Forwarded from Blue Team
⚙️ Analysis of Ryuk Ransomware
A little quick analysis of #RYUK ransomware that prove that the group have just build some payloads only for exploit as possible the Zerologon vulnerability before fixed by the security teams.
Analysis + Yara rule ( + Zerologon) + Samples :
https://github.com/StrangerealIntel/CyberThreatIntel
🔰 @blueteamzone 🔰
A little quick analysis of #RYUK ransomware that prove that the group have just build some payloads only for exploit as possible the Zerologon vulnerability before fixed by the security teams.
Analysis + Yara rule ( + Zerologon) + Samples :
https://github.com/StrangerealIntel/CyberThreatIntel
🔰 @blueteamzone 🔰
GitHub
CyberThreatIntel/Additional Analysis/RUYK/2020-10-27/Analysis.md at master · StrangerealIntel/CyberThreatIntel
Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups - StrangerealIntel/CyberThreatIntel
Forwarded from Blue Team Alerts
OpenEDR for Windows is a free and open source platform which allows you to analyze what’s happening across your entire environment at base-security-event level. The agent records all telemetry information locally and will send the data to locally hosted or cloud hosted ElasticSeach deployments.
https://ift.tt/3ki9O5s
Discuss on Reddit: https://ift.tt/2IkbwWQ
@blueteamalerts
https://ift.tt/3ki9O5s
Discuss on Reddit: https://ift.tt/2IkbwWQ
@blueteamalerts
GitHub
GitHub - ComodoSecurity/openedr: Open EDR public repository
Open EDR public repository. Contribute to ComodoSecurity/openedr development by creating an account on GitHub.
Firejail 是一个 SUID 沙箱程序,通过限制使用 Linux 命名空间、seccomp-bpf 和 Linux 功能的不受信任应用程序的运行环境来降低安全漏洞的风险