Internet Storm Center
Sign In
Sign Up
Watch ISC TV. Great for NOCs, SOCs and Living Rooms:
https://isctv.sans.edu
Handler on Duty:
Guy Bruneau
Threat Level:
green
Date
Author
Title
2023-03-18
Xavier Mertens
Old Backdoor, New Obfuscation
2023-03-11
Xavier Mertens
Overview of a Mirai Payload Generator
2023-03-01
Xavier Mertens
Python Infostealer Targeting Gamers
2023-02-09
Xavier Mertens
A Backdoor with Smart Screenshot Capability
2022-11-14
Jesse La Grew
Extracting 'HTTP CONNECT' Requests with Python
2022-10-24
Xavier Mertens
C2 Communications Through outlook.com
2022-10-18
Xavier Mertens
Python Obfuscation for Dummies
2022-09-26
Xavier Mertens
Easy Python Sandbox Detection
2022-09-14
Xavier Mertens
Easy Process Injection within Python
2022-08-19
Johannes Ullrich
Windows Security Blocks UPX Compressed (packed) Binaries
2022-08-18
Johannes Ullrich
Honeypot Attack Summaries with Python
2022-07-20
Xavier Mertens
Malicious Python Script Behaving Like a Rubber Ducky
2022-06-24
Xavier Mertens
Python (ab)using The Windows GUI
2022-05-24
Yee Ching Tok
ctx Python Library Updated with "Extra" Features
2022-04-21
Xavier Mertens
Multi-Cryptocurrency Clipboard Swapper
2022-01-20
Xavier Mertens
RedLine Stealer Delivered Through FTP
2022-01-07
Xavier Mertens
Custom Python RAT Builder
2022-01-06
Xavier Mertens
Malicious Python Script Targeting Chinese People
2021-12-10
Xavier Mertens
Python Shellcode Injection From JSON Data
2021-12-01
Xavier Mertens
Info-Stealer Using webhook.site to Exfiltrate Data
2021-08-30
Xavier Mertens
Cryptocurrency Clipboard Swapper Delivered With Love
2021-07-16
Xavier Mertens
Multiple BaseXX Obfuscations
2021-07-08
Xavier Mertens
Using Sudo with Python For More Security Controls
2021-07-06
Xavier Mertens
Python DLL Injection Check
2021-07-02
Xavier Mertens
"inception.py"... Multiple Base64 Encodings
2021-06-11
Xavier Mertens
Keeping an Eye on Dangerous Python Modules
2021-05-31
Rick Wanner
Quick and dirty Python: nmap
2021-05-04
Rick Wanner
Quick and dirty Python: masscan
2021-04-29
Xavier Mertens
From Python to .Net
2021-04-09
Xavier Mertens
No Python Interpreter? This Simple RAT Installs Its Own Copy
2021-04-02
Xavier Mertens
C2 Activity: Sandboxes or Real Victims?
2021-03-18
Xavier Mertens
Simple Python Keylogger
2020-12-10
Xavier Mertens
Python Backdoor Talking to a C2 Through Ngrok
2020-11-20
Xavier Mertens
Malicious Python Code and LittleSnitch Detection
2020-11-09
Xavier Mertens
How Attackers Brush Up Their Malicious Scripts
2020-10-20
Xavier Mertens
Mirai-alike Python Scanner
2020-10-14
Xavier Mertens
Nicely Obfuscated Python RAT
2020-09-18
Xavier Mertens
A Mix of Python & VBA in a Malicious Word Document
2020-09-03
Xavier Mertens
Sandbox Evasion Using NTP
2020-09-02
Xavier Mertens
Python and Risky Windows API Calls
2020-08-18
Xavier Mertens
Using API's to Track Attackers
2020-07-30
Johannes Ullrich
Python Developers: Prepare!!!
2019-10-29
Xavier Mertens
Generating PCAP Files from YAML
2018-11-26
Russ McRee
ViperMonkey: VBA maldoc deobfuscation
2017-11-23
Xavier Mertens
Proactive Malicious Domain Search
2017-10-05
Johannes Ullrich
pcap2curl: Turning a pcap file into a set of cURL commands for "replay"
2017-08-22
Xavier Mertens
Defang all the things!
2017-04-19
Xavier Mertens
Hunting for Malicious Excel Sheets
2017-01-12
Mark Baggett
System Resource Utilization Monitor
2017-01-01
Didier Stevens
py2exe Decompiling - Part 1
2016-11-27
Russ McRee
Scapy vs. CozyDuke
2016-07-25
Didier Stevens
Python Malware - Part 4
2016-07-16
Didier Stevens
Python Malware - Part 3
2016-05-15
Didier Stevens
Python Malware - Part 1
2014-12-04
Mark Baggett
Automating Incident data collection with Python
2011-02-21
Adrien de Beaupre
What’s New, it's Python 3.2
2010-08-15
Manuel Humberto Santander Pelaez
Python to test web application security
2010-06-14
Manuel Humberto Santander Pelaez
Python on a microcontroller?
2010-03-30
Marcus Sachs
Zigbee Analysis Tools
2010-02-17
Rob VandenBrink
Multiple Security Updates for ESX 3.x and ESXi 3.x
2009-05-25
Jim Clausing
More tools for (US) Memorial Day
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Forums
Auditing
Diary Discussions
Forensics
General Discussions
Industry News
Network Security
Penetration Testing
Software Security
Contact Us
Contact Us
About Us
Handlers
Slack Channel
Mastodon
Twitter
Make the web a better place by
sharing the SANS Internet Storm Center
with others