VLDB 2026 Research / reviewers in the wild / expert
Mohan Anand Putrevu
dblp:346/1446 · also P. Mohan Anand
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-9523-017XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LARM: Linux Anti Ransomware Monitor
Mohan Anand Putrevu, Venkata Sai Charan Putrevu, Hrushikesh Chunduri, Sandeep K. Shukla |
Comput. Secur. | 1 |
| 2024 | Trusted Yet Disguised: Analysing the Subversive Role of LOLBins in Contemporary Cyber ThreatsabstractThe proliferation of advanced detection techniques and the evolution of next-generation firewalls and antivirus engines have led to the increasing sophistication of cyber threats. In this context, malware authors are crafting disguised payloads that mimic benign behavior. To achieve this, the use of Windows signed executables/binaries (Living off the Land Binaries or LOLBins) and libraries has become increasingly relevant as a method to evade antivirus and signature-based detection techniques. These binaries inherently grant attackers a level of trust within the Windows operating system as they are signed by Microsoft. Understanding the specific LOLBins used by different attacks and their variants is crucial for developing effective detection rules and enhanced threat intelligence. Therefore, in this work, we analyze the presence of LOLBins from five distinct cyber attacks through dynamic analysis to determine the ubiquity and role of these Windows signed binaries in these attacks. We observe that the usage of LOLBins is nearly 51% of the payloads across Ransomware, Cryptominers, Advanced Persistent Threats (APTs), Information Stealers, and Remote Access Trojans (RATs)/Trojans. We also identify the distinct roles of the same LOLBins in attack variants in terms of evading defense strategies, downloading payloads, and offering stealth. Notably, ransomware and crypto miner payloads exhibit a higher diversity of utilizing 55 and 30 distinct LOLBins, respectively. Finally, we systematically analyze and compare the usage of LOLBins in Cobalt Strike payloads—a legacy multipurpose tool used by many malware families to evade detection, gather information, and persist within the victim environment. We identify Cobalt Strike to have the highest usage among all categories, at almost 73%. Hrushikesh Chunduri, Mohan Anand Putrevu, Sandeep K. Shukla, Venkata Sai Charan Putrevu |
IEEE Big Data | 2 |
| 2023 | RTR-Shield: Early Detection of Ransomware Using Registry and Trap Files
Mohan Anand Putrevu, Venkata Sai Charan Putrevu, Hrushikesh Chunduri, Sandeep K. Shukla |
ISPEC | 1 |
| 2023 | DKaaS: DARK-KERNEL as a service for active cyber threat intelligence
Venkata Sai Charan Putrevu, Gowtham Ratnakaram, Hrushikesh Chunduri, Mohan Anand Putrevu, Sandeep K. Shukla |
Comput. Secur. | 4 |
| 2020 | Detecting Word Based DGA Domains Using Ensemble Models
Venkata Sai Charan Putrevu, Sandeep K. Shukla, Mohan Anand Putrevu |
CANS | 3 |