Skip to content

Tracking interesting Linux (and UNIX) malware. Send PRs

License

Notifications You must be signed in to change notification settings

magnologan/linux-malware

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

E: we have a duplicate: https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group E: we have a duplicate: https://twitter.com/Unit42_Intel/status/1653760405792014336

Rolling 7 day view of updates from this repo

Submissions?

Press/academia

In the wild

Breach reports

Supply chain attacks

Malware reports

Malware samples

Malware binaries

Malware source

Malware PoCs

Offensive research

Not necessarily malicious code (see Linikatz and unix-privesc-check =)) but interesting capabilities...

Offensive tools

Offensive techniques

Defensive research

Defensive tools

Defensive techniques

Defensive Yara

Personal rules

  • pscan.yara (#287) - Hunts for references to pscan
  • luckscan.yara (#286) - Hunts for references to luckscan
  • adonunix2.yara (#281) - Hunts for binaries that attack AD on UNIX
  • aix.yara (#280) - Hunts for AIX binaries
  • ciscotools.yara (#279) - Hunts for references to our tools
  • enterpriseapps2.yara (#283) - Hunts for enterprise app binaries
  • enterpriseunix2.yara (#282) - Hunts for enterprise UNIX binaries
  • unixredflags3.yara (#285) - Hunts for UNIX red flags
  • canvasspectre.yara (#284) - Hunts for CANVAS Spectre

Other rules

About

Tracking interesting Linux (and UNIX) malware. Send PRs

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • HTML 95.3%
  • Shell 4.1%
  • Python 0.4%
  • Perl 0.1%
  • PHP 0.1%
  • C 0.0%