Skip to content

lacework-dev/LW_Ghidra_Scripts_PUBLIC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 

Repository files navigation

LW_Ghidra_Scripts_PUBLIC

Ghidra scripts developed by Lacework Labs to aid in research and malware analysis.

Scripts

  • PwnKatien: A script to extract configuration information from Katien, Tsunami, and Ziggystratux IRC bots.

  • PwnRig: A script to extract configuration information from "PwnRig" Cryptocurrency miners.

  • HCRootkit_Sutersu: Extract embedded IPs from HC Rootkit samples.

  • HC_Dropper_ID: Identify embedded ELFs in coreutil dropper binaries.

About

Lacework Labs scripts for Malware analysis &Research

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages