avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,134 views

8,664 detections

Correlates user interaction with email URLs and subsequent risky sign-ins occurring shortly afterward. Commonly observed in adversary-in-the-middle (AiTM) campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects newly registered devices following account compromise. Threat actors frequently register rogue devices after obtaining tokens to maintain persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects commands referencing known C0XMO payload locations while interacting with cron jobs or shell startup files. This behavior may indicate an attempt to maintain persistence across system reboots.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects FFmpeg DLL loading outside expected application directories. Argamal abuses modified FFmpeg libraries to initiate execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Identifies network traffic to a specific malicious Google Firestore project ('braintree-payment-app') used by a Magecart campaign for C2 and data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects local password validation using dscl . -authonly, a technique observed in ClickFix credential theft workflows.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Identifies HTTP/2 requests with excessive header counts to detect the memory amplification stage of an HTTP/2 Bomb DoS attack.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the BITSAdmin utility to transfer files or set notification command lines. BITSAdmin is a legitimate Windows utility often abused by adversaries to download malicious files or achieve persistence/execution via BITS jobs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001