
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects inbound emails originating from 'azure-noreply@microsoft.com' with subjects that typically indicate financial transactions (e.g., 'Invoice Paid', 'Payment Reference') or system alerts (e.g., 'MemorySpike', 'DiskFull'). This pattern could be indicative of phishing attempts leveraging a seemingly legitimate sender to trick recipients.
Detects the command shell execution chain used by scheduled tasks to launch ransomware payloads (run.bat, run.exe) distributed via malicious GPOs
Detects FFmpeg DLL loading outside expected application directories. Argamal abuses modified FFmpeg libraries to initiate execution.
Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.
Detects unusual or suspicious child processes spawned by Visual Studio Code, which could indicate Remote Code Execution (RCE) stemming from a malicious Jupyter notebook on the desktop client.
Detects repository creation activity initiated by service accounts, integrations, or automated identities. Unexpected repository creation may indicate compromised CI/CD credentials, unauthorized automation, or preparation for source code exfiltration.
Detects newly registered devices following account compromise. Threat actors frequently register rogue devices after obtaining tokens to maintain persistence.
Detects execution chains where a suspicious DLL (autorun.dll) is loaded from user-controlled directories and followed by a silent MSI installation. This pattern is commonly associated with malware staging and secondary payload deployment.
Detects instances where rundll32.exe executes with missing or minimal DLL arguments and subsequently establishes outbound network connections. This behavior is uncommon in legitimate Windows operations and has been observed during ACR Stealer infections, including executions originating from remote SMB shares and memory-loaded payloads.
Detects rundll32.exe loading content directly from a UNC path. This behavior is rare in enterprise environments and was observed in ACR Stealer delivery chains.
