A decoder for the SUNBURST DGA malware DNS traffic
Go to file
Neale Pickett 8c7b2a1234 Documentation 2023-03-23 17:47:28 -06:00
.gitignore subst reconstitution is broken 2020-12-22 17:59:54 -07:00
COPYING.md Documentation 2023-03-23 17:47:28 -06:00
Makefile subst reconstitution is broken 2020-12-22 17:59:54 -07:00
NOTES.md subst reconstitution is broken 2020-12-22 17:59:54 -07:00
README.md Documentation 2023-03-23 17:47:28 -06:00
sunburst.py Add release wording and remove redundant thing 2021-05-06 14:51:18 -06:00

README.md

This is a decoder for the SUNBURST/TEARDROP (UNC2452) Domain Generation Algorithm.

This was done pretty much at the same speed as the public decoders, but because of national security concerns associated with my job, it took me months to release it to the public.

We mainly use this for educational purposes, as a part of Cyber Fire.

This software is in the public domain.