avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,235 views

8,664 detections

This rule detects potentially suspicious outbound network connections or DNS queries to known Generative AI service domains (OpenAI, Anthropic, Google, Mistral, Cohere) from non-browser and non-developer processes. It also triggers on suspicious Windows binaries (e.g., PowerShell, bitsadmin, mshta) initiating external connections to these domains or other destinations over port 443, helping identify potential data exfiltration or automated abuse of LLM APIs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
IoT botnet malware family used for DDoS and proxy infrastructure
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Infostealer-as-a-service targeting browser credentials and crypto wallets
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Supply chain worm targeting npm packages and GitHub Actions, linked to Shai-Hulud/Hades lineage
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Malvertising loader delivering CastleStealer via malicious Google Ads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Modular remote access trojan associated with long-term espionage intrusions
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Modular remote access trojan associated with long-term espionage intrusions
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Infostealer distributed via fake open-source tool impersonation sites
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Malvertising loader delivering CastleStealer via malicious Google Ads
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 576 of 867