avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views

8,664 detections

Description- Detects PDF invoice files associated with Crimson Kingsnake using consistent metadata author “hpins”.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects known malicious invoice PDFs and email samples used in Crimson Kingsnake campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects suspicious command-line executions involving common Windows system binaries (rundll32.exe, mshta.exe, certutil.exe, wmic.exe) combined with keywords often associated with network communication or data transfer (http, https, base64, /transfer). This pattern can indicate attempts at downloading malicious payloads, exfiltrating data, or executing encoded commands.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects URL clicks associated with the Moduba cloaking and redirect campaign using UrlClickEvents. Focuses on specific domain IOCs, redirect chains, and beaconing behaviors.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the creation of Windows QoS policies that specifically target EDR, antivirus, or security monitoring processes using the -AppPathNameMatchCondition parameter. This technique can be used to throttle security tool network traffic, reducing telemetry visibility and impairing detection capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects creation of the malicious persistence service observed during the Hola Browser compromise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects Windows Defender exclusion modifications. The malicious Hola miner was observed adding exclusions before beginning mining operations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects PowerShell download activity associated with Argamal's second-stage payload retrieval.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects suspicious GitHub-hosted payload retrieval. Argamal has been observed downloading encrypted components from GitHub repositories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects COM object hijacking through InprocServer32 modifications. Argamal establishes persistence using COM hijacking mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 604 of 867