mirror of
https://github.com/FourCoreLabs/EDRHunt
synced 2026-08-09 12:06:42 +00:00
feat: add elastic endpoint rule
This commit is contained in:
@@ -284,6 +284,11 @@ var EdrList = []string{
|
||||
"threat",
|
||||
"xagt.exe",
|
||||
"xagtnotif.exe",
|
||||
"Elastic Agent",
|
||||
"elastic-agent.exe",
|
||||
"elastic-endpoint.exe",
|
||||
"elastic-endpoint-driver",
|
||||
"ElasticEndpoint",
|
||||
}
|
||||
|
||||
var ReconList = []string{
|
||||
@@ -300,6 +305,7 @@ var ReconList = []string{
|
||||
"SystemProductName",
|
||||
"LocalAccountTokenFilterPolicy",
|
||||
"LsaCfgFlags",
|
||||
"elastic",
|
||||
}
|
||||
|
||||
var McafeeList = []string{
|
||||
|
||||
@@ -9,13 +9,14 @@ type EDRDetection interface {
|
||||
type EDRType string
|
||||
|
||||
var (
|
||||
WinDefenderEDR EDRType = "defender"
|
||||
KaskperskyEDR EDRType = "kaspersky"
|
||||
CrowdstrikeEDR EDRType = "crowdstrike"
|
||||
McafeeEDR EDRType = "mcafee"
|
||||
SymantecEDR EDRType = "symantec"
|
||||
CylanceEDR EDRType = "cylance"
|
||||
CarbonBlackEDR EDRType = "carbon_black"
|
||||
SentinelOneEDR EDRType = "sentinel_one"
|
||||
FireEyeEDR EDRType = "fireeye"
|
||||
WinDefenderEDR EDRType = "defender"
|
||||
KaskperskyEDR EDRType = "kaspersky"
|
||||
CrowdstrikeEDR EDRType = "crowdstrike"
|
||||
McafeeEDR EDRType = "mcafee"
|
||||
SymantecEDR EDRType = "symantec"
|
||||
CylanceEDR EDRType = "cylance"
|
||||
CarbonBlackEDR EDRType = "carbon_black"
|
||||
SentinelOneEDR EDRType = "sentinel_one"
|
||||
FireEyeEDR EDRType = "fireeye"
|
||||
ElasticAgentEDR EDRType = "elastic_agent"
|
||||
)
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
|
||||
type ElasticAgentDetection struct{}
|
||||
|
||||
func (w *ElasticAgentDetection) Name() string {
|
||||
return "Elastic Endpoint Security"
|
||||
}
|
||||
|
||||
func (w *ElasticAgentDetection) Type() resources.EDRType {
|
||||
return resources.ElasticAgentEDR
|
||||
}
|
||||
|
||||
var ElasticAgentHeuristic = []string{
|
||||
"Elastic Endpoint Security",
|
||||
"Elastic Agent",
|
||||
"elastic-agent.exe",
|
||||
"elastic-endpoint.exe",
|
||||
"elastic-endpoint-driver",
|
||||
"ElasticEndpoint",
|
||||
}
|
||||
|
||||
func (w *ElasticAgentDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(ElasticAgentHeuristic)
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
|
||||
return resources.ElasticAgentEDR, true
|
||||
}
|
||||
@@ -13,5 +13,6 @@ var (
|
||||
&SymantecDetection{},
|
||||
&SentinelOneDetection{},
|
||||
&WinDefenderDetection{},
|
||||
&ElasticAgentDetection{},
|
||||
}
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user