
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,235 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potentially suspicious outbound network connections or DNS queries to known Generative AI service domains (OpenAI, Anthropic, Google, Mistral, Cohere) from non-browser and non-developer processes. It also triggers on suspicious Windows binaries (e.g., PowerShell, bitsadmin, mshta) initiating external connections to these domains or other destinations over port 443, helping identify potential data exfiltration or automated abuse of LLM APIs.
IoT botnet malware family used for DDoS and proxy infrastructure
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
Lumma C2Beacon
YARA
Infostealer-as-a-service targeting browser credentials and crypto wallets
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
Malvertising loader delivering CastleStealer via malicious Google Ads
Modular remote access trojan associated with long-term espionage intrusions
Modular remote access trojan associated with long-term espionage intrusions
Infostealer distributed via fake open-source tool impersonation sites
Malvertising loader delivering CastleStealer via malicious Google Ads
Page 576 of 867
