malware-ioc
intelmq
malware-ioc | intelmq | |
---|---|---|
6 | 3 | |
1,502 | 933 | |
0.7% | 1.6% | |
6.9 | 9.0 | |
28 days ago | 20 days ago | |
YARA | Python | |
BSD 2-clause "Simplified" License | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
malware-ioc
-
What are your go-to websites to read cybersecurity news in 2023?
www.welivesecurity.com
-
Learning To Learn IT Security
WeLiveSecurity And many more.
- Open source tools and DFIR Tryhackme equivalents
-
Historic IOCs from previous APT campaigns
There are some here: https://github.com/eset/malware-ioc
-
This Linux malware is hijacking supercomputers across the globe
kabolos
-
New Linux malware steals SSH credentials from supercomputers
IOCs
intelmq
-
What are your favorite open-sources tools?
IntelMQ
- certtools/intelmq - IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol
- IntelMQ is a solution for IT security teams (CERTs & CSIRTs, SOCs, abuse departments, etc.) for collecting and processing security feeds (such as log files) using a message queuing protocol. Its main goal is to give to incident responders an easy way to collect & process threat intelligence...
What are some alternatives?
awesome-yara - A curated list of awesome YARA rules, tools, and people.
MISP - MISP (core software) - Open Source Threat Intelligence and Sharing Platform
yara - The pattern matching swiss knife
IntelOwl - IntelOwl: manage your Threat Intelligence at scale
signature-base - YARA signature and IOC database for my scanners and tools
ThePhish - ThePhish: an automated phishing email analysis tool
Loki - Loki - Simple IOC and YARA Scanner
elasticsearch-mapper-attachments - Mapper Attachments Type plugin for Elasticsearch
reversinglabs-yara-rules - ReversingLabs YARA Rules
wifiphisher - The Rogue Access Point Framework
PEpper - An open source script to perform malware static analysis on Portable Executable
rrgen - A Header Only C++ Library for Storing Safe, Randomly Generated Data Into Modern Containers