timb-machine / timb-machine/linux-malware

[Intel]: https://cloud.google.com/blog/topics/threat-intelligence/live-off-the-land-an-overview-of-unc1945/

Open
#63 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

missing:tactics missing:tag:Non-persistentStorage missing:tag:RedirectionToNull missing:tag:T1005 missing:tag:T1021.002 missing:tag:T1021.004 missing:tag:T1048 missing:tag:T1057 missing:tag:T1070.002 missing:tag:T1070.004 missing:tag:T1070.006 missing:tag:T1071.001 missing:tag:T1083 missing:tag:T1491 missing:tag:T1556.003 missing:tag:T1567 missing:tag:T1573 new
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Malware reports

Parent threat

No response

Finding

https://cloud.google.com/blog/topics/threat-intelligence/live-off-the-land-an-overview-of-unc1945/

Industry reference

No response

Malware reference

https://github.com/timb-machine/linux-malware/issues/134
SLAPSTICK

Actor reference

LightBasin
UNC1945

Component

Solaris

Scenario

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the linked Google Cloud threat-intelligence report and the SLAPSTICK reference in issue #134. Use them to document the LightBasin and UNC1945 finding, including its Solaris component, in the project's malware tracking content; done means the report and references are represented accurately.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, operating-systems, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.