote access trojan associated with long-term espionage intrusions
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001