Chris Walker retweetledi
Chris Walker
75 posts

Chris Walker
@exeron
Working onunderstanding the Linux threat landscape better. SOC, TH & IR for 10 years.
Katılım Eylül 2020
434 Takip Edilen9 Takipçiler
Chris Walker retweetledi

THC RELEASE: 🔐SSH public keys can be infected 💉and backdoored.🚪
blog.thc.org/infecting-ssh-… #lulz #ssh #hacking

English
Chris Walker retweetledi

Persistence || Backdoor Techniques (Beginner to Advanced) in Linux infosecwriteups.com/persistence-ba…
English
Chris Walker retweetledi

Here is an experimental Linux anti-ransomware kernel module project below.
Clandestine@akaclandestine
English
Chris Walker retweetledi
Chris Walker retweetledi


I've got the current, but early version of my auditd log parser library published into Pypi. Currently it can parse process (execve) and network connect events. It also attempts to add edges (GUIDs) to the events.
github.com/exeronn/auditd…
"pip install auditd-python-parser"


English
Chris Walker retweetledi

Now there's (a more detailed) blog post on this all!
Just posted: "Ironing out (the macOS details) of a Smooth Operator"
objective-see.org/blog/blog_0x73…
English

I've used this auditd config from github.com/Neo23x0/auditd… that @cyb3rops put together. To fully replicate the same data as SysmonForLinux I'll need to add a couple of lines to record all process events. This has a data volume impact, but allows for better process ancestry.
English
Chris Walker retweetledi

An unknown 🐼APT discovered by ExaTrack🔥Our team identified an implant and a rootkit targeting Linux systems 🔎We traced the infrastructure used by the attackers and analyzed their backdoors to share a blog post and 70 indicators (including 3 Yara rules)! blog.exatrack.com/melofee/
English
Chris Walker retweetledi

(1/2)
Very cool series by @__pberba__ about persistence in Linux environments
Persistence map: pberba.github.io/assets/posts/c…
Auditd, Sysmon, Osquery: pberba.github.io/security/2021/…
Account Creation and Manipulation: pberba.github.io/security/2021/…
#Linux #kernel #malware #cybersecurity




English
Chris Walker retweetledi

Quick Linux tip 💡
Easily find your gateway IP using the ping command!
$ ping _gateway
It's one of the hidden ping options and not many people know about it.
Follow us @LinuxHandbook for more such Linux tips daily 🐧🙏

English

I should probably take a look at auditd logs that are available and compare the telemetry to Sysmon, seeing if it's better at filling in the missing info in Sysmon.
#Sysmonforlinux #Wine #Linux
English











