avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views

8,664 detections

Detects inbound emails originating from 'azure-noreply@microsoft.com' with subjects that typically indicate financial transactions (e.g., 'Invoice Paid', 'Payment Reference') or system alerts (e.g., 'MemorySpike', 'DiskFull'). This pattern could be indicative of phishing attempts leveraging a seemingly legitimate sender to trick recipients.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the command shell execution chain used by scheduled tasks to launch ransomware payloads (run.bat, run.exe) distributed via malicious GPOs
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects FFmpeg DLL loading outside expected application directories. Argamal abuses modified FFmpeg libraries to initiate execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects unusual or suspicious child processes spawned by Visual Studio Code, which could indicate Remote Code Execution (RCE) stemming from a malicious Jupyter notebook on the desktop client.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects repository creation activity initiated by service accounts, integrations, or automated identities. Unexpected repository creation may indicate compromised CI/CD credentials, unauthorized automation, or preparation for source code exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects newly registered devices following account compromise. Threat actors frequently register rogue devices after obtaining tokens to maintain persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects execution chains where a suspicious DLL (autorun.dll) is loaded from user-controlled directories and followed by a silent MSI installation. This pattern is commonly associated with malware staging and secondary payload deployment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where rundll32.exe executes with missing or minimal DLL arguments and subsequently establishes outbound network connections. This behavior is uncommon in legitimate Windows operations and has been observed during ACR Stealer infections, including executions originating from remote SMB shares and memory-loaded payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
Detects rundll32.exe loading content directly from a UNC path. This behavior is rare in enterprise environments and was observed in ACR Stealer delivery chains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001