Skip to content

Instantly share code, notes, and snippets.

View 0xThiebaut's full-sized avatar
🔍
Doing Threat Intelligence stuff 👀

Maxime Thiebaut 0xThiebaut

🔍
Doing Threat Intelligence stuff 👀
View GitHub Profile
@0xThiebaut
0xThiebaut / sodinokibi_ransomware_registry_key.yml
Last active March 29, 2021 20:18
Sodinokibi Ransomware Registry Key
title: Sodinokibi Ransomware Registry Key
id: 9fecd354-77f0-498e-a611-c963970e7bca
description: Detects the creation of Sodinokibi (aka REvil) registry keys
status: experimental
references:
- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
- https://twitter.com/malwrhunterteam/status/1372648463553462279
tags:
- attack.persistence
- attack.t1547.001