avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,254 views

8,664 detections

This rule detects modifications to Group Policy Objects (GPOs) that involve sensitive attributes such as logon scripts, startup/shutdown scripts, or file system paths, particularly when performed by service accounts or non-administrator users. This activity is a common indicator of persistence mechanisms or lateral movement via GPO abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
This rule detects scenarios where a new local user account is created on a Windows system during off-hours (between 7 PM and 7 AM), followed by the execution of known remote access tools within a 30-minute window of that account creation. This combination is often indicative of unauthorized persistent access establishment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
macOS malware used by JINX-0164 against cryptocurrency developers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
macOS malware used by JINX-0164 against cryptocurrency developers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Commodity .NET keylogger and remote access trojan
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 593 of 867