
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,260 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential screenshot collection activity. Argamal supports screen capture functionality as part of its RAT capabilities.
Detects network connections and DNS queries to the Binance Smart Chain testnet endpoint 'data-seed-prebsc-1-s1.binance.org', which AnimateClipper uses to resolve its actual C2 domain via a smart contract.
Detects the execution of Jupyter Notebooks from unexpected or temporary locations. Crafted Jupyter notebooks are the primary delivery mechanism for exploiting a zero-click/one-click GitHub token theft vulnerability in VS Code.
Detects Bun runtime execution from temporary or user-writable directories such as /tmp/ or Windows Temp folders. Threat actors increasingly leverage Bun as an alternative JavaScript runtime to execute payloads directly from temporary locations and evade traditional application controls.
Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.
Detects download activity targeting Bun binaries or release packages from GitHub-hosted repositories. Adversaries may dynamically download Bun at runtime to execute malicious JavaScript payloads without embedding tooling inside container images or endpoints.
Detects execution chains where npm launches Node.js and Node.js subsequently launches Bun. This sequence may indicate malicious package execution, dependency confusion attacks, CI/CD compromise, or supply-chain abuse.
Detects Bun or Node.js processes communicating with cloud metadata service endpoints. This behavior is frequently associated with credential harvesting, cloud reconnaissance, token theft, and post-exploitation activity.
Detects command-line activity searching for secret-related values within application or runner configurations. Attackers commonly enumerate secrets, credentials, API keys, and environment variables immediately after gaining access to CI/CD infrastructure.
Detects access to npm token management and identity endpoints. This activity may indicate attempts to enumerate authentication tokens, validate account access, or prepare for software supply-chain compromise.
Page 605 of 867
