返回排行榜

aptnotes/data

APTnotes data

aptmalwareanalysis
Star 增长趋势
Star
1.8k
Forks
292
周增长
Issues
35
5001k1.5k
2016年4月2019年9月2023年2月2026年7月
README

What is it?

APTnotes is a repository of publicly-available papers and blogs (sorted by year) related to malicious campaigns/activity/software that have been associated with vendor-defined APT (Advanced Persistent Threat) groups and/or tool-sets.

Where's that data?

In the original repo, we maintained an ongoing README with links to all of the reports in some form (we tried) order. We also stored all of the reports in year named folders within the repo itself (we ran out of room).

To solve the storage problem, we have moved everything over to Box (thanks Box!). In order to maintain chronological order (and our sanity) we have migrated to CSV and JSON summary file(s).

How can I download all the reports from Box?

Use one of the scripts within this repo: https://github.com/aptnotes/tools

APTnotes.csv

APTnotes.csv This a CSV summary file used to keep track of all the data

Format

Filename Title Source Link SHA-1 Date Year
Name of the file Title of the report Vendor Box Link to the report SHA-1 of report Date of report release Year of release

APTnotes.json

APTnotes.json -- This is a converted version of the CSV format

Format

Example

[{"sha1": "3e6399a4b608bbd99dd81bd2be4cd49731362b5e", "Title": "How China Will Use Cyber Warfare", "Filename": "Fritz_HOW-CHINA-WILL-USE-CYBER-WARFARE(Oct-01-08)", "Source": "Jason Fritz", "Link": "https://app.box.com/s/696xnzy1an3jbm3b212y5n8xieirbemd", "Year": "2008", "Date": "10/1/08"},

How can I help?

There are multiple ways to get a report added:

  • Notify us via Twitter using the hash tag #aptnotes
    • Example: new report by vendor on this group - link #aptnotes
  • Reach out to us directly
  • Create a new issue on Github including the data you want added (using the default issue template)
    • We created an issue template to take the guesswork out of things
      • If the document is only available in HTML, print a "clean" version (e.g. with Print Friendly or similar) to PDF

Why do we do it?

Like almost every open-source project, this is a labor of love. There are so many reports out there, and they either get lost in the mix or taken down before you get a chance to read them. This is our effort to:

  • 1. Make sure these lovely reports get consumed
  • 2. Ensure the people of #DFIR #infosec know what's out there
  • 3. Hopefully add some context to the chaos

How is this data being utilized?

At present (that we know of...) these current projects consume this repo and make magical things happen:

Thank You

This project would not be where it is without the people that have helped along the way, thank you contributors

相关仓库
CyberMonitor/APT_CyberCriminal_Campagin_Collections

APT & CyberCriminal Campaign Collection

YARAapt
4.1k969
PatchMon/PatchMon

Linux Patch Management & Automation Platform

JavaScriptnpmGNU Affero General Public License v3.0aptapt-get
patchmon.net
3.1k159
blackorbird/APT_REPORT

Interesting APT Report Collection And Some Special IOCs

PythonPyPIaptcybersecurity
x.com/blackorbird
3.1k575
aptly-dev/aptly

aptly - Debian repository management tool

GoGo ModulesMIT Licensegodebian
aptly.info
2.9k418
north2016/T-MVP

Android AOP Architecture by Apt, AspectJ, Javassisit, based on Realm+Databinding+MVP+Retrofit+Rxjava2

JavaMavenaopaop-architecture
2.7k624
wimpysworld/deb-get

apt-get for .debs published via GitHub or direct download 📦

ShellMIT Licenseaptapt-get
1.7k171
zbrateam/Zebra

🦓 A Useful Package Manager for iOS

SwiftGNU General Public License v3.0jailbreakios
getzbra.com
1.3k203
alvin-tosh/Malware-Exhibit

🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.

AssemblyMIT Licensecryptographycybersecurity
1.2k196
S3N4T0R-0X0/APTs-Adversary-Simulation

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stagers, bootloaders, and other malicious artifacts that mirror those used in real world attacks .

C++Otheradversary-simulationadversarial-attacks
1.1k186
UCodeUStory/S-MVP

🔥🔥优化版MVP,使用注解泛型简化代码编写,使用模块化协议方便维护,APT过程使用注解解析器利用JavaPoet🌝完成重复模块的编写,利用ASpect+GradlePlugin 完成横向AOP编程+Javassist动态字节码注入+Tinker实现热修复+Retrofit实现优雅网络操作+RxJava轻松玩转数据处理

JavaMavenMIT Licensemvpjavassist
1.1k125