awesome-csirt
Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.
https://github.com/Spacial/awesome-csirt
Last synced: 14 days ago
JSON representation
-
Archs
-
ARM
- Understanding the Glibc Heap Implementation
- Heap Exploit Development - the-wild iOS 0-day. [thread](https://threader.app/thread/1168969597799866368)
- ARM Instruction Set + Simple Heap Overflow
- Use After Free
- A Simple ROP Chain
- AZM Online Arm Assembler
- Understanding the GLIBC Heap Implementation
- ARM64 Reversing and Exploitation
- ARM64 Reversing and Exploitation
- ARM Instruction Set + Simple Heap Overflow
- Use After Free
- A Simple ROP Chain
-
CTFs tools
- Hacker Finds Hidden 'God Mode' on Old x86 CPUs - > [rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge): Hardware backdoors in some x86 CPUs
- Patching Binaries with Radare2 - ARM64
- USBHarpoon
- Lexra - bit variant of the MIPS architecture.
- Potential candidate for open source bootloaders? Complete removal of Intel ME firmware possible on certain Intel HEDT/Server platforms
- Dragonblood
- Something about IR optimization
- Unfixable Seed Extraction on Trezor - A practical and reliable attack. An attacker with a stolen device can extract the seed from the device. It takes less than 5 minutes and the necessary materials cost around 100$.
- Extracting seed from Ellipal wallet
- Breaking Trezor One with Side Channel Attacks
- Rewriting Functions in Compiled Binaries
- Deep Dive
- LAB ENVIRONMENT
- A 2018 practical guide to hacking RFID/NFC
- Saleae
- Osiris
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
- IDA-scripts
- The Hacker's Hardware Toolkit
- HUB
- arm vm working out of the box for everyone
- riscv-ida - V ISA processor module for IDAPro 7.x
- mac-age
- IntelTEX-PoC
- me_cleaner
- wacker
- Deep Dive
- Statically compiled ARM binaries for debugging and runtime analysis.
- IDA-scripts
- Saleae
- A 2018 practical guide to hacking RFID/NFC
- Unfixable Seed Extraction on Trezor - A practical and reliable attack. An attacker with a stolen device can extract the seed from the device. It takes less than 5 minutes and the necessary materials cost around 100$.
- Extracting seed from Ellipal wallet
- Breaking Trezor One with Side Channel Attacks
-
Hardware
- Hacker's guide to deep-learning side-channel attacks: the theory
- Guarding Against Physical Attacks: The Xbox One Story
- BrakTooth
- Breaking the Bluetooth Pairing: Fixed Coordinate Invalid Curve Attack
- The Practical Guide to Hacking Bluetooth Low Energy
- A Practical Guide to BLE Throughput
- SkyJack
- Hacking Printers Wiki
- Full key extraction of NVIDIA™ TSEC
- The x86 architecture is the weirdo, part 2
- USB Attacks: Past, Present and Future - VTYuo&feature=youtu.be) - P4wnP1 is below on pentesting section. [wrap-up here](https://twitter.com/RoganDawes/status/1303297634858393608)
- PLATYPUS - based power side-channel attacks on Intel server, desktop and laptop CPUs.
- VoltPillager - based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface
- ToorCon 14 Badge
- Evil Logitech - erm I ment USB cable. [USB Samurai](https://infosecwriteups.com/usbsamurai-a-remotely-controlled-malicious-usb-hid-injecting-cable-for-less-than-10-ebf4b81e1d0b?gi=ade3f719f778) [For Dummies](https://infosecwriteups.com/usbsamurai-for-dummies-4bd47abf8f87)
- Common BMC vulnerabilities and how to avoid repeating them - 18/Wed-August-8/us-18-Waisman-Soler-The-Unbearable-Lightness-of-BMC.pdf) [Perilous Peripherals: The Hidden Dangers Inside Windows & Linux Computers](https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/)
- Exploiting IoT enabled BLE smart bulb security
- Cracking WiFi at Scale with One Simple Trick
- Car hijacking swapping a single bit
- Hacking a VW Golf Power Steering ECU - Part 1, [Part 2](https://blog.willemmelching.nl/carhacking/2022/01/02/vw-part2/) [Part 3](https://blog.willemmelching.nl/carhacking/2022/01/02/vw-part3/) and [Part 4](https://blog.willemmelching.nl/carhacking/2022/01/02/vw-part4/). [VW PQ35 EPS flasher](https://github.com/pd0wm/pq-flasher)
- Reverse Engineering Yaesu FT-70D Firmware Encryption
- Reverse-engineering an airspeed/Mach indicator from 1977
- Breaking the Bluetooth Pairing: Fixed Coordinate Invalid Curve Attack
- hcxdumptool
- Wifi-Ducky-ESPUSB
- Analyzing a buffer overflow in the DLINK DIR-645 with Qiling framework, Part I
- HammerKit - source library for inducing and characterizing rowhammer that provides out-of-the-box support for Chrome OS platforms.
- BLEAH
- ESP8266 Deauther Version 2
- Airspy-Utils
- infernal-twin - This is automated wireless hacking tool
- SkyJack
- eaphammer - Enterprise networks. Indirect wireless pivots using hostile portal attacks.
- whereami
- Hacking Kia: Remotely Controlling Cars With Just a License Plate
- BMC-Tools
- Hacking Printers Wiki
- awesome flipper
- Dark Flipper
- My Flipper Shits
- Unlocking free WiFi on British Airways
- Valetudo - only operation. [repo](https://github.com/Hypfer/Valetudo)
- USB Attacks: Past, Present and Future - VTYuo&feature=youtu.be) - P4wnP1 is below on pentesting section. [wrap-up here](https://twitter.com/RoganDawes/status/1303297634858393608)
- Hacker's guide to deep-learning side-channel attacks: the theory
- Stepping Insyde System Management Mode
- Valetudo - only operation. [repo](https://github.com/Hypfer/Valetudo)
-
-
Articles
-
Sans
- [1808.00659
- [1809.08325
- DeepMasterPrints: Generating MasterPrints for Dictionary Attacks via Latent Variable Evolution
- Stealing Webpages Rendered on Your Browser by Exploiting GPU Vulnerabilities
- The Hunt for 3ve
- Page Cache Attacks - agnostic side-channel attack that targets one of the most fundamental software caches in modern computer systems: the operating system page cache.
- Identification and Illustration of Insecure Direct Object References and their Countermeasures
- China’s Maxim
- Listen to Your Key: Towards Acoustics-based Physical Key Inference
- Mailto: Me Your Secrets. On Bugs and Features in Email End-to-End Encryption
- Everything Old is New Again: Binary Security of WebAssembly
- Discovering Suspicious APT Behaviors by Analyzing DNS Activities
- Harvard Belfer National Cyber Power Index 2020
- Quantum Blockchain using entanglement in time
- Reflections on Trusting Trust
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op Caches
- BIAS: Bluetooth Impersonation AttackS
- LOKI: Hardening Code Obfuscation Against Automated Attacks
- FPGA-Based Near-Memory Acceleration of Modern Data-Intensive Applications
- China’s Maxim
- The Accidental Altruist: Inferring Altruism from an Extraterrestrial Signal
- Interstellar communication. IX. Message decontamination is impossible
- The Accidental Altruist: Inferring Altruism from an Extraterrestrial Signal
- Quantum Blockchain using entanglement in time
- LOKI: Hardening Code Obfuscation Against Automated Attacks
- The Accidental Altruist: Inferring Altruism from an Extraterrestrial Signal
- The Accidental Altruist: Inferring Altruism from an Extraterrestrial Signal
- Discovering Suspicious APT Behaviors by Analyzing DNS Activities
- Harvard Belfer National Cyber Power Index 2020
- Reflections on Trusting Trust
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op Caches
-
-
Blue Team
-
IoCs
- CVE-2020-1472 Zerologon IoCs
- Ryuk Speed Run, 2 Hours to Ransom
- What did DeathStalker hide between two ferns?
- Yikes, Microsoft have signed multiple rootkits (which allow kernel drivers) and reach out to a remote IP
- Netfilter Rootkit Samples
- There are evil packages on the npm registry that deploy XMRIG
- 238 Cobalt Strike stage 2 IP's, with 238 unique configurations, identified today.
- IcedID | 31.08.2022 | Campaign 2786525712
- Feodo Tracker
- Emotet 2022 | epoch4 | 22.04.2022 |
- sophos labs IoCs - originated indicators-of-compromise from published
- DailyIOC
- iocs
- Threat intelligence and threat detections
- APT_Digital_Weapon - AnXin.
- malware-IoC
- Yikes, Microsoft have signed multiple rootkits (which allow kernel drivers) and reach out to a remote IP
- There are evil packages on the npm registry that deploy XMRIG
- 238 Cobalt Strike stage 2 IP's, with 238 unique configurations, identified today.
- malware-IoC
-
SIEM
- Suspicious Use of Procdump
- KrbRelayUp local privilege escalation.
- Events Heatmap
- Heatmaps Make Ops Better
- Auditing Continuously vs. Monitoring Continuously
- Auditing Continuously vs. Monitoring Continuously
- Logsspot
- Scalable Logging and Tracking
- Scalable Logging and Tracking
- Logs were our lifeblood. Now they're our liability.
- Using Flume to Collect Apache 2 Web Server Logs
- spectx
- The log/event processing pipeline you can't have
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Here's a Splunk way to score behaviors that are derived from detections
- The Log Pile
- Part of my role is ensuring we're *not* EDR-centric. We have to be able to detect threats w/o OS-level viz (e.g., control plane only), using auth/net events, or whatever data is in a SIEM
- Shipping to Elasticsearch Microsoft DNS Logs
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Using Flume to Collect Apache 2 Web Server Logs
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Log Parser Lizard
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
- Auditing Continuously vs. Monitoring Continuously
- Scalable Logging and Tracking
- Building a SIEM: combining ELK, Wazuh HIDS and Elastalert for optimal performance
-
Programming Languages
Categories
Pentesting
1,204
Operating Systems
781
Blue Team
415
Malware Analysis
383
Reverse Engineering
253
Tools
236
Secure Programming
187
Resources
176
Mobile
152
Exfiltration
94
Hardening
92
Archs
92
General
91
Forensics
82
Links
79
CTFs
57
Browsers
55
Fun
52
Articles
31
DNS
31
Sources
30
Risk Assessment and Vulnerability Management
28
Privacy
28
Credentials
26
Phishing
20
ICS (SCADA)
17
Radio
15
Social Engineering
10
psyops
9
Phreak
8
Books
7
CVEs
7
Frameworks
3
Patching
1
Other Repos
1
Sub Categories
Windows
634
Payloads
443
Malware Articles and Sources
273
ARM
216
Hashing
181
Satellite
174
SIEM
167
Threat Hunting
148
Sans
140
Volatility
129
Secure Sharing
128
macOS/iOS
128
ShellCodes
119
Purple Team
106
Conferences and Slides
95
Steganography
90
Exploits
85
Ghidra
80
Tokens
80
Red Team
77
OSINT - Open Source INTelligence
76
Linux/ *Nix
76
API
75
Malware Samples
68
Reporting
63
Training and Certifications
58
Vulnerability
55
WebServers
52
CTFs tools
50
Hardware
46
Ransomwares
44
Enumeration
43
Guidelines
36
VPN
34
Secure Web dev
33
AWS
33
Browsers Addons
32
Fuzzing
30
Incident Response
29
Android
28
WAFs
23
Cloud
23
Virus/Anti-Virus
22
SAST
22
IoCs
20
Search Engines
15
Yara
13
PDF
13
Repos
10
Azure
9
Reconnaissance
8
Note-taking
8
Configs
7
Decompilers
6
Web Malwares
6
Distros
6
UEFI
6
WebShells
5
Shell tools
4
Email Headers
4
Trojans/Loggers
3
Formal Analysis
3
Web Training
3
GCP/Google
2
Kali
2
IP Reputation
2
Keywords
security
133
python
57
hacking
49
security-tools
48
pentesting
47
linux
41
reverse-engineering
40
bugbounty
37
windows
34
malware
33
penetration-testing
30
osint
29
malware-analysis
29
dfir
26
cybersecurity
26
infosec
25
pentest
23
threat-hunting
22
golang
20
threat-intelligence
20
python3
20
redteam
17
vulnerability
16
scanner
15
incident-response
14
forensics
14
reconnaissance
14
awesome-list
14
red-team
14
cli
13
pentest-tool
13
powershell
13
static-analysis
13
rust
13
recon
13
malware-research
12
macos
12
phishing
12
ctf
12
fuzzing
12
awesome
12
hacking-tool
11
c2
10
automation
10
security-audit
10
information-security
10
dns
10
docker
10
payload
10
vulnerability-scanners
10