Gift giveaway for the first 20 New topics posted!

Be one of the first 20 to make a meaningful post :white_check_mark: to any of the categories here on the Sysdig Open Source Community, and I will reach out to you with your prize! :1st_place_medal:

1 prize per person.

1 Like

Hi, just registered looking forward to add sysdig in my toolbelt, workflow and more.
My threats models and threats actors that tend to target me will most likely lead to interesting dig result.
I’m currently researching a discord malwares that affected me.
discord malware/worm virus total
My old github, 0hmware (Privy) · GitHub I’m currently using this new one for Privy / Interohm projects which will be the one hosting my write ups.

1 Like

Welcome @Atmos :waving_hand: and thanks for sharing your malware analysis with us! Is your plan to use Falco to help you to detect malware? Any other plans with the other OSS here? :smiley:

2 Likes

Well I aim get more familiar with sysdig, it def has the potential to replace snoopy, proc and some audit. First and foremost i will use it for my own needs to collect data on APT / threats actors constantly targeting me. TL:DR My isp is heavily compromised it is harder to find a BRAS server not compromised. I had multiples computers compromised even brand new one getting evil maid’d ( Considering the isp layer 2 device are compromised ) Lot’s of what i was seeing on amazon was probably poisoned which even led to me ordering a computer with a small winbond surprises added on my mobo for free !. I had moonbounce , blacklotus even before they were “public”. ( it boot so much faster than it used to lol ); so yeah I need it for myself and for lot’s of my friend i am wikimos lool.
Eventually has i get more flexible with sysdig, i might consider some kind of front end projects which would mainly aim to get it ruining with other solutions but it’s too early to say such.

2 Likes

Just made a post. Thanks!

Hey Atmos,

Interesting comments here, some of which I’m trying to think how I can include in my project: GitHub - maddigsys/falco-vanguard: Falco Vanguard

I’d love your feedback on it, improvements and such.