
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,134 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Correlates user interaction with email URLs and subsequent risky sign-ins occurring shortly afterward. Commonly observed in adversary-in-the-middle (AiTM) campaigns.
Detects newly registered devices following account compromise. Threat actors frequently register rogue devices after obtaining tokens to maintain persistence.
Detects commands referencing known C0XMO payload locations while interacting with cron jobs or shell startup files. This behavior may indicate an attempt to maintain persistence across system reboots.
Detects FFmpeg DLL loading outside expected application directories. Argamal abuses modified FFmpeg libraries to initiate execution.
Identifies network traffic to a specific malicious Google Firestore project ('braintree-payment-app') used by a Magecart campaign for C2 and data exfiltration.
Detects local password validation using dscl . -authonly, a technique observed in ClickFix credential theft workflows.
Identifies HTTP/2 requests with excessive header counts to detect the memory amplification stage of an HTTP/2 Bomb DoS attack.
Detects the use of the BITSAdmin utility to transfer files or set notification command lines. BITSAdmin is a legitimate Windows utility often abused by adversaries to download malicious files or achieve persistence/execution via BITS jobs.
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
