monty

73 posts

monty banner
monty

monty

@_montysecurity

threat hunter | profile art credit @vxunderground @pancak3lullz

Katılım Şubat 2020
233 Takip Edilen686 Takipçiler
monty
monty@_montysecurity·
C2-Tracker Update ❗️Censys support for C2-Tracker is currently disabled as searches are migrated to the new Platform syntax. Many of the queries will need to be removed in the process. Feel free to contribute new searches by opening an issue at github.com/montysecurity/…
English
1
6
20
1.2K
monty
monty@_montysecurity·
Dropped a new tool for malware researchers. It is used to continuously ingest, analyze, and alert on samples given a set of yara rules. Out of the box it works with @abuse_ch MalwareBazaar recent uploads but it's modular so you can add more sources github.com/montysecurity/…
English
1
32
135
7.1K
Marco Pedrinazzi
Marco Pedrinazzi@pedrinazziM·
Hunting #PoshC2 I think I've found a new methodology. It focuses on the 404 response's body hash of PoshC2. I've included the body hash of its latest version (2023) http.html_hash:855112502 and the previous one (2020) http.html_hash:-1700067737.
English
1
0
0
167
monty
monty@_montysecurity·
Big changes to C2 Tracker ‼️ - Added support for Censys searches 🎉 - Updates weekly on Mondays (modeled after Censys/Shodan scanning frequency) - Added multiple new C2s/malware/botnets github.com/montysecurity/…
English
0
22
96
6K
monty
monty@_montysecurity·
Dropped a new blog on hunting APT41 🐼 one of my favorite ones to put together, full of hunts for common TTPs and just things you should probably be hunting for anyway 🎯 montysecurity.medium.com/hunting-apt41-…
English
0
31
165
13K
monty
monty@_montysecurity·
@Cyb3rMonk I spent a lot of time on this question in the past. While limited to process/EDR data, the definition I came up with was "any combination of programs, files, and arguments that achieve some [MITRE] technique". Not perfect but it works for me :) montysecurity.medium.com/a-practical-gu…
English
0
1
5
234