🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sigma #rules

📦 项目名称: ghost-cring-defender-toolkit
👤 项目作者: yankywilson
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-26 04:54:34

📝 项目描述:
Defender toolkit for Ghost (Cring) ransomware, derived from binary-level reverse engineering of the AA25-050A sample. Detection rules (YARA, Sigma, KQL, SPL, EQL), STIX 2.1 IOCs, hunt queries, hardening, and IR playbooks. Documents gaps between advisory claims and observed behavior.

🔗 点击访问项目地址 GitHub - yankywilson/ghost-cring-defender-toolkit: Defender toolkit for Ghost (Cring) ransomware, derived from binary-level reverse…
 
 
Back to Top