Skip to content

Instantly share code, notes, and snippets.

@BushidoUK
Created September 28, 2024 11:13
Show Gist options
  • Save BushidoUK/c6eebfbaaa9058f508233f8551de61ab to your computer and use it in GitHub Desktop.
Save BushidoUK/c6eebfbaaa9058f508233f8551de61ab to your computer and use it in GitHub Desktop.
ossec-win32 used by Storm-0501
https://www.ossec.net/about/
OSQuery used by Storm-0501
https://www.osquery.io/
GitGuardian used by Scattered Spider*
https://www.gitguardian.com/
MAGNET RAM Capture used by Scattered Spider*
https://www.magnetforensics.com/resources/magnet-ram-capture/
Volatility used by Scattered Spider*
https://volatilityfoundation.org/
Avast Anti-Rootkit driver used by Cuba, AvosLocker, MONTI
https://www.avast.com/c-rootkit-scanner-tool
ThreatFire System Monitor driver used by RansomHub
https://web.archive.org/web/20080822102358/http://www.threatfire.com/features/
Universal Virus Sniffer used by Phobos
https://www.majorgeeks.com/files/details/universal_virus_sniffer.html
Zemana Anti-Rootkit driver used by Qilin, Akira, BlackByte
https://zemana.com/us/antimalware.html
GMER used by BlackSuit, Royal, PLAY, LockBit, Bassterlord*, Conti, 8BASE, TargetCompany, Hive, Avaddon, MONTI
http://www.gmer.net/
FileShredder used by BlackCat
https://www.fileshredder.org/
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment