# MostShittyEDR - Malware Hash Signatures
#
# Format: one SHA256 hash per line
# Lines starting with # are comments
# Optional: hash followed by space and description
#
# Usage: edr_agent.exe --signatures signatures/malware_hashes.txt
#
# WEAKNESS: This file is plaintext — an attacker who can read it
# knows exactly which hashes to avoid. A real EDR would use
# encrypted or obfuscated signature databases.

# === Known Malware Samples ===

# Mimikatz 2.2.0 x64 (trunk, common build)
61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1 mimikatz.exe

# Mimikatz 2.2.0 x86
e930b05aba559160b2daf4b68593a559e09cf3e87e1650a2e70eb4fd0f1d3e8f mimikatz_x86.exe

# Rubeus (common build)
c1d5cf1c0a5ade52ef7633b5e7c2b949f7e3ce96146b1e43c2f91f4e8eeda39c rubeus.exe

# SharpHound / BloodHound collector
8a2b5a6c7e3f5d8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b sharphound.exe

# Cobalt Strike beacon (common staging DLL hash)
3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c beacon_x64.dll

# LaZagne (credential harvester)
a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 lazagne.exe

# ProcDump (Sysinternals - dual use)
5d41402abc4b2a76b9719d911017c592fc0d5ebe1698e4f3d4e4b6c5a3b2a1c0d procdump64.exe

# SafetyKatz (modified Mimikatz)
b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6 safetykatz.exe

# Seatbelt (GhostPack recon)
7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f seatbelt.exe

# Certify (AD CS abuse)
f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 certify.exe

# === Test Entry ===
# Use this to verify signature detection is working:
# Compile a small test binary whose SHA256 matches this hash,
# or replace this line with the hash of any test .exe

# To generate a hash for testing:
#   certutil -hashfile your_test.exe SHA256
#   or: powershell Get-FileHash your_test.exe -Algorithm SHA256
