modified in the last day

persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/registry
j.j.vannielen@utwente.nl
persistence/scheduled-tasks
0x534a@mailbox.org, j.j.vannielen@utwente.nl
persistence/screensaver
michael.hunhoff@mandiant.com
host-interaction/process/create
michael.hunhoff@mandiant.com
persistence/registry
moritz.raabe@mandiant.com
persistence/registry/appinitdlls
michael.hunhoff@fireye.com
persistence/registry/winlogon-helper
0x534a@mailbox.org, j.j.vannielen@utwente.nl
persistence/registry/run
moritz.raabe@mandiant.com
persistence/registry/ginadll
michael.hunhoff@fireye.com
persistence/service
moritz.raabe@mandiant.com
persistence/startup-folder
matthew.williams@mandiant.com, j.j.vannielen@utwente.nl
persistence/scheduled-tasks
joren485

modified in the last week

persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
persistence/file-system
j.j.vannielen@utwente.nl
anti-analysis/anti-av
jakub.jozwiak@mandiant.com

modified in the last month

linking/static/touchsocket
still@teamt5.org
runtime/dotnet
still@teamt5.org
persistence
j.j.vannielen@utwente.nl
host-interaction/wmi
michael.hunhoff@mandiant.com
linking/hooking
william.ballenthin@mandiant.com
persistence
j.j.vannielen@utwente.nl
collection
still@teamt5.org
collection/browser
still@teamt5.org
collection/browser
still@teamt5.org
persistence
j.j.vannielen@utwente.nl

modified in the last three months

host-interaction/registry/create
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/file-system/move
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/file-system/write
william.ballenthin@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/copy
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/file-system/write
jonathanlepore@google.com
host-interaction/session
michael.hunhoff@mandiant.com, jonathanlepore@google.com
collection
jonathanlepore@google.com
data-manipulation/encryption
chuong.dong@mandiant.com
host-interaction/process
matthew.williams@mandiant.com
linking/runtime-linking
moritz.raabe@mandiant.com
anti-analysis/anti-vm/vm-detection
BitsOfBinary
host-interaction/registry
matthew.williams@mandiant.com
anti-analysis/packer/nmm-protect
william.ballenthin@mandiant.com
host-interaction/driver
moritz.raabe@mandiant.com
host-interaction/os
still@teamt5.org
anti-analysis
@kulinacs, @mr-tz, mehunhoff@google.com, still@teamt5.org
linking/runtime-linking
still@teamt5.org
host-interaction/firewall/modify
jakub.jozwiak@mandiant.com
host-interaction/firewall/modify
jakub.jozwiak@mandiant.com
host-interaction/shortcut
mehunhoff@google.com
host-interaction/com
mehunhoff@google.com
host-interaction/wsh
mehunhoff@google.com
communication/websocket
mehunhoff@google.com
host-interaction/ui/automation
mehunhoff@google.com
data-manipulation/json
mehunhoff@google.com
ervinocampo@google.com
host-interaction/network/traffic/filter
jakub.jozwiak@mandiant.com
host-interaction/network/traffic/filter
jakub.jozwiak@mandiant.com
linking/static/sqlite3
wballenthin@google.com

modified in the last year

host-interaction/hardware/firmware
michael.hunhoff@mandiant.com
linking/static/minhook
jakub.jozwiak@mandiant.com
host-interaction/file-system/delete
mehunhoff@google.com
host-interaction/log/debug/write-event
michael.hunhoff@mandiant.com
moritz.raabe@mandiant.com
anti-analysis/anti-forensic/self-deletion
daniel.stepanic@elastic.co
data-manipulation/encoding/base64
still@teamt5.org
anti-analysis/anti-av
jakub.jozwiak@mandiant.com
communication/socket
jakub.jozwiak@mandiant.com
load-code/shellcode
ervin.ocampo@mandiant.com, jakub.jozwiak@mandiant.com, still@teamt5.org
communication/c2/file-transfer
jaredswilson@google.com, ervinocampo@google.com
load-code/dotnet
anushka.virgaonkar@mandiant.com, mehunhoff@google.com
host-interaction/file-system/write
joakim@intezer.com, mehunhoff@google.com
data-manipulation/encryption/hc-128
blaine.stancill@mandiant.com
linking/runtime-linking
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
anti-analysis
mehunhoff@google.com
host-interation/process
mehunhoff@google.com
host-interaction/bypass
mehunhoff@google.com
host-interaction/file-system/truncate
mehunhoff@google.com
linking/hooking
mehunhoff@google.com
host-interation/process
mehunhoff@google.com
host-interaction/bypass
mehunhoff@google.com
host-interation/process
mehunhoff@google.com
host-interaction/process/create
joakim@intezer.com, mehunhoff@google.com
host-interaction/gui
michael.hunhoff@mandiant.com
collection/keylog
michael.hunhoff@mandiant.com
compiler/dart
jakub.jozwiak@mandiant.com
host-interaction/gui/window/hide
jakub.jozwiak@mandiant.com
persistence
jakub.jozwiak@mandiant.com
host-interaction/file-system
mehunhoff@google.com
host-interaction/memory
mehunhoff@google.com
anti-analysis/anti-emulation/android
mehunhoff@google.com
host-interaction/memory
mehunhoff@google.com
host-interaction/file-system
joakim@intezer.com, mehunhoff@google.com
persistence
jakub.jozwiak@mandiant.com
persistence
jakub.jozwiak@mandiant.com
data-manipulation/encryption/dpapi
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com
compiler/go
michael.hunhoff@mandiant.com
communication/socket
michael.hunhoff@mandiant.com
communication/socket
blas.kojusner@mandiant.com
communication/socket
michael.hunhoff@mandiant.com
communication/socket
michael.hunhoff@mandiant.com
communication/socket
michael.hunhoff@mandiant.com
communication/socket/send
moritz.raabe@mandiant.com, joakim@intezer.com, anushka.virgaonkar@mandiant.com
communication/socket/udp/send
moritz.raabe@mandiant.com, joakim@intezer.com, michael.hunhoff@mandiant.com
communication/socket/receive
moritz.raabe@mandiant.com, joakim@intezer.com, michael.hunhoff@mandiant.com
communication/socket/tcp
moritz.raabe@mandiant.com, joakim@intezer.com
communication/socket/tcp
william.ballenthin@mandiant.com, joakim@intezer.com, anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
communication/dns
william.ballenthin@mandiant.com, johnk3r, joakim@intezer.com, michael.hunhoff@mandiant.com
host-interaction/process
michael.hunhoff@mandiant.com
host-interaction/thread
michael.hunhoff@mandiant.com
linking/runtime-linking
joakim@intezer.com
host-interaction/mutex
joakim@intezer.com
host-interaction/mutex
@ramen0x3f
host-interaction/mutex
@ramen0x3f
host-interaction/mutex
@ramen0x3f
host-interaction/thread/create
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, joakim@intezer.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/files/list
@_re_fox, anushka.virgaonkar@mandiant.com
host-interaction/file-system/files/list
william.ballenthin@mandiant.com
host-interaction/file-system/read
joakim@intezer.com
host-interaction/session
joakim@intezer.com
host-interaction/hardware/memory
joakim@intezer.com
joakim@intezer.com
michael.hunhoff@mandiant.com, @ramen0x3f
linking/runtime-linking
moritz.raabe@mandiant.com, joakim@intezer.com
data-manipulation/encryption/rc4
daniel.stepanic@elastic.co
data-manipulation/encryption/salsa20
moritz.raabe@mandiant.com
host-interaction/hardware/storage
william.ballenthin@mandiant.com
host-interaction/hardware/storage
william.ballenthin@mandiant.com
impact/inhibit-system-recovery
michael.hunhoff@mandiant.com
host-interaction/hardware/storage
william.ballenthin@mandiant.com
host-interaction/hardware/storage
michael.hunhoff@mandiant.com
host-interaction/driver
moritz.raabe@mandiant.com
host-interaction/driver
moritz.raabe@mandiant.com
host-interaction/driver
moritz.raabe@mandiant.com
host-interaction/hardware/storage
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
impact/wipe-disk
william.ballenthin@mandiant.com
host-interaction/process/inject
sara.rincon@mandiant.com
linking/static/hp-socket
still@teamt5.org
data-manipulation/compression
michael.hunhoff@mandiant.com, jakub.jozwiak@mandiant.com
collection/network
@_re_fox, still@teamt5.org
linking/hooking
william.ballenthin@mandiant.com
host-interation/process
william.ballenthin@mandiant.com
host-interation/process
william.ballenthin@mandiant.com
collection/network
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, echernofsky@google.com
host-interaction/file-system/files/list
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/files/list
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
collection/network
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, echernofsky@google.com
host-interaction/hardware
@mr-tz
host-interaction/thread/tls
michael.hunhoff@mandiant.com
host-interaction/thread/tls
michael.hunhoff@mandiant.com
anti-analysis
michael.hunhoff@mandiant.com
0x534a@mailbox.org, @mr-tz
0x534a@mailbox.org, @mr-tz

older

anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/read
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
communication/socket
jakub.jozwiak@mandiant.com
data-manipulation/compression
jakub.jozwiak@mandiant.com
internal/limitation/file
william.ballenthin@mandiant.com
data-manipulation/encryption/rc4
richard.weiss@mandiant.com
collection/microphone
michael.hunhoff@mandiant.com
host-interaction
michael.hunhoff@mandiant.com
host-interaction/os/info
michael.hunhoff@mandiant.com
host-interaction/hardware/camera
michael.hunhoff@mandiant.com
collection/screenshot
michael.hunhoff@mandiant.com
host-interaction
michael.hunhoff@mandiant.com
compiler/xamarin
michael.hunhoff@mandiant.com
executable/dotnet-singlefile
sara.rincon@mandiant.com
anti-analysis/anti-av
jakub.jozwiak@mandiant.com
internal/limitation/file
sara.rincon@mandiant.com
data-manipulation/encoding
jakub.jozwiak@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
host-interaction/file-system/exists
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis
michael.hunhoff@mandiant.com
executable/pe
moritz.raabe@mandiant.com
data-manipulation/encoding/base58
william.ballenthin@mandiant.com
compiler/vb
@williballenthin
host-interaction/service
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
collection/credit-card
@_re_fox
collection/screenshot
@_re_fox
persistence
jakub.jozwiak@mandiant.com
persistence
jakub.jozwiak@mandiant.com
persistence
william.ballenthin@mandiant.com
persistence
william.ballenthin@mandiant.com
persistence/office
jakub.jozwiak@mandiant.com
persistence/office
jakub.jozwiak@mandiant.com
persistence/authentication-process
jakub.jozwiak@mandiant.com
persistence/authentication-process
jakub.jozwiak@mandiant.com
persistence/authentication-process
jakub.jozwiak@mandiant.com
persistence/authentication-process
jakub.jozwiak@mandiant.com
data-manipulation/hashing/md5
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
load-code/pe
@Ana06, @mr-tz
host-interaction/session
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
jonathanlepore@google.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
collection/webcam
@johnk3r
data-manipulation/hashing/ripemd128
raymond.leong@mandiant.com
compiler/perl2exe
@_re_fox
host-interaction/process/inject
@mr-tz
host-interaction/process/modules/list
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/process/list
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/clipboard
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/service
@mr-tz
host-interaction/service
@mr-tz
host-interaction/service/stop
moritz.raabe@mandiant.com
host-interaction/thread/list
moritz.raabe@mandiant.com
host-interaction/gui/window/get-text
moritz.raabe@mandiant.com
host-interaction/file-system/delete
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/session
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/hardware/keyboard
michael.hunhoff@mandiant.com, johnk3r
collection/webcam
johnk3r
linking/runtime-linking
jakub.jozwiak@mandiant.com
linking/runtime-linking
@r3c0nst (Frank Boldewin)
communication/socket/tcp
william.ballenthin@mandiant.com
communication/c2/shell
moritz.raabe@mandiant.com
data-manipulation/compression
david@edeca.net
data-manipulation/hashing
michael.hunhoff@mandiant.com
data-manipulation/hashing/sha1
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, william.ballenthin@mandiant.com
collection/screenshot
moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com
anti-analysis/anti-forensic/clear-logs
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-evasion
michael.hunhoff@mandiant.com, jakub.jozwiak@mandiant.com
host-interaction/gui
michael.hunhoff@mandiant.com
data-manipulation/encryption
matthew.williams@mandiant.com
host-interaction/hardware/monitor
michael.hunhoff@mandiant.com
communication/http/client
anamaria.martinezgom@mandiant.com
host-interaction/hardware
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
communication/http/server
michael.hunhoff@mandiant.com
collection/network
joakim@intezeer.com
runtime
michael.hunhoff@mandiant.com
impact/inhibit-system-recovery
michael.hunhoff@mandiant.com
host-interaction/process
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/sid
michael.hunhoff@mandiant.com
host-interaction/container/docker
william.ballenthin@mandiant.com
data-manipulation/compression
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
data-manipulation/compression
anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/network/proxy
moritz.raabe@mandiant.com
communication
michael.hunhoff@mandiant.com
impact/inhibit-system-recovery
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/firewall
joakim@intezer.com
host-interaction/kernel
michael.hunhoff@mandiant.com
host-interaction/file-system
michael.hunhoff@mandiant.com
data-manipulation/hashing/md4
anamaria.martinezgom@mandiant.com
host-interaction/process/list
joakim@intezer.com
anti-analysis/anti-vm/vm-detection
echernofsky@google.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
collection/network
joakim@intezer.com
host-interaction/clipboard
michael.hunhoff@mandiant.com
data-manipulation/encryption
matthew.williams@mandiant.com
data-manipulation/encryption
matthew.williams@mandiant.com
data-manipulation/encryption
matthew.williams@mandiant.com
communication/http
michael.hunhoff@mandiant.com
host-interaction/domain
michael.hunhoff@mandiant.com
data-manipulation/hashing/sha1
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
collection
joakim@intezer.com
communication/http
william.ballenthin@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
collection/network
michael.hunhoff@mandiant.com
communication/rpc/server
michael.hunhoff@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/container/docker
william.ballenthin@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/thread
michael.hunhoff@mandiant.com
host-interaction/network/address
michael.hunhoff@mandiant.com
communication/http
anamaria.martinezgom@mandiant.com
host-interaction/accounts
michael.hunhoff@mandiant.com
host-interaction/container/docker
william.ballenthin@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
host-interaction/container/docker
william.ballenthin@mandiant.com
data-manipulation/encryption
matthew.williams@mandiant.com
collection/network
michael.hunhoff@mandiant.com
persistence
michael.hunhoff@mandiant.com
compiler/py2exe
@_re_fox
host-interaction/process
michael.hunhoff@mandiant.com
host-interaction/process
michael.hunhoff@mandiant.com
host-interaction/process/dump
michael.hunhoff@mandiant.com
host-interaction/process/create
moritz.raabe@mandiant.com
host-interaction/process/create
william.ballenthin@mandiant.com
host-interaction/process/list
@_re_fox
host-interaction/process/list
michael.hunhoff@mandiant.com
host-interaction/process/terminate
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/process/terminate
joakim@intezer.com
host-interaction/process/modify
william.ballenthin@mandiant.com
host-interaction/filter
michael.hunhoff@mandiant.com
host-interaction/filter
michael.hunhoff@mandiant.com
host-interaction/mutex
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/thread/resume
0x534a@mailbox.org, anushka.virgaonkar@mandiant.com
host-interaction/thread/suspend
0x534a@mailbox.org, anushka.virgaonkar@mandiant.com
host-interaction/thread/terminate
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/gui/logon
@_re_fox
host-interaction/gui/window/hide
michael.hunhoff@mandiant.com
host-interaction/gui/session
@_re_fox
host-interaction/gui/taskbar/find
moritz.raabe@mandiant.com
host-interaction/cli
@_re_fox
host-interaction/environment-variable
matthew.williams@mandiant.com
host-interaction/os/version
joakim@intezer.com
host-interaction/file-system
michael.hunhoff@mandiant.com
host-interaction/file-system
moritz.raabe@mandiant.com
host-interaction/file-system
blas.kojusner@mandiant.com, william.ballenthin@mandiant.com
host-interaction/file-system
david.cannings@pwc.com
host-interaction/file-system/read
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/windows-file-protection
michael.hunhoff@mandiant.com
host-interaction/file-system/meta
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/meta
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/bootloader
william.ballenthin@mandiant.com
host-interaction/session
michael.hunhoff@mandiant.com
host-interaction/hardware/cpu
moritz.raabe@mandiant.com, joakim@intezer.com
collection
moritz.raabe@mandiant.com
collection/network
@_re_fox
persistence
joakim@intezer.com
persistence
joakim@intezer.com
persistence/registry/appinitdlls
william.ballenthin@fireye.com
persistence/service
joakim@intezer.com
persistence/startup-folder
matthew.williams@mandiant.com
0x534a@mailbox.org
michael.hunhoff@mandiant.com, joakim@intezer.com
0x534a@mailbox.org
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
anti-analysis/anti-av
@_re_fox
anti-analysis/anti-av
jakub.jozwiak@mandiant.com
anti-analysis/anti-forensic
michael.hunhoff@mandiant.com
anti-analysis/anti-forensic
michael.hunhoff@mandiant.com
anti-analysis/obfuscation/string/stackstring
moritz.raabe@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
anti-analysis/anti-vm/vm-detection
@_re_fox
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/packer/generic
william.ballenthin@mandiant.com
communication
william.ballenthin@mandiant.com, joakim@intezer.com
communication
william.ballenthin@mandiant.com
communication/named-pipe/write
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
communication/ip
@mr-tz
communication/tcp/serve
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com
communication/tcp/client
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com
communication/http
william.ballenthin@mandiant.com
communication/http/client
matthew.williams@mandiant.com
communication/http/client
matthew.williams@mandiant.com
communication/http/client
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
data-manipulation/encoding/base64
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
data-manipulation/encoding/base64
michael.hunhoff@mandiant.com
data-manipulation/encoding/base64
moritz.raabe@mandiant.com
data-manipulation/checksum/luhn
@_re_fox
data-manipulation/encryption
matthew.williams@mandiant.com
data-manipulation/prng
william.ballenthin@mandiant.com, richard.weiss@mandiant.com
load-code/dotnet
michael.hunhoff@mandiant.com, blas.kojusner@mandiant.com, jakub.jozwiak@mandiant.com
host-interaction/file-system/move
michael.hunhoff@mandiant.com
executable/imprec
william.ballenthin@mandiant.com
host-interaction/network
michael.hunhoff@mandiant.com
anti-analysis/packer/simple-pack
william.ballenthin@mandiant.com
host-interaction/memory
michael.hunhoff@mandiant.com
data-manipulation/hashing/md5
william.ballenthin@mandiant.com
data-manipulation/encryption/aes
moritz.raabe@mandiant.com
data-manipulation/hashing/murmur
william.ballenthin@mandiant.com
anti-analysis/anti-vm/vm-detection
matthew.williams@mandiant.com
linking/static/jsoncpp
@mr-tz
linking/static/crypto
@mr-tz
data-manipulation/hashing/ripemd256
raymond.leong@mandiant.com
communication/dns
william.ballenthin@mandiant.com
data-manipulation/hashing
michael.hunhoff@mandiant.com
communication/dns
william.ballenthin@mandiant.com
data-manipulation/json
michael.hunhoff@mandiant.com
compiler/epl
william.ballenthin@mandiant.com
anti-analysis/packer/mpress
william.ballenthin@mandiant.com
executable/pe/section/tls
michael.hunhoff@mandiant.com
anti-analysis/packer/vprotect
william.ballenthin@mandiant.com
data-manipulation/encryption/rsa
michael.hunhoff@mandiant.com
executable/installer/installshield
moritz.raabe@mandiant.com
anti-analysis/packer/pepack
william.ballenthin@mandiant.com
data-manipulation/prng
anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
data-manipulation/hashing
michael.hunhoff@mandiant.com
executable/installer/createinstall
william.ballenthin@mandiant.com
collection/credit-card
matthew.williams@mandiant.com
host-interaction/user
michael.hunhoff@mandiant.com
communication/http
michael.hunhoff@mandiant.com
host-interaction/file-system
michael.hunhoff@mandiant.com
communication/dns
william.ballenthin@mandiant.com
host-interaction/gui
anushka.virgaonkar@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
linking/static/cppregex
william.ballenthin@mandiant.com
communication/http
michael.hunhoff@mandiant.com
anti-analysis/packer/dragon-armor
william.ballenthin@mandiant.com
host-interaction/log/clfs/append
blaine.stancill@mandiant.com
host-interaction/browser/history/list
michael.hunhoff@mandiant.com
anti-analysis/packer/rpcrypt
william.ballenthin@mandiant.com
communication/http/client
anushka.virgaonakr@mandiant.com
linking/runtime-linking
william.ballenthin@mandiant.com
host-interaction/file-system/exists
michael.hunhoff@mandiant.com
anti-analysis/packer/starforce
william.ballenthin@mandiant.com
host-interaction/memory
michael.hunhoff@mandiant.com
executable/installer/nsis
moritz.raabe@mandiant.com
host-interaction/process/terminate
anushka.virgaonkar@mandiant.com
anti-analysis/anti-vm/vm-detection
matthew.williams@mandiant.com
data-manipulation/hashing/aphash
@_re_fox
data-manipulation/hashing/sha512
jonathanlepore@google.com
communication/dns
william.ballenthin@mandiant.com
executable/installer/winzip
william.ballenthin@mandiant.com
data-manipulation/hashing/rshash
@_re_fox
host-interaction/file-system
michael.hunhoff@mandiant.com
host-interaction/os/version
michael.hunhoff@mandiant.com
data-manipulation/encryption/aes
william.ballenthin@mandiant.com, Ivan Kwiatkowski (@JusticeRage)
executable/pe/debug
william.ballenthin@mandiant.com
data-manipulation/encryption/rsa
Ana06
anti-analysis/packer/mew
william.ballenthin@mandiant.com
communication/http
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
anti-analysis/anti-vm/vm-detection
echernofsky@google.com
host-interaction/gui/window-station
william.ballenthin@mandiant.com
communication/http
michael.hunhoff@mandiant.com
persistence/startup-folder
matthew.williams@mandiant.com
host-interaction/process/terminate
william.ballenthin@mandiant.com
communication/authentication
michael.hunhoff@mandiant.com
anti-analysis/packer/ccg
william.ballenthin@mandiant.com
host-interaction/process/inject
@mr-tz
anti-analysis/packer/perplex
william.ballenthin@mandiant.com
load-code/dotnet
anushka.virgaonkar@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
data-manipulation/encoding/base64
michael.hunhoff@mandiant.com
collection
michael.hunhoff@mandiant.com
host-interaction/process
michael.hunhoff@mandiant.com
linking/runtime-linking
still@teamt5.org
linking/static/xzip
moritz.raabe@mandiant.com
load-code/dotnet
anushka.virgaonkar@mandiant.com
host-interaction/internet/cache
michael.hunhoff@mandiant.com
anti-analysis/packer/procrypt
william.ballenthin@mandiant.com
communication/dns
william.ballenthin@mandiant.com
linking/static/httplib
@mr-tz
data-manipulation/encryption/dsa
Ana06
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
data-manipulation/hashing/ripemd320
raymond.leong@mandiant.com
collection/credentials
michael.hunhoff@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
anti-analysis/packer/tsuloader
william.ballenthin@mandiant.com
anti-analysis/packer/maskpe
william.ballenthin@mandiant.com
host-interaction/process
michael.hunhoff@mandiant.com
executable/pintool
william.ballenthin@mandiant.com
host-interaction/registry
johnk3r
data-manipulation/regex
michael.hunhoff@mandiant.com
load-code/dotnet
anushka.virgaonkar@mandiant.com
data-manipulation/encryption
michael.hunhoff@mandiant.com
anti-analysis/packer/wwpack
william.ballenthin@mandiant.com
data-manipulation/encryption/ecdsa
Ana06
host-interaction/hardware/keyboard
anushka.virgaonkar@mandiant.com
communication/dns
william.ballenthin@mandiant.com
host-interaction/console
michael.hunhoff@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
data-manipulation/encryption/rsa
michael.hunhoff@mandiant.com
data-manipulation/hashing/sha256
@_re_fox
communication/dns
william.ballenthin@mandiant.com
host-interaction/file-system
michael.hunhoff@mandiant.com
data-manipulation/prng/lcg
william.ballenthin@mandiant.com
runtime/dotnet
michael.hunhoff@mandiant.com
host-interaction/os/info
joakim@intezer.com, michael.hunhoff@mandiant.com
host-interaction/wmi
anushka.virgaonkar@mandiant.com
load-code/dotnet
michael.hunhoff@mandiant.com
persistence/scheduled-tasks
michael.hunhoff@mandiant.com
anti-analysis/obfuscation
michael.hunhoff@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
host-interaction/network
michael.hunhoff@mandiant.com
communication/dns
william.ballenthin@mandiant.com
load-code/pe
@mr-tz
load-code/shellcode
ronnie.salomonsen@mandiant.com
anti-analysis/packer/shrinker
william.ballenthin@mandiant.com
host-interaction/network/routing-table
michael.hunhoff@mandiant.com
host-interaction/clipboard
anushka.virgaonkar@mandiant.com
collection/screenshot
joakim@intezer.com
communication/http/client
michael.hunhoff@mandiant.com
anti-analysis/packer/epack
william.ballenthin@mandiant.com
anti-analysis/anti-vm/vm-detection
richard.weiss@mandiant.com
data-manipulation/xml
michael.hunhoff@mandiant.com
data-manipulation/database/sql
michael.hunhoff@mandiant.com
communication/c2/file-transfer
william.ballenthin@mandiant.com
communication/dns
william.ballenthin@mandiant.com
host-interaction/file-system
william.ballenthin@mandiant.com
host-interaction/process
@Ana06
data-manipulation/encoding/xor
dan.kelly@mandiant.com
host-interaction/clipboard
anushka.virgaonkar@mandiant.com
host-interaction/uac/bypass
anamaria.martinezgom@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
communication/dns
william.ballenthin@mandiant.com
host-interaction/hardware/storage
michael.hunhoff@mandiant.com
collection/keylog
michael.hunhoff@mandiant.com
host-interaction/hardware/firmware
michael.hunhoff@mandiant.com
communication/smtp/send
michael.hunhoff@mandiant.com
compiler/exescript
jonathanlepore@google.com
load-code/dotnet/vb
michael.hunhoff@mandiant.com
host-interaction/thread/timer
michael.hunhoff@mandiant.com
anti-analysis/packer/neolite
william.ballenthin@mandiant.com
anti-analysis/packer/crunch
william.ballenthin@mandiant.com
data-manipulation/encryption/aes
william.ballenthin@mandiant.com
communication/dns
william.ballenthin@mandiant.com
communication/sms
@mr-tz
impact/cryptocurrency
moritz.raabe@mandiant.com
host-interaction/thread/task
michael.hunhoff@mandiant.com
host-interaction/process
matthew.williams@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com
data-manipulation/hashing/sha1
@_re_fox
runtime
michael.hunhoff@mandiant.com
data-manipulation/hashing/whirlpool
william.ballenthin@mandiant.com
executable/resource
joakim@intezer.com
linking/runtime-linking
still@teamt5.org
host-interaction/wmi
michael.hunhoff@mandiant.com
data-manipulation/checksum/crc32
moritz.raabe@mandiant.com
load-code/dotnet/csharp
michael.hunhoff@mandiant.com
host-interaction/internet/cache
michael.hunhoff@mandiant.com
anti-analysis/packer/enigma
william.ballenthin@mandiant.com
communication/c2/file-transfer
william.ballenthin@mandiant.com
executable/installer/wiseinstall
moritz.raabe@mandiant.com
data-manipulation/compression
michael.hunhoff@mandiant.com
anti-analysis/packer/svkp
william.ballenthin@mandiant.com
anti-analysis/anti-debugging
echernofsky@google.com
host-interaction/bootloader
william.ballenthin@mandiant.com
host-interaction/file-system
michael.hunhoff@mandiant.com
data-manipulation/encryption
michael.hunhoff@mandiant.com
collection/keylog
@mr-tz
host-interaction/recycle-bin
moritz.raabe@mandiant.com
host-interaction/process/dump
@mr-tz
host-interaction/session
michael.hunhoff@mandiant.com
host-interaction/process/list
joakim@intezer.com
collection/database/wmi
joakim@intezer.com
communication/http
michael.hunhoff@mandiant.com
data-manipulation/prng
michael.hunhoff@mandiant.com
host-interaction/registry
joakim@intezer.com
data-manipulation/hashing/jshash
@_re_fox
host-interaction/os/version
@mr-tz
host-interaction/user
michael.hunhoff@mandiant.com
linking/runtime-linking
@mr-tz
executable/hooked/api-override
william.ballenthin@mandiant.com
data-manipulation/encoding/url
michael.hunhoff@mandiant.com
anti-analysis/packer/seausfx
william.ballenthin@mandiant.com
host-interaction/process/list
anushka.virgaonkar@mandiant.com
data-manipulation/json
michael.hunhoff@mandiant.com
host-interaction/clipboard
michael.hunhoff@mandiant.com
compiler/zig
jakub.jozwiak@mandiant.com
compiler/pyarmor
@stvemillertime, @itreallynick
compiler/autohotkey
awillia2@cisco.com
compiler/v
jakub.jozwiak@mandiant.com
compiler/mingw
william.ballenthin@mandiant.com
compiler/nuitka
@williballenthin, @mr-tz
compiler/exe4j
johnk3r
compiler/autoit
william.ballenthin@mandiant.com
compiler/ps2exe
@_re_fox, jakub.jozwiak@mandiant.com
compiler/nim
michael.hunhoff@mandiant.com
compiler/d
@_re_fox
compiler/cx_freeze
@mr-tz, jakub.jozwiak@mandiant.com
compiler/delphi
william.ballenthin@mandiant.com, @mr-tz
compiler/rust
@_re_fox, william.ballenthin@mandiant.com
malware-family/plugx
still@teamt5.org
executable/resource
@mr-tz
executable/resource
@johnk3r, @mr-tz
executable/resource
william.ballenthin@mandiant.com
executable/subfile/pe
moritz.raabe@mandiant.com
executable/dotnet-singlefile
michael.hunhoff@mandiant.com
executable/pe/section/tls
michael.hunhoff@mandiant.com
executable/pe/pdb
moritz.raabe@mandiant.com
executable/pe/export
ronnie.salomonsen@mandiant.com
executable/installer/iexpress
awillia2@cisco.com
executable/installer/inno-setup
awillia2@cisco.com
host-interaction/registry
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/registry
michael.hunhoff@mandiant.com
host-interaction/registry
johnk3r
host-interaction/registry
johnk3r
host-interaction/registry
johnk3r
host-interaction/registry
johnk3r
host-interaction/registry/delete
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, johnk3r
host-interaction/registry/delete
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/firewall/modify
moritz.raabe@mandiant.com
host-interaction/software
moritz.raabe@mandiant.com, @_re_fox
host-interaction/uac/bypass
richard.cole@mandiant.com
host-interaction/uac/bypass
anamaria.martinezgom@mandiant.com
host-interaction/uac/bypass
david.cannings@pwc.com, david@edeca.net
host-interaction/uac/bypass
richard.cole@mandiant.com, david.cannings@pwc.com
host-interaction/process
william.ballenthin@mandiant.com
host-interaction/process/inject
william.ballenthin@mandiant.com
host-interaction/process/inject
jakub.jozwiak@mandiant.com
host-interaction/process/inject
michael.hunhoff@mandiant.com
host-interaction/process/inject
0x534a@mailbox.org
host-interaction/process/inject
anamaria.martinezgom@mandiant.com, 0x534a@mailbox.org
host-interaction/process/inject
moritz.raabe@mandiant.com
host-interaction/process/inject
0x534a@mailbox.org, michael.hunhoff@mandiant.com
host-interaction/process/inject
0x534a@mailbox.org
host-interaction/process/inject
michael.hunhoff@mandiant.com
host-interaction/process/inject
jakub.jozwiak@mandiant.com
host-interaction/process/inject
jakub.jozwiak@mandiant.com
host-interaction/process/inject
william.ballenthin@mandiant.com
host-interaction/process/inject
michael.hunhoff@mandiant.com
host-interaction/process/create
matthew.williams@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/process/create
@mr-tz
host-interaction/process/list
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/process/list
michael.hunhoff@mandiant.com
host-interaction/process/modify
moritz.raabe@mandiant.com
host-interaction/clipboard
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/clipboard
michael.hunhoff@mandiant.com
host-interaction/filter
aseel.kayal@mandiant.com
host-interaction/mutex
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/mutex
@_re_fox, moritz.raabe@mandiant.com
host-interaction/driver
@mr-tz
host-interaction/driver
william.ballenthin@mandiant.com
host-interaction/service
michael.hunhoff@mandiant.com
host-interaction/service
@mr-tz
host-interaction/service/delete
moritz.raabe@mandiant.com
host-interaction/service/create
moritz.raabe@mandiant.com
host-interaction/service/list
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/service/start
moritz.raabe@mandiant.com
host-interaction/service/modify
moritz.raabe@mandiant.com
host-interaction/log/winevt/access
moritz.raabe@mandiant.com
host-interaction/log/clfs/read
blaine.stancill@mandiant.com
host-interaction/gui
johnk3r, anushka.virgaonkar@mandiant.com
host-interaction/gui
jakub.jozwiak@mandiant.com
host-interaction/gui/console
michael.hunhoff@mandiant.com
host-interaction/gui/window/find
moritz.raabe@mandiant.com
host-interaction/gui/session/lock
michael.hunhoff@mandiant.com
host-interaction/gui/taskbar/hide
michael.hunhoff@mandiant.com
host-interaction/cli
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/memory
jakub.jozwiak@mandiant.com
host-interaction/environment-variable
michael.hunhoff@mandiant.com
host-interaction/environment-variable
michael.hunhoff@mandiant.com, @_re_fox
host-interaction/network/domain
awillia2@cisco.com
host-interaction/network/domain
awillia2@cisco.com, anushka.virgaonkar@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/network/domain
awillia2@cisco.com
host-interaction/network/traffic/filter
michael.hunhoff@mandiant.com
host-interaction/network/traffic/copy
michael.hunhoff@mandiant.com
host-interaction/network/connectivity
matthew.williams@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/network/connectivity
@johnk3r
host-interaction/network/interface
moritz.raabe@mandiant.com, joakim@intezer.com, anushka.virgaonkar@mandiant.com
host-interaction/network/address
moritz.raabe@mandiant.com, joakim@intezer.com
host-interaction/os
michael.hunhoff@mandiant.com
host-interaction/os/info
moritz.raabe@mandiant.com, joakim@intezer.com
host-interaction/os/version
michael.hunhoff@mandiant.com, johnk3r
host-interaction/os/version
joakim@intezer.com
host-interaction/os/hostname
moritz.raabe@mandiant.com, joakim@intezer.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system
william.ballenthin@mandiant.com
host-interaction/file-system
jakub.jozwiak@mandiant.com
host-interaction/file-system
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/read
@_re_fox
host-interaction/file-system/read
@_re_fox, michael.hunhoff@mandiant.com
host-interaction/file-system/delete
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/file-system/create
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/file-system/meta
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/file-system/meta
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/console
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com
host-interaction/bootloader
william.ballenthin@mandiant.com
host-interaction/bootloader
william.ballenthin@mandiant.com
host-interaction/bootloader
jakub.jozwiak@mandiant.com
host-interaction/bootloader
jakub.jozwiak@mandiant.com
host-interaction/session
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/session
awillia2@cisco.com
host-interaction/session
michael.hunhoff@mandiant.com
host-interaction/hardware/mouse
moritz.raabe@mandiant.com
host-interaction/hardware/storage
michael.hunhoff@mandiant.com
host-interaction/hardware/storage
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/hardware/cpu
michael.hunhoff@mandiant.com
host-interaction/hardware/cpu
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
host-interaction/hardware/memory
moritz.raabe@mandiant.com
host-interaction/hardware/cdrom
michael.hunhoff@mandiant.com
host-interaction/hardware/keyboard
michael.hunhoff@mandiant.com
host-interaction/recycle-bin
matthew.williams@mandiant.com
collection
moritz.raabe, michael.hunhoff@mandiant.com
collection
@johnk3r
collection/database/sql
william.ballenthin@mandiant.com
collection/database/wmi
michael.hunhoff@mandiant.com
collection/password-manager
@Ana06
collection/browser
@_re_fox, still@teamt5.org
collection/browser
@_re_fox, still@teamt5.org
collection/microphone
@_re_fox
collection/group-policy
william.ballenthin@mandiant.com
collection/network
jakub.jozwiak@mandiant.com
collection/network
johnk3r
collection/keylog
michael.hunhoff@mandiant.com
collection/keylog
moritz.raabe@mandiant.com
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
collection/file-managers
@_re_fox
persistence
matthew.williams@mandiant.com
persistence/exchange
jakub.jozwiak@mandiant.com
persistence/office
jakub.jozwiak@mandiant.com
persistence/scheduled-tasks
moritz.raabe@mandiant.com
moritz.raabe@mandiant.com
moritz.raabe@mandiant.com
moritz.raabe@mandiant.com
michael.hunhoff@mandiant.com
william.ballenthin@mandiant.com
moritz.raabe@mandiant.com
anti-analysis/anti-av
jakub.jozwiak@mandiant.com
anti-analysis/anti-forensic
william.ballenthin@mandiant.com, @_re_fox
anti-analysis/anti-forensic
awillia2@cisco.com
anti-analysis/anti-forensic/timestomp
moritz.raabe@mandiant.com
anti-analysis/anti-forensic/self-deletion
michael.hunhoff@mandiant.com, @mr-tz
anti-analysis/anti-disasm
awillia2@cisco.com
anti-analysis/anti-disasm
moritz.raabe@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/obfuscation
johnk3r
anti-analysis/obfuscation
jakub.jozwiak@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox, echernofsky@google.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com, @johnk3r
anti-analysis/anti-vm/vm-detection
ervin.ocampo@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
anti-analysis/anti-vm/vm-detection
anders.vejlby@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
anti-analysis/anti-vm/vm-detection
anders.vejlby@mandiant.com
anti-analysis/anti-vm/vm-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-vm/vm-detection
@_re_fox
anti-analysis/anti-vm/vm-detection
moritz.raabe@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
moritz.raabe@mandiant.com
anti-analysis/anti-debugging/debugger-detection
michael.hunhoff@mandiant.com
anti-analysis/anti-debugging/debugger-detection
moritz.raabe@mandiant.com
anti-analysis/anti-debugging/debugger-detection
moritz.raabe@mandiant.com
anti-analysis/anti-emulation/wine
@_re_fox
anti-analysis/packer/confuser
william.ballenthin@mandiant.com
anti-analysis/packer/nspack
@_re_fox
anti-analysis/packer/vmprotect
william.ballenthin@mandiant.com
anti-analysis/packer/kkrunchy
@_re_fox
anti-analysis/packer/peshield
@_re_fox
anti-analysis/packer/rlpack
@_re_fox
anti-analysis/packer/upx
william.ballenthin@mandiant.com
anti-analysis/packer/pebundle
@_re_fox
anti-analysis/packer/pelocknt
@_re_fox
anti-analysis/packer/themida
william.ballenthin@mandiant.com
anti-analysis/packer/amber
john.gorman@mandiant.com
anti-analysis/packer/gopacker
jared.wilson@mandiant.com
anti-analysis/packer/pespin
jakub.jozwiak@mandiant.com
anti-analysis/packer/petite
@_re_fox
anti-analysis/packer/upack
@_re_fox
anti-analysis/packer/pecompact
william.ballenthin@mandiant.com
anti-analysis/packer/y0da
@_re_fox
anti-analysis/packer/huan
jakub.jozwiak@mandiant.com
anti-analysis/packer/aspack
william.ballenthin@mandiant.com
linking/static
@mr-tz
linking/static/aplib
still@teamt5.org
linking/static/polarssl
william.ballenthin@mandiant.com
linking/static/msdetours
moritz.raabe@mandiant.com
linking/static/cryptopp
moritz.raabe@mandiant.com
linking/static/openssl
william.ballenthin@mandiant.com, michael.hunhoff@mandiant.com
linking/static/libcurl
moritz.raabe@mandiant.com
linking/static/sqlite3
still@teamt5.org
linking/static/sqlite3
still@teamt5.org
linking/static/wolfcrypt
jakub.jozwiak@mandiant.com
linking/static/zlib
william.ballenthin@mandiant.com
linking/static/wolfssl
jakub.jozwiak@mandiant.com
linking/runtime-linking
moritz.raabe@mandiant.com
linking/runtime-linking
moritz.raabe@mandiant.com
impact/wipe-disk/wipe-mbr
michael.hunhoff@mandiant.com
impact/inhibit-system-recovery
moritz.raabe@mandiant.com
communication/mailslot
nick.simonian@mandiant.com
communication/mailslot
william.ballenthin@mandiant.com
communication/ftp/send
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
communication/named-pipe/connect
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
communication/named-pipe/read
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
communication/named-pipe/create
matthew.williams@mandiant.com
communication/named-pipe/create
moritz.raabe@mandiant.com, michael.hunhoff@mandiant.com
communication/socket/tcp/send
jonathan.lepore@mandiant.com
communication/socket/tcp/send
michael.hunhoff@mandiant.com
communication/icmp
michael.hunhoff@mandiant.com
communication/dns
markus.neis@swisscom.com / @markus_neis
communication/c2/file-transfer
moritz.raabe@mandiant.com
communication/c2/file-transfer
moritz.raabe@mandiant.com
communication/c2/shell
matthew.williams@mandiant.com
communication/c2/shell
joakim@intezer.com
communication/c2/shell
joakim@intezer.com
communication/http
@mr-tz
communication/http
michael.hunhoff@mandiant.com
communication/http
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
communication/http
matthew.williams@mandiant.com
communication/http
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
communication/http/server
michael.hunhoff@mandiant.com
communication/http/server
michael.hunhoff@mandiant.com
communication/http/server
michael.hunhoff@mandiant.com, jakub.jozwiak@mandiant.com
communication/http/client
michael.hunhoff@mandiant.com
communication/http/client
matthew.williams@mandiant.com
communication/http/client
michael.hunhoff@mandiant.com
communication/http/client
matthew.williams@mandiant.com
communication/http/client
@mr-tz
communication/http/client
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
communication/http/client
michael.hunhoff@mandiant.com
communication/http/client
matthew.williams@mandiant.com
communication/http/client
michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
communication/http/client
michael.hunhoff@mandiant.com
communication/http/client
@mr-tz
communication/http/client
matthew.williams@mandiant.com, michael.hunhoff@mandiant.com, anushka.virgaonkar@mandiant.com
targeting/language
william.ballenthin@mandiant.com
targeting/automated-teller-machine
william.ballenthin@mandiant.com
targeting/automated-teller-machine/ncr
william.ballenthin@mandiant.com
targeting/automated-teller-machine/ncr
william.ballenthin@mandiant.com
targeting/automated-teller-machine/diebold-nixdorf
william.ballenthin@mandiant.com
targeting/automated-teller-machine/diebold-nixdorf
william.ballenthin@mandiant.com
internal/limitation/file
william.ballenthin@mandiant.com
internal/limitation/file
william.ballenthin@mandiant.com
internal/limitation/file
@mr-tz
internal/limitation/file
@mr-tz
data-manipulation/encoding/base64
gilbert.elliot@mandiant.com, sara.rincon@mandiant.com
data-manipulation/encoding/base64
moritz.raabe@mandiant.com
data-manipulation/encoding/xor
moritz.raabe@mandiant.com
data-manipulation/checksum/crc32
moritz.raabe@mandiant.com
data-manipulation/checksum/adler32
matthew.williams@mandiant.com
data-manipulation/encryption
zander.work@mandiant.com
data-manipulation/encryption
moritz.raabe@mandiant.com
data-manipulation/encryption
william.ballenthin@mandiant.com
data-manipulation/encryption/twofish
@_re_fox
data-manipulation/encryption/skipjack
@_re_fox
data-manipulation/encryption/blowfish
@_re_fox
data-manipulation/encryption/hc-128
awillia2@cisco.com
data-manipulation/encryption/aes
moritz.raabe@mandiant.com
data-manipulation/encryption/aes
moritz.raabe@mandiant.com
data-manipulation/encryption/aes
@johnk3r
data-manipulation/encryption/aes
huynh.t.nhan@gmail.com
data-manipulation/encryption/aes
william.ballenthin@mandiant.com
data-manipulation/encryption/aes
@mr-tz
data-manipulation/encryption/rsa
moritz.raabe@mandiant.com
data-manipulation/encryption/rc4
moritz.raabe@mandiant.com
data-manipulation/encryption/rc4
blaine.stancill@mandiant.com
data-manipulation/encryption/rc4
moritz.raabe@mandiant.com
data-manipulation/encryption/rc4
moritz.raabe@mandiant.com
data-manipulation/encryption/des
@_re_fox, william.ballenthin@mandiant.com
data-manipulation/encryption/des
@_re_fox
data-manipulation/encryption/tea
william.ballenthin@mandiant.com, raymond.leong@mandiant.com
data-manipulation/encryption/tea
william.ballenthin@mandiant.com, raymond.leong@mandiant.com
data-manipulation/encryption/camellia
@_re_fox
data-manipulation/encryption/xxtea
raymond.leong@mandiant.com
data-manipulation/encryption/sosemanuk
awillia2@cisco.com
data-manipulation/encryption/elliptic-curve
dimiter.andonov@mandiant.com
data-manipulation/encryption/vest
@_re_fox
data-manipulation/encryption/rc6
william.ballenthin@mandiant.com
data-manipulation/encryption/xtea
raymond.leong@mandiant.com
data-manipulation/prng
michael.hunhoff@mandiant.com, johnk3r
data-manipulation/prng/mersenne
moritz.raabe@mandiant.com
data-manipulation/json
@johnk3r
data-manipulation/svg
@johnk3r
data-manipulation/compression
jakub.jozwiak@mandiant.com
data-manipulation/compression
moritz.raabe@mandiant.com
data-manipulation/compression
david@edeca.net, david.cannings@pwc.com
data-manipulation/compression
@r3c0nst (Frank Boldewin), moritz.raabe@mandiant.com, cdong49@gatech.edu
data-manipulation/compression
matthew.williams@mandiant.com
data-manipulation/compression
blas.kojusner@mandiant.com
data-manipulation/compression
david@edeca.net, david.cannings@pwc.com
data-manipulation/hashing/tiger
@_re_fox
data-manipulation/hashing/sha384
william.ballenthin@mandiant.com
data-manipulation/hashing/sha512
william.ballenthin@mandiant.com
data-manipulation/hashing/djb2
awillia2@cisco.com, still@teamt5.org
data-manipulation/hashing/murmur
william.ballenthin@mandiant.com
data-manipulation/hashing/fnv
moritz.raabe@mandiant.com, @_re_fox, michael.hunhoff@mandiant.com
data-manipulation/hashing/sha224
moritz.raabe@mandiant.com
data-manipulation/hashing/sha256
moritz.raabe@mandiant.com, anushka.virgaonkar@mandiant.com, william.ballenthin@mandiant.com
data-manipulation/hmac
moritz.raabe@mandiant.com
runtime/dotnet
william.ballenthin@mandiant.com
runtime/dotnet
william.ballenthin@mandiant.com
load-code
blas.kojusner@mandiant.com
load-code/powershell/
anamaria.martinezgom@mandiant.com
load-code/pe
moritz.raabe@mandiant.com
load-code/pe
@Ana06
load-code/pe
moritz.raabe@mandiant.com
load-code/pe
@Ana06
load-code/shellcode
jakub.jozwiak@mandiant.com
load-code/shellcode
moritz.raabe@mandiant.com
load-code/shellcode
jakub.jozwiak@mandiant.com
load-code/shellcode
jakub.jozwiak@mandiant.com