Double Trouble: RevengeRAT and WSHRAT
https://www.fortinet.com/blog/threat-research/malware-analysis-revenge-rat-sample.html
https://www.fortinet.com/blog/threat-research/malware-analysis-revenge-rat-sample.html
Various public documents, whitepapers and articles about APT campaigns
https://github.com/kbandla/APTnotes
https://github.com/kbandla/APTnotes
GitHub
GitHub - kbandla/APTnotes: Various public documents, whitepapers and articles about APT campaigns
Various public documents, whitepapers and articles about APT campaigns - kbandla/APTnotes
Standard Windows processes: a brief reference
https://www.andreafortuna.org/2017/06/15/standard-windows-processes-a-brief-reference/
https://www.andreafortuna.org/2017/06/15/standard-windows-processes-a-brief-reference/
Andrea Fortuna
Standard Windows processes: a brief reference
Useful in forensics analysis and incident response During the analysis phase, after (for example) a system compromization, is very important to know the standard Windows processes, in order to have a ‘baseline’ useful to make a ‘diff’ with the compromised…
DynamoRIO
DynamoRIO is a runtime code manipulation system that supports code transformations on any part of a program, while it executes. DynamoRIO exports an interface for building dynamic tools for a wide variety of uses: program analysis and understanding, profiling, instrumentation, optimization, translation, etc.
https://github.com/DynamoRIO/dynamorio
DynamoRIO is a runtime code manipulation system that supports code transformations on any part of a program, while it executes. DynamoRIO exports an interface for building dynamic tools for a wide variety of uses: program analysis and understanding, profiling, instrumentation, optimization, translation, etc.
https://github.com/DynamoRIO/dynamorio
GitHub
GitHub - DynamoRIO/dynamorio: Dynamic Instrumentation Tool Platform
Dynamic Instrumentation Tool Platform. Contribute to DynamoRIO/dynamorio development by creating an account on GitHub.
sysmon-modular
a sysmon configuration repository for everybody to customise
https://github.com/olafhartong/sysmon-modular
a sysmon configuration repository for everybody to customise
https://github.com/olafhartong/sysmon-modular
sysmon-config
a sysmon configuration file for everybody to fork
https://github.com/SwiftOnSecurity/sysmon-config
a sysmon configuration file for everybody to fork
https://github.com/SwiftOnSecurity/sysmon-config
GitHub
GitHub - SwiftOnSecurity/sysmon-config: Sysmon configuration file template with default high-quality event tracing
Sysmon configuration file template with default high-quality event tracing - SwiftOnSecurity/sysmon-config