vineetp6 / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

E: we have a duplicate: https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group E: we have a duplicate: https://twitter.com/Unit42_Intel/status/1653760405792014336

Rolling 7 day view of updates from this repo

Submissions?

Press/academia

In the wild

Breach reports

Supply chain attacks

Malware reports

Malware samples

Malware binaries

Malware source

Malware PoCs

Offensive research

Not necessarily malicious code (see Linikatz and unix-privesc-check =)) but interesting capabilities...

Offensive tools

Offensive techniques

Defensive research

Defensive tools

Defensive techniques

Defensive Yara

Personal rules

  • pscan.yara (#287) - Hunts for references to pscan
  • luckscan.yara (#286) - Hunts for references to luckscan
  • adonunix2.yara (#281) - Hunts for binaries that attack AD on UNIX
  • aix.yara (#280) - Hunts for AIX binaries
  • ciscotools.yara (#279) - Hunts for references to our tools
  • enterpriseapps2.yara (#283) - Hunts for enterprise app binaries
  • enterpriseunix2.yara (#282) - Hunts for enterprise UNIX binaries
  • unixredflags3.yara (#285) - Hunts for UNIX red flags
  • canvasspectre.yara (#284) - Hunts for CANVAS Spectre

Other rules

About

Tracking interesting Linux (and UNIX) malware. Send PRs

License:The Unlicense


Languages

Language:HTML 95.4%Language:Shell 4.1%Language:Python 0.4%Language:Perl 0.1%Language:PHP 0.1%Language:C 0.0%Language:YARA 0.0%