strings residing within a malware sample can be used as a method of attribution.
When developing yara rules, detections, etc. be on the lookout for unique strings, error messages, misspellings, strange grammar, and other interesting strings.
strings as attribution
0001-01-01
strings residing within a malware sample can be used as a method of attribution.
When developing yara rules, detections, etc. be on the lookout for unique strings, error messages, misspellings, strange grammar, and other interesting strings.
Linux Persistence: atd
2025-04-01 DFIR CTF linux persistence at atd
Linux Persistence: SSH
2025-03-29 DFIR CTF SSH hardening hunting persistence linux persistence hunting hardening SSH PAM