SentinelLabs (SentineLabs)

SentinelLabs

SentineLabs

Geek Repo

Home Page:labs.sentinelone.com

Twitter:@labssentinel

Github PK Tool:Github PK Tool

SentinelLabs's repositories

AlphaGolang

IDApython Scripts for Analyzing Golang Binaries

Language:PythonLicense:GPL-3.0Stargazers:541Issues:17Issues:1

SentinelLabs_RevCore_Tools

The Windows Malware Analysis Reversing Core Tools

XProtect-Malware-Families

Mapping XProtect's obfuscated malware family names to common industry names.

Language:YARAStargazers:77Issues:14Issues:0

aevt_decompile

This is a work-in-progress command line tool for reversing run-only AppleScripts. It will help parse the output of applescript-disassembler.py into something more human-readable.

Language:Objective-CStargazers:60Issues:10Issues:0

macos-ttps-yara

A ruleset to find potentially malicious code in macOS malware samples

Language:YARALicense:GPL-3.0Stargazers:37Issues:2Issues:0

Memloader

Memory Loader Open Source Project by Sentinel-Labs.

Language:C++License:NOASSERTIONStargazers:20Issues:5Issues:2

PowerTrick

This is a repository for the public blog with Labs indicators of compromise and code

Language:PowerShellStargazers:18Issues:5Issues:0

Cl0p-ELF-Decryptor

Python3 script which decrypts files encrypted by flawed Cl0p ELF variant.

Language:PythonStargazers:16Issues:2Issues:0
Language:PythonLicense:NOASSERTIONStargazers:15Issues:7Issues:0
Language:JavaLicense:NOASSERTIONStargazers:12Issues:1Issues:0

TrickBot-Anchor

This is a repository for the public blog with Labs indicators of compromise.

Stargazers:11Issues:0Issues:0

aeon

Repository containing Aeon Timeline templates and example projects

SolarWinds_Countermeasures

This tool is designed to identify processes, services, and drivers that SUNBURST attempts to identify on the victim's machine.

Language:C#Stargazers:5Issues:7Issues:0

TrickBot-Deobfuscator

Code and data related to TrickBot-Deobfuscator blog

Language:PythonStargazers:5Issues:4Issues:0

Gamaredon-APT

This is a collection of relevant indicators of compromise for the main blog.

Shadowpad

Technical Indicators for SentinelLabs ShadowPad research

Yara

Public SentinelLabs Yara Rules

Language:YARAStargazers:3Issues:1Issues:0
Language:PythonStargazers:2Issues:2Issues:0

IOCs

A Collection of IOC's

Crypt1_IOCs

Massive unpacking of CryptOne samples

meteor-express

Hashes and Yara hunting rules for MeteorExpress Wiper

Language:YARAStargazers:1Issues:5Issues:0

enumerate-macos-loginitems

Xcode Playground that will return a list of all installed applications for a user that use SMLoginItem API

Stargazers:0Issues:2Issues:0

ZLoader-2021

IOCs for ZLoader Campaign 2021

Stargazers:0Issues:0Issues:0

Gootloader-iocs-q1-2021

900 SHA1 Gootloader js loader hashes plus some of the most relevant lures with the embedded URLs used for the delivery of the payloads.

Stargazers:0Issues:4Issues:0

hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Language:JavaLicense:NOASSERTIONStargazers:0Issues:0Issues:0

MOVEit-IIS-Log-Scanner

A simple script to scan IIS logs for potential exploitation of MOVEit

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:0Issues:0
Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0