Tim Brown

Results 258 issues of Tim Brown

### Area Defensive tools ### Parent threat _No response_ ### Finding https://github.com/ancat/egrets ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No...

new

According to my reading of https://github.com/google/re2/blob/main/doc/syntax.txt, ```((?sm).*fprintf.*fclose.*)``` should allow for multiline matches to be treated as a single line to match printf on one line, fclose on another, but this...

Add Data
Person Added

https://en.wikipedia.org/wiki/Ian_Murdock

Person Added

### Area Defensive techniques ### Parent threat Defense Evasion ### Finding https://www.forensicxlab.com/posts/inodes/ ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new

### Area Offensive techniques ### Parent threat Defense Evasion ### Finding https://github.com/akawashiro/sloader ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

confirmed

### Area Offensive tools ### Parent threat _No response_ ### Finding https://github.com/fireeye/SSSDKCMExtractor ### Industry reference attack:T1558:Steal or Forge Kerberos Tickets ### Malware reference _No response_ ### Actor reference _No response_...

confirmed

### Area Offensive tools ### Parent threat Credential Access ### Finding https://github.com/blacklanternsecurity/KCMTicketFormatter ### Industry reference attack:T1558:Steal or Forge Kerberos Tickets ### Malware reference _No response_ ### Actor reference _No response_...

confirmed

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.bitdefender.com/files/News/CaseStudies/study/319/Bitdefender-PR-Whitepaper-DarkNexus-creat4349-en-EN-interactive.pdf ### Industry reference _No response_ ### Malware reference DarkNexus ### Actor reference _No response_ ### Component Linux ###...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1027.002
missing:tag:T1053.003
missing:tag:T1560
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1562.004
missing:tag:T1037.004

### Area Defensive tools ### Parent threat _No response_ ### Finding https://github.com/chriskaliX/Hades ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1053.003
missing:tag:Non-persistentStorage
missing:tag:T1007
missing:tag:T1053.006
missing:tag:T1543.002
missing:tag:T1518
missing:tag:T1021.004
missing:tag:T1620
missing:tag:eBPF