/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

blog.talosintelligence.com
| | synacktiv.com
3.4 parsecs away

Travel
| | LinkPro: eBPF rootkit analysis
| | forensicitguy.github.io
9.9 parsecs away

Travel
| | In a previous blog post I mentioned how adversaries using VHD files to distribute malware can leave around a lot more data than they intend, including identifiable data for tracking. In this post I want to break out the best friend everyone made during SANS FOR508, Plaso, so I can process the filesystem data for a malicious VHD and illustrate how we can establish a timeline of operations for the adversary. Just like last time, the sample I'm working with is here in MalwareBazaar: https://bazaar.abuse.ch/sample/72ba4bd27c5d95912ac5e572849f0aaf56c5873e03f5596cb82e56ac879e3614/.
| | thehackernews.com
3.2 parsecs away

Travel
| | AI-created VS Code malware and fake npm packages reveal how attackers exploit open-source trust.
| | amperecomputing.com
27.7 parsecs away

Travel
| Ampere Computing and the Cloud Native Computing Foundation (CNCF) are launching a pilot project to provide Actuated's managed CI for GitHub Actions to a number of CNCF projects.