Groups
Groups
Sign in
Groups
Groups
OpenIOC
Conversations
About
Send feedback
Help
OpenIOC
1–30 of 32
Mark all as read
Report group
0 selected
Douglas Wilson
3/25/15
Pending Messages
Hey folks -- weird issue with google apps -- the group has several pending messages, but they won
unread,
Pending Messages
Hey folks -- weird issue with google apps -- the group has several pending messages, but they won
3/25/15
Wesley Spencer
2/23/15
Carbanak IOC Scan Failure
Hi everyone, Been spending a few days on this problem and thought this group might be able to give
unread,
Carbanak IOC Scan Failure
Hi everyone, Been spending a few days on this problem and thought this group might be able to give
2/23/15
Jim Roberts
,
Tom Ueltschi
2
9/8/14
IOC Repositories
Try this one https://www.iocbucket.com Cheers Tom @c_APT_ure Sent from a spam-bot trojan rootkit on
unread,
IOC Repositories
Try this one https://www.iocbucket.com Cheers Tom @c_APT_ure Sent from a spam-bot trojan rootkit on
9/8/14
Douglas Wilson
8/21/14
OpenIOC recent news bites
Two things popped up recently online: SANS ISC now supports OpenIOC in their RESTful API: https://isc
unread,
OpenIOC recent news bites
Two things popped up recently online: SANS ISC now supports OpenIOC in their RESTful API: https://isc
8/21/14
bluecloud
, …
Nathan McBride
3
7/2/14
Availability of open source, web based tool for editing OpenIOC indicators
We have forked this and have it available on iocbucket.com as well. On Friday, June 6, 2014 8:16:18
unread,
Availability of open source, web based tool for editing OpenIOC indicators
We have forked this and have it available on iocbucket.com as well. On Friday, June 6, 2014 8:16:18
7/2/14
Douglas Wilson
3/7/14
Update on OpenIOC and a future under FireEye
Hey folks, sorry I have been so delinquent in moderation duties. I've just added a bunch of folks
unread,
Update on OpenIOC and a future under FireEye
Hey folks, sorry I have been so delinquent in moderation duties. I've just added a bunch of folks
3/7/14
authorizedsamurai
, …
Douglas Wilson
3
3/7/14
Aumlib IOC
weird -- apparently Nate's response got caught in a spam trap. just cleaning out entries and
unread,
Aumlib IOC
weird -- apparently Nate's response got caught in a spam trap. just cleaning out entries and
3/7/14
Patrick Olsen
,
Devon Kerr (Mandiant)
5
1/15/14
Parent Processes
No problem. I was looking at building a whitelist of sorts for core windows processes. For example...
unread,
Parent Processes
No problem. I was looking at building a whitelist of sorts for core windows processes. For example...
1/15/14
Douglas Wilson
2
10/29/13
Blog Posts on OpenIOC
Hey all, These have been a little slower coming out than we had planned, but we are up to three in
unread,
Blog Posts on OpenIOC
Hey all, These have been a little slower coming out than we had planned, but we are up to three in
10/29/13
Douglas Wilson
, …
vil...@evilthings.org
3
10/4/13
OpenIOC Editor that is not the Mandiant IOC Editor for Windows
i was also part of that discussion. the team i'm in is all linux or osx which has generally
unread,
OpenIOC Editor that is not the Mandiant IOC Editor for Windows
i was also part of that discussion. the team i'm in is all linux or osx which has generally
10/4/13
HAREN BHATT
, …
Douglas Wilson
5
8/12/13
Need help on the attached code.
My apologies Doug on this request. I am at a dead end and hence though i may find a way out. Please
unread,
Need help on the attached code.
My apologies Doug on this request. I am at a dead end and hence though i may find a way out. Please
8/12/13
authorizedsamurai
8/8/13
Reveton IOC
This one's a little more timely.
unread,
Reveton IOC
This one's a little more timely.
8/8/13
authorizedsamurai
8/7/13
Magic malware IOC
Just a few months late.
unread,
Magic malware IOC
Just a few months late.
8/7/13
Douglas Wilson
2
7/25/13
Upcoming OpenIOC stuff
So, as the day gets closer -- is anyone going to BE at Black Hat? Info on Will's Arsenal
unread,
Upcoming OpenIOC stuff
So, as the day gets closer -- is anyone going to BE at Black Hat? Info on Will's Arsenal
7/25/13
authorizedsamurai
4/25/13
IOC data in splunk
Just finished this TA to get IOC data into splunk. http://splunk-base.splunk.com/apps/85151/ta-
unread,
IOC data in splunk
Just finished this TA to get IOC data into splunk. http://splunk-base.splunk.com/apps/85151/ta-
4/25/13
authorizedsamurai
3/12/13
Citadel IOC sanitized
Fixed and sanitized the links in the first section (obviously the links in the ioc file are still
unread,
Citadel IOC sanitized
Fixed and sanitized the links in the first section (obviously the links in the ioc file are still
3/12/13
Kelcey Tietjen
3/12/13
Re: [OpenIOC] Citadel IOC
You will need to change the MD5 to 91B64502A89D6C47D1ADBDE3EBBF2532 not "
unread,
Re: [OpenIOC] Citadel IOC
You will need to change the MD5 to 91B64502A89D6C47D1ADBDE3EBBF2532 not "
3/12/13
authorizedsamurai
, …
Devon Kerr
4
3/8/13
Miniduke IOC
I couldn't get the attachment to work, but I'll try again next time I have something to post.
unread,
Miniduke IOC
I couldn't get the attachment to work, but I'll try again next time I have something to post.
3/8/13
tk_lane
2/12/13
OpenIOC and Splunk API Integration
A colleague of mine created a perl script that uses the Splunk API script to search for OpenIOCs in
unread,
OpenIOC and Splunk API Integration
A colleague of mine created a perl script that uses the Splunk API script to search for OpenIOCs in
2/12/13
tk_lane
, …
Devon Kerr
3
2/6/13
Autogenerating OpenIOC
It's never a bad idea to look in process memory - ProcessItem ProcessPort RemoteIP can be
unread,
Autogenerating OpenIOC
It's never a bad idea to look in process memory - ProcessItem ProcessPort RemoteIP can be
2/6/13
jeff bryner
,
David Ross
5
10/3/12
and/or logic
Thanks! <1. if the attacker compromises your agent or is able to mimic..> True that; it's a
unread,
and/or logic
Thanks! <1. if the attacker compromises your agent or is able to mimic..> True that; it's a
10/3/12
chudel
, …
David Ross
3
10/2/12
Optimization Opportunities
This is a great thread. Validating IOCs can be rather tricky as the format is intentional very
unread,
Optimization Opportunities
This is a great thread. Validating IOCs can be rather tricky as the format is intentional very
10/2/12
Douglas Wilson
, …
Tom U. @c_APT_ure
8
8/16/12
GFIRST in Atlanta
well there's already https://www.hashdays.ch/ from decon chapter switzerland which is pretty cool
unread,
GFIRST in Atlanta
well there's already https://www.hashdays.ch/ from decon chapter switzerland which is pretty cool
8/16/12
Kyle Maxwell
, …
Douglas Wilson
3
8/15/12
CybOX
I think it's a valid point to raise. It's definitely been raised before outside of this group
unread,
CybOX
I think it's a valid point to raise. It's definitely been raised before outside of this group
8/15/12
Douglas Wilson
, …
Brad Shoop
9
7/20/12
Meetup in Vegas
Excellent. See you then! Brad On Tue, Jul 17, 2012 at 1:23 PM, Douglas Wilson <douglas.wilson@
unread,
Meetup in Vegas
Excellent. See you then! Brad On Tue, Jul 17, 2012 at 1:23 PM, Douglas Wilson <douglas.wilson@
7/20/12
Douglas Wilson
4/12/12
Upcoming Webinar on OpenIOC - April 19th 2PM EDT
Hey folks, Just a head's up that I'm going to be participating in an upcoming webinar that
unread,
Upcoming Webinar on OpenIOC - April 19th 2PM EDT
Hey folks, Just a head's up that I'm going to be participating in an upcoming webinar that
4/12/12
Douglas Wilson
3/20/12
ioc_lint.py script
Hey folks, sorry that it's been so quite over here -- the OpenIOC team has been head down on a
unread,
ioc_lint.py script
Hey folks, sorry that it's been so quite over here -- the OpenIOC team has been head down on a
3/20/12
@Digital4rensics
1/6/12
IOC Repository & Sharing
Hi everyone! I'd like to announce the creation of ioc.forensicartifacts.com. The site has now
unread,
IOC Repository & Sharing
Hi everyone! I'd like to announce the creation of ioc.forensicartifacts.com. The site has now
1/6/12
Douglas Wilson
12/15/11
M-unitions blog post on creating an IOC
For those who may be interested, Ryan Kazanciyan expands on his blog post from last week, stepping
unread,
M-unitions blog post on creating an IOC
For those who may be interested, Ryan Kazanciyan expands on his blog post from last week, stepping
12/15/11
Douglas Wilson
,
Kyle Maxwell
3
12/13/11
OpenIOC, IODEF and other piles of XML
Don't hold me to this, but currently the list I'm looking at includes: AV Oval Vulnerability
unread,
OpenIOC, IODEF and other piles of XML
Don't hold me to this, but currently the list I'm looking at includes: AV Oval Vulnerability
12/13/11