Malware
reGeorg
S1187 · Network Devices, Windows, macOS, Linux
reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of targeted networks.
ATT&CK S1187
Malware family
▤
Techniques Used
10ATT&CK techniques this malware is documented performing. Each links to its detections - Sigma, vendor SIEM rules, and analytics - so you catch the behaviour even when the binary changes.
⚊
Live Indicators
Indicators are defanged for safe handling. Newest first.
Aliases
reGeorg
External lookups - second-class, for what we don’t hold ourselves