
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis
"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Signatures and IoCs from public Volexity blog posts.

Sophos-originated indicators-of-compromise from published reports

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Python library for extracting Indicators of Compromise, URLs, IP addresses, hashes, and email addresses from text using declarative grammars instead…

This repository contains indicators of compromise (IOCs) of our various investigations.


Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

IOCs and notes related to malware

Elastic Security Labs releases

Config extractor for AgentTesla - Discord/Telegram Variant

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

HexaLocker ransomware analysis

KrustyLoader Analysis

Public repository of Sigma and YARA rules created by Synacktiv