Find samples containing registry run key pathways with YARA.
Category: incident response
100 Days of YARA – Day 23: socat
Detect socat with YARA.
100 Days of YARA – Day 4: Identifying Mach-O Files and Java Classes
Detect Mach-O binaries with YARA.
100 Days of YARA – Day 1: Basics
Getting started with YARA.
YARA Rules Index
YARA Rules Index
Accessibility Features Persistence
Abusing Accessibility Features as a persistence mechanism.
Malicious LNK Files
Malicious LNK files.
Scheduled Task Persistence
Some notes on finding malicious Scheduled Tasks.
Get-ChildItem Performance
I was writing some PowerShell scripts to scan disks for certain types of malware and realized that Get-ChildItem was kind of slow. I googled around and found this site which demonstrated using robocopy.exe and dir as faster alternatives to Get-ChildItem. Here were the results I had searching for LNK files on my disk using both …
Cron Persistence
All about cron persistence
REVIEW: RED TEAM Operator: Windows Evasion Course by SEKTOR7 Institute
REVIEW: RED TEAM Operator: Windows Evasion Course by SEKTOR7 Institute.
Enumerating Processes with CreateToolhelp32Snapshot
Quick and dirty example of process enumeration using CreateToolhelp32Snapshot