elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.96k stars 500 forks source link

[Meta] Linux Ransomware Analysis - Cl0p & BlackCat #2936

Closed Aegrah closed 1 year ago

Aegrah commented 1 year ago

Summary

Dynamic/Static analysis of most recent blackcat, cl0p, and royal ransomware samples to identify unique characteristics across the entirety of the MITRE ATT&CK matrix.

### Tasks
- [ ] collect and study public documentations (blogs, whitepapers etc.) - week 1
- [ ] collect samples - week 1
- [ ] test coverage and identify gaps - week 1/2
- [ ] tune or write new rules - week 2

Goals

Resources:

https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available/

botelastic[bot] commented 1 year ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

botelastic[bot] commented 1 year ago

This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment.