Plus d'informations : Post de Boni Yeamin

État de l’art

https://start.me/p/wMrA5z/cyber-threat-intelligence

IP & URL Reputation

1. Virus Total : https://www.virustotal.com/gui/home/upload
2. URL Scan : https://urlscan.io/
3. AbuseIPDB : https://www.abuseipdb.com/
4. Cisco Talos : https://www.talosintelligence.com
5. IBM X-Force : https://exchange.xforce.ibmcloud.com/
6. URL Filtering(Palo Alto) : https://urlfiltering.paloaltonetworks.com/
7. URL Filtering(Symantec) : https://sitereview.bluecoat.com/
8. IP Void : https://www.ipvoid.com/
9. URL Void : https://www.urlvoid.com/

2- File | Hash | Search | Analysis | Sandboxing

1. File Extension : https://filesec.io/
2. LOLBAS : https://lolbas-project.github.io/
3. GTFOBins : https://gtfobins.github.io/
4. File Hash Check : https://www.virustotal.com/gui/home/search
5. Hash Search : https://valkyrie.comodo.com/
6. Hash Search : https://www.malwares.com/
7. MetaDefender : https://metadefender.opswat.com/
8. Kaspersky Threat Intel. : https://opentip.kaspersky.com/#search/
9. Cuckoo Sabdbox : https://cuckoosandbox.org/
10. AnyRun >> Online sandboxing : https://any.run/
11. Hybrid-Analysis : https://www.hybrid-analysis.com/
12. Joe Sandbox : https://www.joesandbox.com/#windows
13. VMRay Sandbox : https://www.vmray.com/
14. Triage : http://tria.ge/
15. Browser Sandbox : https://www.browserling.com/

3- Getting File hash

HashTools> Windows : https://www.binaryfortress.com/HashTools/

Powershell :
Get-FileHash -Path C:\path\to\file.txt -Algorithm MD5
Get-FileHash -InputObject "This is a string" -Algorithm MD5

QuickHash > MacOS : https://www.quickhash-gui.org/

Terminal: shasum -a 256 filename

4- Find Suspicious Artifacts | Reverse Engineer | Debug Files

1. PeStudio : https://www.winitor.com/download
2. CFF Explorer : https://ntcore.com/?page_id=388
3. DocGuard files : https://www.docguard.io/
4. File Scan : https://www.filescan.io/scan
5. Ghidra : https://ghidra-sre.org/
6. IDA Pro : https://hex-rays.com/ida-pro/
7. Radare2/Cutter : https://rada.re/n/radare2.html
 : https://www.kali.org/tools/radare2-cutter/

5- Monitor System Resources | Detect malware

1. Process Hacker : https://processhacker.sourceforge.io/
2. Process Monitor : https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
3. ProcDot : https://www.procdot.com/
4. Autoruns : https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
5. TcpView : https://learn.microsoft.com/en-us/sysinternals/downloads/tcpview

6- Web proxy

Fiddler : https://www.telerik.com/download/fiddler

7- Malware Samples - Abuse.ch

1. MalwareBazaar : https://bazaar.abuse.ch/
2. FeodoTracker : https://feodotracker.abuse.ch/
3. SSLBlacklist : https://sslbl.abuse.ch/
4. URLHaus : https://urlhaus.abuse.ch/
5. ThreatFox : https://threatfox.abuse.ch/
6. YARAIfy : https://yaraify.abuse.ch/

8- Malware Traffic | Pcap & Malware Samples

1. Malware Trafic Analysis : https://www.malware-traffic-analysis.net/

9- Free Malware Analysis Trainings

1. Malware Analysis BootCamp : https://www.youtube.com/watch?v=uHhKkLwT4Mk&list=PLBf0hzazHTGMSlOI2HZGc08ePwut6A2Io
2. Malware Analysis In 5+ Hours : https://www.youtube.com/watch?v=qA0YcYMRWyI

List from Priom Biswas
#allhandsondeck #saturdaymotivation #malwareanalysis #sharingiscaring #cybersaint

10- MITRE Different Frameworks

1. ATT&CK : https://attack.mitre.org/
2. D3FEND : https://d3fend.mitre.org/
3. ENGAGE : https://engage.mitre.org/
4. ATLAS : https://atlas.mitre.org/
5. CREF NAVIGATOR : https://crefnavigator.mitre.org/
6. ATT&CK NAVIGATOR : https://mitre-attack.github.io/attack-navigator/
7. CAR : https://car.mitre.org/
8. CAPEC : https://capec.mitre.org/
9. INSIDER THREAT FRAMEWORK : https://insiderthreat.mitre.org/
10. SAF : https://saf.mitre.org/
11. INNOVATION TOOLKIT : https://itk.mitre.org/

MAEC : https://maecproject.github.io/
SPARTA (not MITRE) : https://lnkd.in/drm5f9ZQ

Accueil > Notes Techniques > Sécurité Informatique > SSI Analysis and Tools 2023