APT Lazarus group - PSJoshi/Notes GitHub Wiki

Lazarus group - analysis links

PDF reports:

Analysis

Mitigation strategies

Analysis notes

Host artifacts

  • Amcache
  • Shimcache
  • SRUDB
  • Jumplist
  • userassist
  • sysmon/windows-evt logs
  • Prefetch
  • Volume shadow copy
  • registry analysis using regripper
  • Recycle bin
  • Analysis of Temporary internet files (DLL, EXE,powershell script files)- C:\Users<user name>\AppData\Local\Microsoft\Windows\Temporary Internet Files

Network artifacts

  • dns logs
  • firewall logs
  • router logs
  • UTM logs

Symantec AV log

  • anti-virus logs - C:\ProgramData\Symantec\Symantec Endpoint Protection%SEP Version%\Data\Quarantine\
  • SEP logs - C:\ProgramData\Symantec\Symantec Endpoint Protection%SEP Version%\Data\AV\Logs\

Note:

⚠️ **GitHub.com Fallback** ⚠️