Skip to content

Instantly share code, notes, and snippets.

@albertzsigovits
Created November 3, 2022 15:40
Show Gist options
  • Save albertzsigovits/764683ccafc0c50f7229f13d638bbd94 to your computer and use it in GitHub Desktop.
Save albertzsigovits/764683ccafc0c50f7229f13d638bbd94 to your computer and use it in GitHub Desktop.
Malware report template
Recon
Delivery
Execution
Exec arguments, parameters
Command line execution
Privilege Escalation
Token impersonation
Admin escalation
Exploits
Lateral movement
Share enumeration
Encryption process
Malware configuration
Config decoding, extraction
Network activity/C2
PCAP captures
C2 traffic pattern
HTTP(S) requests, response
Exploits used and included
Persistence mechanisms
Mutex
Services
Registry
Scheduled Task
Driver
Evasion
Injections techniques
UAC bypasses
Hooking
AntiAV
AntiVM
AntiDebug
AntiSandbox
AntiAnalysis
AntiDebugging
Exfiltration steps
Cleanup
Log deletion
Deleting clues
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment