Arama Sonuçları: "#SysmonForLinux"

18 sonuç
Chris Walker
Chris Walker@exeron·
I should probably take a look at auditd logs that are available and compare the telemetry to Sysmon, seeing if it's better at filling in the missing info in Sysmon. #Sysmonforlinux #Wine #Linux
English
0
0
0
40
Chris Walker
Chris Walker@exeron·
A fairly crude, yet relatively well functioned perl implant. Supports Scanning, log cleanup, DOS and arbitary command execution. Whilst it was simple it was good for 8 new sigma rules! #Sigma #SysmonforLinux #Perl #Malware 1/
Chris Walker tweet mediaChris Walker tweet mediaChris Walker tweet mediaChris Walker tweet media
English
0
0
0
172
Chris Walker
Chris Walker@exeron·
Analysis of a multi platform coin miner & generic RAT. Has persistence via crontab & systemctl, can execute shell commands & DOS certain protocols. #SysmonforLinux #RAT #CoinMiner 1/
English
0
0
0
73
Chris Walker
Chris Walker@exeron·
Running a sample which is a pyInstaller compiled ELF. The Python code is multi OS (Linux & Windows). Will post more detail on it after I've some time to look at it properly. #SysmonforLinux #PyInstaller #malware
Chris Walker tweet media
English
0
0
0
156
Chris Walker
Chris Walker@exeron·
Still need to do some work to show process graphs. This was interesting, several GTFOBins & utilises a tool to rename the binary so tools such as "ps" show something else. Also sets up a cronjob to run every 5 minutes. It uses a pid file to deduplicate runs. #sysmonforlinux
Chris Walker tweet mediaChris Walker tweet mediaChris Walker tweet mediaChris Walker tweet media
English
0
0
0
44
Chris Walker
Chris Walker@exeron·
Sysmon for Linux setup to start testing running payloads from the honeypots and other public sources. Currently collecting & processing; *process start/stop *network connections *file create/delete #Linux #Sysmonforlinux
Chris Walker tweet mediaChris Walker tweet mediaChris Walker tweet mediaChris Walker tweet media
English
0
0
0
29
RawSec
RawSec@0xrawsec·
Its been a while I did not posted on my #SysmonForLinux kind of project ! It is because it takes a lot of time to develop, here is where I am. Example, executing dig command: - we see execve event with hashes #ThreatHunting 1/6
RawSec tweet media
English
0
0
0
2.9K
RawSec
RawSec@0xrawsec·
I think I got bored waiting after #SysmonForLinux so I decided to start my own BPF based Linux monitoring project. Roadmap: - shared object loading - driver loading - dns queries - network connections Tell me if you want other stuffs for a first release ! #ThreatHunting
RawSec tweet media
English
0
0
0
0