Git Product home page Git Product logo

curated-intel / ukraine-cyber-operations Goto Github PK

View Code? Open in Web Editor NEW
906.0 76.0 92.0 4.54 MB

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava Ukraini. Glory to Ukraine.

Home Page: https://www.curatedintel.org/

YARA 100.00%
ukraine osint cti threat-intelligence iocs threat-hunting yara malware

ukraine-cyber-operations's Introduction

logo

Ukraine Cyber Operations

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava Ukraini. Glory to Ukraine. (Blog | Twitter | LinkedIn)

Resources

Graphics by ETAC

timeline

cyberwar

Vendor Support

Vendor Offering URL
Dragos Access to Dragos service if from US/UK/ANZ and in need of ICS cybersecurity support twitter.com/RobertMLee
GreyNoise Any and all Ukrainian emails registered to GreyNoise have been upgraded to VIP which includes full, uncapped enterprise access to all GreyNoise products. There is a landing page for GreyNoise data at https://www.greynoise.io/viz/pulse twitter.com/Andrew___Morris
Recorded Future Providing free intelligence-driven insights, perspectives, and mitigation strategies as the situation in Ukraine evolves recordedfuture.com
Flashpoint Free Access to Flashpoint’s Latest Threat Intel on Ukraine go.flashpoint-intel.com
ThreatABLE A Ukraine tag for free threat intelligence feed that's more highly curated to cyber twitter.com/threatable
Orange IOCs related to Russia-Ukraine 2022 conflict extracted from our Datalake Threat Intelligence platform. github.com/Orange-Cyberdefense
FSecure F-Secure FREEDOME VPN is now available for free in all of Ukraine twitter.com/FSecure
Multiple vendors List of vendors offering their services to Ukraine for free, put together by @chrisculling docs.google.com/spreadsheets
Mandiant Free threat intelligence, webinar and guidance for defensive measures relevant to the situation in Ukraine. mandiant.com
Starlink Satellite internet constellation operated by SpaceX providing satellite Internet access coverage to Ukraine twitter.com/elonmusk
Romania DNSC Romania’s DNSC – in partnership with Bitdefender – will provide technical consulting, threat intelligence and, free of charge, cybersecurity technology to any business, government institution or private citizen of Ukraine for as long as it is necessary. Romania's DNSC Press Release
BitDefender Access to Bitdefender technical consulting, threat intelligence and both consumer and enterprise cybersecurity technology bitdefender.com/ukraine/
NameCheap Free anonymous hosting and domain name registration to any anti-Putin anti-regime and protest websites for anyone located within Russia and Belarus twitter.com/Namecheap
Avast Free decryptor for PartyTicket ransomware decoded.avast.io
Recorded Future Insikt Group’s list of indicators of compromise associated with threat actors and malware related to the Russian cyber actions against Ukraine recordedfuture.com
CybelAngel CybelAngel offers its services to interested NGOs active in the war at no cost, to minimize the risks of their missions being interrupted by cyber attacks. CybelAngel also offers Ukrainian companies an assessment of their digital exposure in the region at no charge. cybelangel.com
Malware Patrol Free 6 months DNS Firewall service subscription for Ukraine-based companies and goverment entities www.linkedin.com
UnderDefense UnderDefense is providing Managed Detection & Response services and incident repsonse support for Ukrainian critical infrastructure & government consulting in cybersecurity underdefense.com

Vetted OSINT Sources

Handle Affiliation
@KyivIndependent English-language journalism in Ukraine
@IAPonomarenko Defense reporter with The Kyiv Independent
@KyivPost English-language journalism in Ukraine
@Shayan86 BBC World News Disinformation journalist
@Liveuamap Live Universal Awareness Map (“Liveuamap”) independent global news and information site
@DAlperovitch The Alperovitch Institute for Cybersecurity Studies, Founder & Former CTO of CrowdStrike
@COUPSURE OSINT investigator for Centre for Information Resilience
@netblocks London-based Internet's Observatory

Miscellaneous Resources

Source URL Content
PowerOutages.com https://poweroutage.com/ua Tracking PowerOutages across Ukraine
Monash IP Observatory https://twitter.com/IP_Observatory Tracking IP address outages across Ukraine
Project Owl Discord https://discord.com/invite/projectowl Tracking foreign policy, geopolitical events, military and governments, using a Discord-based crowdsourced approach, with a current emphasis on Ukraine and Russia
russianwarchatter.info https://www.russianwarchatter.info/ Known Russian Military Radio Frequencies
UT CREEES https://liberalarts.utexas.edu Compiled resources to help understand the Russian invasion of Ukraine, with links to resources, action items, and academic sources
Telegram https://t.me/s/itarmyofukraine2022 IT ARMY of Ukraine
Telegram https://t.me/s/cert_ua Computer Emergency Response Team (CERT) of Ukraine
CERT-UA https://cert.gov.ua/articles Computer Emergency Response Team (CERT) of Ukraine
Telegram https://t.me/SBUkr Security Service of Ukraine (SBU)
Twitter https://twitter.com/dsszzi State Service of Special Communications and Information Protection of Ukraine
Telegram https://t.me/DIUkraine The Main Intelligence Directorate of Ukraine
Telegram https://t.me/UA_National_Police The National Police of Ukraine
Telegram https://t.me/spravdi Center for Strategic Communications and Information Security of Ukraine
Telegram https://t.me/verkhovnaradaukrainy Verkhovna Rada of Ukraine
Telegram https://t.me/DPSUkr State Border Guard Service of Ukraine
Telegram https://t.me/CenterCounteringDisinformation Countering Disinformation Center under the NSDC of Ukraine
Telegram https://t.me/CinCAFU Commander-in-Chief of the Armed Forces of Ukraine

Note:

Curated Intel does not support, encourage, partake, or condone hacking, attacking or targeting users of any kind. This information is clearly meant to help cybersecurity teams supporting Ukraine still doing their jobs while dealing with the Russian invasion.

ukraine-cyber-operations's People

Contributors

0xb4nd1t0 avatar bushidouk avatar crypto-cypher avatar disrel avatar fr0gger avatar jgmsoftware avatar komeara1 avatar nekosheen avatar ocbrollingpaper avatar rpigu-i avatar seizui avatar srcr avatar vladdba avatar wayward710 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

ukraine-cyber-operations's Issues

CaddyWiper YARA

Hi Team,

I did a study on Caddywiper and came up with some YARA rules focusing on the functionality of it rather than the actual hex code (which I think the current rule is). Not really sure about the noisy-ness of it, just tested it against 1k+ samples and CaddyWiper was the only one got picked up. Here's the rule:

rule caddywiper {
  meta:
  author = "Ali Mosajjal"
  email = "[email protected]"
  license = "Apache 2.0"
  description = "Caddy Wiper Stack String Detection"

  strings:
    $s1 = /F.{6}i.{6}n.{6}d.{6}F.{6}i.{6}r.{6}s.{6}t.{6}F.{6}i.{6}l.{6}e.{6}A/      // FindFirstFileA
    $s2 = /F.{6}i.{6}n.{6}d.{6}N.{6}e.{6}x.{6}t.{6}F.{6}i.{6}l.{6}e.{6}A/           // FindNextFileA
    $s3 = /C.{6}r.{6}e.{6}a.{6}t.{6}e.{6}F.{6}i.{6}l.{6}e.{6}A/                     // CreateFileA
    $s4 = /G.{6}e.{6}t.{6}F.{6}i.{6}l.{6}e.{6}S.{6}i.{6}z.{6}e/                     // GetFileSize
    $s5 = /L.{6}o.{6}c.{6}a.{6}l.{6}A.{6}l.{6}l.{6}o.{6}c/                          // LocalAlloc
    $s6 = /S.{6}e.{6}t.{6}F.{6}i.{6}l.{6}e.{6}P.{6}o.{6}i.{6}n.{6}t.{6}e.{6}r/      // SetFilePointer
    $s7 = /W.{3}r.{3}i.{3}t.{3}e.{3}F.{3}i.{3}l.{3}e/                               // WriteFile
    $s8 = /L.{6}o.{6}c.{6}a.{6}l.{6}F.{6}r.{6}e.{6}e/                               // LocalFree
    $s9 = /C.{6}l.{6}o.{6}s.{6}e.{6}H.{6}a.{6}n.{6}d.{6}l.{6}e/                     // CloseHandle
    $s10 = /F.{3}i.{3}n.{3}d.{3}C.{3}l.{3}o.{3}s.{3}e/                              // FindClose
  condition:
    all of ($s*) and filesize < 100KB
}

also the full analysis is here.

Cheers,

Please add vendor: Malware Patrol

Hello,
Would you please add our offer to the list of vendors supporting Ukraine? And, it'd be great to sort the list alphabetically. :-)

Here is our information:

Malware Patrol

Please let me know if you have any questions or need additional information.

Thank you.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.