Detecting the Pony Trojan with RegEx using CapLoader

#regex #malware #IDS #curl #malware-traffic-analysis.net

This short video demonstrates how you can search through PCAP files with regular expressions (regex) using CapLoader and how this can be leveraged in order to improve IDS signatures. Your browser does not support the video tag. The EmergingThreats snort/suricata rule mentioned in the video is SID 20[...]

Read the full writeup in the blog post Detecting the Pony Trojan with RegEx using CapLoader