Indicators of Compromises (IOC) of our various investigations
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Repository of yara rules
This repository provides a collection of security detection rules created by FireEye to help organizations identify malicious activity involving their own red team tools, which were compromised in a 2020 breach. These rules enable security teams to detect potential attacks using those tools across various security monitoring platforms. ## Key Features - **Multi-Platform Rules** — Includes detection rules for Snort, YARA, ClamAV, and HXIOC security systems. - **Production & Supplemental Rules** — Categorized into production-ready rules and supplemental rules requiring environment-specific tuning. - **Threat Hunting Support** — Supplemental rules are designed for proactive hunting workflows. - **Community Resource** — Freely provided to the security community without warranty. ## Philosophy FireEye released these countermeasures transparently to help the broader security community defend against potential misuse of their compromised tools, emphasizing shared responsibility in threat detection.
This repository provides a collection of detection rules and indicators of compromise (IoCs) for identifying malicious activities associated with the SolarWinds SunBurst supply chain attack. These rules help security teams detect backdoored SolarWinds Orion NMS activities and related vulnerabilities in their environments. ## Key Features - **Multi-language Rules** — Detection logic available in Snort, Yara, IOC, and ClamAV formats for integration with various security tools - **Production & Supplemental Rules** — Categorized rules with production-ready signatures and supplemental rules for threat hunting workflows - **Community-Driven Updates** — Regularly updated repository with the latest detection capabilities for evolving threats - **Threat-Specific Detection** — Focused rules for UNC2452/SolarWinds compromise activities while noting distinctions for COSMICGALE and SUPERNOVA threats ## Philosophy These rules are provided freely to the community to enhance collective defense against sophisticated supply chain attacks, with clear categorization to help security teams balance detection accuracy and operational efficiency.