avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

Rust-based ransomware family targeting enterprise environments
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Loader malware delivering follow-on ransomware payloads
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Credential and browser data stealer distributed via OXLOADER campaigns
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Ransomware group exploiting edge devices and managed file transfer software
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Credential and browser data stealer distributed via OXLOADER campaigns
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Credential and browser data stealer distributed via OXLOADER campaigns
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where the Node.js executable (node.exe) spawns common command shells or scripting interpreters such as cmd.exe, powershell.exe, pwsh.exe, or wscript.exe. This behavior is often indicative of Node.js-based applications being used as a staging point for command execution, a common pattern in post-exploitation or the usage of malicious npm packages.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the coordinated execution of multiple Windows command-line utilities (vssadmin, wbadmin, and bcdedit) within a short time frame (60 seconds). These tools are frequently used by ransomware and other malware to delete volume shadow copies, clear backup catalogs, and disable system recovery features, effectively preventing the restoration of the system after a damaging event.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects modifications to Group Policy Objects (GPOs) that involve sensitive attributes such as logon scripts, startup/shutdown scripts, or file system paths, particularly when performed by service accounts or non-administrator users. This activity is a common indicator of persistence mechanisms or lateral movement via GPO abuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects scenarios where a new local user account is created on a Windows system during off-hours (between 7 PM and 7 AM), followed by the execution of known remote access tools within a 30-minute window of that account creation. This combination is often indicative of unauthorized persistent access establishment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001