Submitting the form

All results for 'Anthony Faruna'

Showing 8 of 8 results

Blackbit ransomware detection with Wazuh

Blog / Engineering / Blackbit ransomware detection with Wazuh

...'C:\Program Files (x86)\ossec-agent\active-response\bin\yara\rules\' 4. Edit the C:\Program Files e(x86)\ossec-agent\active-response\bin\yara\rules\yara_rules.yar file and add the following Blackbit YARA rules: rule _Blackbit_ransomware { meta: description = "Blackbit executable detection" author = "Anthony Faruna"...

Kuiper ransomware detection and response with Wazuh

Blog / Engineering / Kuiper ransomware detection and response with Wazuh

...meta: description = "Kuiper ransomware executable detection" author = "Anthony Faruna" reference = "https://github.com/Neo23x0/yarGen" date = "2024-03-28" strings: $s1 = "os.(*ProcessState).Sys" fullword ascii $s2 = "os.(*ProcessState).sys" fullword ascii $s3 =...

Detecting Lockbit 3.0 ransomware with Wazuh

Blog / Engineering / Detecting Lockbit 3.0 ransomware with Wazuh

Lockbit malware is regarded as one of the most notorious and active ransomware  in existence since 2019. Lockbit ransomware makes use of a broad range of techniques to target critical...

Monitoring SFX archives with Wazuh

Blog / Engineering / Monitoring SFX archives with Wazuh

Self-extracting archives (SFX) are executables that contain compressed data with a built-in code to extract the data when it executes. They are commonly used for packaging and distributing software installers,...

CrossLock ransomware detection with Wazuh

Blog / Engineering / CrossLock ransomware detection with Wazuh

CrossLock ransomware is a recent strain of ransomware developed using the Go programming language, making it harder to reverse engineer. The ransomware is capable of infecting several platforms, including Windows...

No results for 'Anthony Faruna'

Please make sure that all words are spelled correctly.