{"id":8184,"date":"2022-07-31T18:40:47","date_gmt":"2022-07-31T18:40:47","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=8184"},"modified":"2022-07-31T18:40:47","modified_gmt":"2022-07-31T18:40:47","slug":"week-of-data-dumps-part-5-commands","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2022\/07\/31\/week-of-data-dumps-part-5-commands\/","title":{"rendered":"Week of Data Dumps, Part 5 &#8211; commands"},"content":{"rendered":"\n<p>Writing your own sandbox has many advantages &#8211; the most important is an ability to collect data only large companies have. Analysing many samples gives us an unique insight into coding patterns and one of them is a simple laziness of coders who are often leveraging OS programs\/commands to achieve their goals. Today, with the EDR all over the place, many sandboxing services available online, and a admirable tendency of everyone to finally share this data openly it only makes sense to make my obsolete data public.<\/p>\n\n\n\n<p><a href=\"https:\/\/hexacorn.com\/d\/commands.txt\">Here&#8217;s a snapshot<\/a> of some of the malicious commands I &#8216;logged&#8217; in the past.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Writing your own sandbox has many advantages &#8211; the most important is an ability to collect data only large companies have. Analysing many samples gives us an unique insight into coding patterns and one of them is a simple laziness &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/07\/31\/week-of-data-dumps-part-5-commands\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[53,39,21],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8184"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=8184"}],"version-history":[{"count":3,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8184\/revisions"}],"predecessor-version":[{"id":8191,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8184\/revisions\/8191"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=8184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=8184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=8184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}