AlienVault R&D Labs Portal. Get the latest news from our research.
Header

Red October – Indicators of Compromise and Mitigation Data

January 21st, 2013 | Posted by jaime.blasco in APT | Attacks | Exploits | Malware

Together with our partner, Kaspersky, we’re releasing a whitepaper on the “indicators of compromise” that can be useful to detect and mitigate the threats from Red October. It contains indicators to detect most of the Red October activity in your systems and networks. Inside the whitepaper you will find snort rules as well as an OpenIOC file that you can use to check your systems for activity related to this cyber espionage campaign.

Link to the whitepaper

OpenIOC file

Read more from Red October

jaime.blasco

At AlienVault Jaime manages the Lab and runs the Vulnerability Research Team. Prior to working in the AlienVault lab he founded a couple of startups (Eazel, Aitsec) working on web application security, source code analysis and incident response. His background stems from a number of years working in vulnerability management, malware analysis and security researching.

More Posts - Website

Follow Me:
TwitterLinkedIn

You can follow any responses to this entry through the RSS 2.0 Both comments and pings are currently closed.