Skip to content

timb-machine/linux-malware

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

E: we have a duplicate: https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group E: we have a duplicate: https://twitter.com/Unit42_Intel/status/1653760405792014336

Rolling 7 day view of updates from this repo

Submissions?

Press/academia

In the wild

Breach reports

Supply chain attacks

Malware reports

Malware samples

Malware binaries

Malware source

Malware PoCs

Offensive research

Not necessarily malicious code (see Linikatz and unix-privesc-check =)) but interesting capabilities...

Offensive tools

Offensive techniques

Defensive research

Defensive tools

Defensive techniques

Defensive Yara

Personal rules

  • pscan.yara (#287) - Hunts for references to pscan
  • luckscan.yara (#286) - Hunts for references to luckscan
  • adonunix2.yara (#281) - Hunts for binaries that attack AD on UNIX
  • aix.yara (#280) - Hunts for AIX binaries
  • ciscotools.yara (#279) - Hunts for references to our tools
  • enterpriseapps2.yara (#283) - Hunts for enterprise app binaries
  • enterpriseunix2.yara (#282) - Hunts for enterprise UNIX binaries
  • unixredflags3.yara (#285) - Hunts for UNIX red flags
  • canvasspectre.yara (#284) - Hunts for CANVAS Spectre

Other rules

About

Tracking interesting Linux (and UNIX) malware. Send PRs

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published