diff --git a/README.md b/README.md index 596b1bb..f6d87cd 100644 --- a/README.md +++ b/README.md @@ -144,7 +144,7 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea MalShare.com - The MalShare Project is a public malware repository that provides researchers free access to samples. + The MalShare Project is a public malware repository that provides researchers free access to samples. @@ -171,6 +171,14 @@ A certain amount of (domain- or business-specific) analysis is necessary to crea PhishTank delivers a list of suspected phishing URLs. Their data comes from human reports, but they also ingest external feeds where possible. It's a free service, but registering for an API key is sometimes necessary. + + + Ransomware Tracker + + + The Ransomware Tracker by abuse.ch tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. + + signature-base @@ -335,7 +343,7 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari Barncat - Fidelis Cybersecurity offers free access to Barncat after registration. The platform is intended to be used by CERTs, researchers, governments, ISPs and other, large organizations. The database holds various configuration settings used by attackers. + Fidelis Cybersecurity offers free access to Barncat after registration. The platform is intended to be used by CERTs, researchers, governments, ISPs and other, large organizations. The database holds various configuration settings used by attackers. @@ -483,7 +491,7 @@ Frameworks, platforms and services for collecting, analyzing, creating and shari Scumblr - Scumblr is a web application that allows performing periodic syncs of data sources (such as Github repositories and URLs) and performing analysis (such as static analysis, dynamic checks, and metadata collection) on the identified results. + Scumblr is a web application that allows performing periodic syncs of data sources (such as Github repositories and URLs) and performing analysis (such as static analysis, dynamic checks, and metadata collection) on the identified results. Scumblr helps you streamline proactive security through an intelligent automation framework to help you identify, track, and resolve security issues faster. @@ -614,7 +622,7 @@ All kinds of tools for parsing, creating and editing Threat Intelligence. Mostly CrowdFMS - CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the Private API system. + CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the Private API system. The framework automatically downloads recent samples, which triggered an alert on the users YARA notification feed. @@ -995,7 +1003,7 @@ All kinds of reading material about Threat Intelligence. Includes (scientific) r The Diamond Model of Intrusion Analysis - This paper presents the Diamond Model, a cognitive framework and analytic instrument to support and improve intrusion analysis. Supporint increased measurability, testability and repeatability + This paper presents the Diamond Model, a cognitive framework and analytic instrument to support and improve intrusion analysis. Supporint increased measurability, testability and repeatability in intrusion analysis in order to attain higher effectivity, efficiency and accuracy in defeating adversaries is one of its main contributions. @@ -1069,7 +1077,7 @@ All kinds of reading material about Threat Intelligence. Includes (scientific) r Pyramid of Pain - The Pyramid of Pain is a graphical way to express the difficulty of obtaining different levels of indicators and the amount of resources adversaries have to expend when obtained by defenders. + The Pyramid of Pain is a graphical way to express the difficulty of obtaining different levels of indicators and the amount of resources adversaries have to expend when obtained by defenders. @@ -1109,7 +1117,7 @@ All kinds of reading material about Threat Intelligence. Includes (scientific) r WOMBAT Project - The WOMBAT project aims at providing new means to understand the existing and emerging threats that are targeting the Internet economy and the net citizens. To reach this goal, the proposal includes three key workpackages: (i) real time gathering of a diverse set of security related raw data, (ii) enrichment of this input by means of various analysis techniques, and (iii) root cause identification and understanding of the phenomena under scrutiny. + The WOMBAT project aims at providing new means to understand the existing and emerging threats that are targeting the Internet economy and the net citizens. To reach this goal, the proposal includes three key workpackages: (i) real time gathering of a diverse set of security related raw data, (ii) enrichment of this input by means of various analysis techniques, and (iii) root cause identification and understanding of the phenomena under scrutiny.