avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views

8,664 detections

Detects emails originating from sender addresses identified by Microsoft as part of the April 2026 "Code of Conduct" adversary-in-the-middle (AiTM) phishing campaign that targeted Microsoft 365 users and attempted to steal authentication tokens.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects delivery of known PDF attachments used in the Code of Conduct credential theft campaign.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects files staged in C:\Users\Public\Music via RDP (mstsc.exe), a known Grixba ransomware scanner behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Flags mutex creation (CPFATE) in .NET runtime, linked to Grixba ransomware scanner variants.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Identifies .lnk files dropped into Startup folders, a persistence technique tied to WinRAR exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects suspicious PowerShell execution chains (-nop, -w hidden, iex (gc) used in ClickFix RAT delivery.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects execution of CRYPTBASE.dll from non‑system directories, a technique used in the STX RAT campaign to hijack legitimate installers (e.g., CPUID HWMonitor, X‑VPN).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects PowerShell queries for motherboard serial numbers or UUIDs, behaviors commonly associated with malware reconnaissance and sandbox evasion. This rule specifically looks for 'powershell.exe' executing commands that query 'Win32_BaseBoard' or 'Win32_ComputerSystemProduct' and contain 'SerialNumber' or 'UUID'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Identifies PowerShell executing scripts or expressions from the ProgramData directory, which may indicate malicious staging or backdoor execution. This rule specifically looks for PowerShell processes where the command line includes 'C:\ProgramData\' and also contains keywords like 'IEX', 'Invoke-Expression', or '.ps1', suggesting the execution of a script or expression.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects calls to NtAllocateVirtualMemory originating from scripting engines or binaries executing from temporary user-controlled locations. This behavior is commonly associated with reflective loading, shellcode execution, and in-memory malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 606 of 867