Skip to content

timb-machine/linux-malware

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

E: we have a duplicate: https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group E: we have a duplicate: https://twitter.com/Unit42_Intel/status/1653760405792014336

Rolling 7 day view of updates from this repo

Submissions?

Press/academia

In the wild

Breach reports

Supply chain attacks

Malware reports

Malware samples

Malware binaries

Malware source

Malware PoCs

Offensive research

Not necessarily malicious code (see Linikatz and unix-privesc-check =)) but interesting capabilities...

Offensive tools

Offensive techniques

Defensive research

Defensive tools

Defensive techniques

Defensive Yara

Personal rules

  • enterpriseapps2.yara (#283) - Hunts for enterprise app binaries
  • unixredflags3.yara (#285) - Hunts for UNIX red flags
  • aix.yara (#280) - Hunts for AIX binaries
  • ciscotools.yara (#279) - Hunts for references to our tools
  • luckscan.yara (#286) - Hunts for references to luckscan
  • canvasspectre.yara (#284) - Hunts for CANVAS Spectre
  • enterpriseunix2.yara (#282) - Hunts for enterprise UNIX binaries
  • pscan.yara (#287) - Hunts for references to pscan
  • adonunix2.yara (#281) - Hunts for binaries that attack AD on UNIX

Other rules

About

Tracking interesting Linux (and UNIX) malware. Send PRs

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published