Oct. 23, 2022, 7:23 a.m. | /u/digicat

For [Blue|Purple] Teams in Cyber Defence www.reddit.com

These scripts/Yara have emerged to detect files with Canary Tokens in


Yara:

[https://gist.github.com/singe/0c334b514a9eed2792b88df1dfb766cc](https://gist.github.com/singe/0c334b514a9eed2792b88df1dfb766cc)


Python:

[https://gist.github.com/HackingLZ/0285d248f648f5dd216758c3fbf78c97](https://gist.github.com/HackingLZ/0285d248f648f5dd216758c3fbf78c97)

blueteamsec files scripts tokens

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Officer Level 1 (L1)

@ NTT DATA | Virginia, United States of America

Alternance - Analyste VOC - Cybersécurité - Île-De-France

@ Sopra Steria | Courbevoie, France

Senior Security Researcher, SIEM

@ Huntress | Remote US or Remote CAN

Cyber Security Engineer Lead

@ ASSYSTEM | Bridgwater, United Kingdom