avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,260 views

8,664 detections

Detects potential screenshot collection activity. Argamal supports screen capture functionality as part of its RAT capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects network connections and DNS queries to the Binance Smart Chain testnet endpoint 'data-seed-prebsc-1-s1.binance.org', which AnimateClipper uses to resolve its actual C2 domain via a smart contract.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the execution of Jupyter Notebooks from unexpected or temporary locations. Crafted Jupyter notebooks are the primary delivery mechanism for exploiting a zero-click/one-click GitHub token theft vulnerability in VS Code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects Bun runtime execution from temporary or user-writable directories such as /tmp/ or Windows Temp folders. Threat actors increasingly leverage Bun as an alternative JavaScript runtime to execute payloads directly from temporary locations and evade traditional application controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects download activity targeting Bun binaries or release packages from GitHub-hosted repositories. Adversaries may dynamically download Bun at runtime to execute malicious JavaScript payloads without embedding tooling inside container images or endpoints.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects execution chains where npm launches Node.js and Node.js subsequently launches Bun. This sequence may indicate malicious package execution, dependency confusion attacks, CI/CD compromise, or supply-chain abuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects Bun or Node.js processes communicating with cloud metadata service endpoints. This behavior is frequently associated with credential harvesting, cloud reconnaissance, token theft, and post-exploitation activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects command-line activity searching for secret-related values within application or runner configurations. Attackers commonly enumerate secrets, credentials, API keys, and environment variables immediately after gaining access to CI/CD infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects access to npm token management and identity endpoints. This activity may indicate attempts to enumerate authentication tokens, validate account access, or prepare for software supply-chain compromise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 605 of 867