Skip to content

Tracking interesting Linux (and UNIX) malware. Send PRs

License

Notifications You must be signed in to change notification settings

CiscoCXSecurity/linux-malware

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Rolling 7 day view of updates from this repo

Submissions?

Press/academia

In the wild

Breach reports

Supply chain attacks

Malware reports

Malware samples

Malware binaries

Malware source

Malware PoCs

Offensive research

Not necessarily malicious code (see Linikatz and unix-privesc-check =)) but interesting capabilities...

Offensive tools

Offensive techniques

Defensive research

Defensive tools

Defensive techniques

Defensive Yara

Personal rules

  • pscan.yara (#287) - Hunts for references to pscan
  • luckscan.yara (#286) - Hunts for references to luckscan
  • adonunix2.yara (#281) - Hunts for binaries that attack AD on UNIX
  • aix.yara (#280) - Hunts for AIX binaries
  • ciscotools.yara (#279) - Hunts for references to our tools
  • enterpriseapps2.yara (#283) - Hunts for enterprise app binaries
  • enterpriseunix2.yara (#282) - Hunts for enterprise UNIX binaries
  • unixredflags3.yara (#285) - Hunts for UNIX red flags
  • canvasspectre.yara (#284) - Hunts for CANVAS Spectre

Other rules

About

Tracking interesting Linux (and UNIX) malware. Send PRs

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • HTML 99.0%
  • Python 0.4%
  • Shell 0.4%
  • Perl 0.1%
  • PHP 0.1%
  • C 0.0%