Oct. 5, 2023, 6:50 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

So, this week it is my privilege to be TA-ing for Taz Wake for the beta run of his new class FOR577: Linux Incident Response and Threat Hunting. We were looking in the linux /proc filesystem and were noticing in the /proc/<pid>/net/{tcp/udp/icmp/…} that the IP addresses were listed in hex, but little-endian.


Article Link: https://isc.sans.edu/diary/rss/30284


1 post - 1 participant


Read full topic

addresses beta class filesystem hex hunting icmp incident incident response ip addresses linux privilege proc response run tcp threat threat hunting tool udp week

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, VA, Arlington (1550 Crystal Dr Suite 300) non-client

Invoice Compliance Reviewer

@ AC Disaster Consulting | Fort Myers, Florida, United States - Remote

Technical Program Manager II - Compliance

@ Microsoft | Redmond, Washington, United States

Head of U.S. Threat Intelligence / Senior Manager for Threat Intelligence

@ Moonshot | Washington, District of Columbia, United States

Customer Engineer, Security, Public Sector

@ Google | Virginia, USA; Illinois, USA