Tuesday, December 5, 2017

Threat Intelligence source:

Executive Summary
This post comprises of important things in TI (Threat Intelligence) sources and it will be helpful for the detection against threats. Even in the cases of incident handling and response purposes, CTI will be a bullet point.


Sources

http://s3.amazonaws.com/alexa-static/top-1m.csv.zip

(This is top one million sites mostly for whitelisting purpose)


https://docs.google.com/spreadsheets/u/1/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml

(APT list in spreadsheet)


https://intel.malwaretech.com/

(Botnet Tracker)



http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt

(C&C Tracker)



http://s3-us-west-1.amazonaws.com/umbrella-static/index.html

(Top one million sites- mostly for whitelisting purpose)


Conclusion
We will add more to this list in upcoming post, please watch this space.

Post by
newWorld

Setting up breakpoints in VirtualAlloc and VirtualProtect during malware analysis:

 Malware analysts add breakpoints in functions like `VirtualProtect` and `VirtualAlloc` for several key reasons: Understanding Malware Behav...