-
Notifications
You must be signed in to change notification settings - Fork 91
Issues: timb-machine/linux-malware
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
[Intel]: https://github.com/avilum/secimport
missing:tag:eBPF
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1059.006
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
new
#748
opened Aug 18, 2023 by
timb-machine
[Intel]: https://github.com/codewhitesec/daphne
missing:tag:Auditd
missing:tag:T1003.008
missing:tag:T1005
missing:tag:T1007
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1053.006
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1543.002
missing:tag:T1562.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.007
new
#740
opened Aug 12, 2023 by
timb-machine
[Intel]: https://code-white.com/blog/2023-08-blindsiding-auditd-for-fun-and-profit/
new
#739
opened Aug 12, 2023 by
timb-machine
[Intel]: https://github.com/DavidBuchanan314/stelf-loader
ignore:tag:RedirectionToNull
missing:tag:ProcessTreeSpoofing
missing:tag:T1001
missing:tag:T1005
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
new
#738
opened Aug 12, 2023 by
timb-machine
[Intel]: https://hckng.org/articles/perljam-elf64-virus.html
missing:tag:ProcessTreeSpoofing
missing:tag:T1005
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1222
missing:tag:T1491
missing:tag:T1548.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#735
opened Aug 12, 2023 by
timb-machine
[Intel]: https://github.com/codewhitesec/apollon
missing:tag:Auditd
missing:tag:T1003.008
missing:tag:T1005
missing:tag:T1007
missing:tag:T1027.004
missing:tag:T1048
missing:tag:T1053.006
missing:tag:T1057
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1543.002
missing:tag:T1546.004
missing:tag:T1562.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.007
new
#734
opened Aug 10, 2023 by
timb-machine
[Intel]: https://www.lab539.com/blog/linux-malware-detection-with-limacharlie
new
#728
opened Aug 4, 2023 by
timb-machine
[Intel]: https://blog.aquasec.com/teamtnt-reemerged-with-new-aggressive-cloud-campaign
new
#727
opened Jul 15, 2023 by
timb-machine
[Intel]: https://github.com/marin-m/vmlinux-to-elf
missing:tag:IRC
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1518
missing:tag:T1548.003
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#726
opened Jul 15, 2023 by
timb-machine
[Intel]: https://www.trendmicro.com/en_us/research/23/g/detecting-bpfdoor-backdoor-variants-abusing-bpf-filters.html
missing:tag:T1040
missing:tag:T1048
missing:tag:T1053.003
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1205
missing:tag:T1518
missing:tag:T1590
new
#725
opened Jul 15, 2023 by
timb-machine
[Intel]: https://github.com/89luca89/pakkero
missing:tag:IRC
missing:tag:Non-persistentStorage
missing:tag:ProcessTreeSpoofing
missing:tag:T1005
missing:tag:T1027.002
missing:tag:T1048
missing:tag:T1053.007
missing:tag:T1057
missing:tag:T1059.006
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.006
missing:tag:T1574.007
missing:tag:T1590
missing:tag:T1609
missing:tag:T1610
new
#718
opened Jul 14, 2023 by
timb-machine
[Intel]: https://sysdig.com/blog/cloud-defense-in-depth/
new
#713
opened Jul 9, 2023 by
timb-machine
[Intel]: https://github.com/aviat/passe-partout
missing:tag:Non-persistentStorage
missing:tag:RedirectionToNull
missing:tag:T1003.007
missing:tag:T1005
missing:tag:T1021.004
missing:tag:T1048
missing:tag:T1055.008
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1098.004
missing:tag:T1215
missing:tag:T1491
missing:tag:T1548.003
missing:tag:T1552.004
missing:tag:T1553.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1622
new
#704
opened Jun 25, 2023 by
timb-machine
[Intel]: https://github.com/nicocha30/ligolo-ng
missing:tag:Go
missing:tag:T1005
missing:tag:T1021.001
missing:tag:T1048
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1205
missing:tag:T1491
missing:tag:T1548.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
new
#699
opened Jun 25, 2023 by
timb-machine
[Intel]: https://www.trendmicro.com/en_us/research/23/e/investigating-blacksuit-ransomwares-similarities-to-royal.html
missing:tag:T1021.002
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1546.004
missing:tag:T1562.001
missing:tag:T1590
missing:tag:wltm
new
#698
opened Jun 25, 2023 by
timb-machine
ProTip!
Mix and match filters to narrow down what you’re looking for.