VT Livehunt Cheat Sheet
ID: 469d191e-bbb5-51c8-8d7c-4d82e5b2e486
STIX ID: report--469d191e-bbb5-51c8-8d7c-4d82e5b2e486
Feed Name: VirusTotal Blog
This post introduces VirusTotal’s Livehunt Cheat Sheet and demonstrates how to build effective YARA rules with the vt module by leveraging metadata and sandbox behavior, including examples for detecting malicious DOCX macros, PowerShell execution via .lnk EXIF fields, VBScript persistence through RunOnce, and shell scripts dropped or written into /etc/profile.d/ on Linux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
