Back to browse
GitHub Repository
18 starsPowerShell

Script to check if Notepad++ is backdoored by Lotus Blossom APT

by 10000000001·Feb 17, 2026·11 points·1 comment

AI Analysis

●●SolidSolve My Problem

Triage tool for a real attack, but static IoC-matching won't catch adaptive threats.

Strengths
  • Checks 12 specific attack vectors (C2 IPs, registry persistence, process names, SHA-256 hashes)
  • Read-only, exit-code-based output design fits incident response workflows
  • Sourced IoCs from Rapid7 Labs; published guidance on tool limitations
Weaknesses
  • Static signature detection alone; documented as insufficient for targeted threat actors
  • No memory analysis, behavioral detection, or EDR integration capability
Category
Target Audience

Windows system administrators, incident responders, security teams

Similar To

LOLBAS hunting scripts · Windows Defender Offline · Rapid7 InsightIDR triage playbooks

Similar Projects

SecurityMid

OO – Automated O&O Shut-Up for Windows

Wraps O&O ShutUp with auto-reapply after updates, but adds minimal value.

Ship It
mytechtoday
101mo ago