Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

threat actor

2024-08-20

A threat actor is an individual or group that carries out malicious activities with the intent of harming an entity’s security.

This term is used often in the context of cybersecurity.


Links to this note

  • attribution-steffens2020
  • toroiseandthemalwahare-pwc2023
  • dumpinglsasslikeits2019-reid2024
  • trackingteamtnt-fiser2021
  • VXadventure-amethystbasilisk2024
  • chaos-blacklotuslabs2022
  • borges2021
  • falseflags-kaspersky2017
  • yara as a tool for attribution
  • … hidden directory
  • activity cluster
  • attackable surface
  • attribution by language usage
  • code reuse as attribution
  • customized UPX packers
  • Diicot
  • exploits and 0-day as attribution
  • living off the land
  • malware disguising User-Agent strings
  • malware installing additional software
  • Nirsoft false positives
  • SSH key persistence
  • systemd service persistence
  • TeamTNT
  • typos in malware
  • user account persistence

Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.