Compare commits

...
13 Commits
Author SHA1 Message Date
Aarush Ahuja 4e1f5c8765 feat: add cortex xdr (#17) 2025-12-10 16:14:10 +05:30
arush15june 3402394469 fix: update goreleaser 2025-07-03 17:16:30 +05:30
arush15june 3c49cb6caa fix: remove garble from release 2025-07-03 17:09:24 +05:30
arush15june 0e2a3915d6 fix: add harfanglab in EDRList 2025-07-03 17:07:17 +05:30
johnsherchan90andAarush Ahuja e574169768 update: added harfanglab in scanner (#16)
* update: added harfanglab in scanner

* Update scan_harfanglab.go

---------

Co-authored-by: Aarush Ahuja <ahujaarush@gmail.com>
2025-05-12 19:35:38 +05:30
achilles4828 da2b0c6f61 Disabled Registry Check Functionality 2023-09-14 10:14:46 +05:30
arush15june b71a13507d fix: update package 2023-05-11 00:32:53 +05:30
arush15june d84148336f fix: update go mod 2023-05-11 00:25:16 +05:30
achilles4828 4644e4ee07 Update scan_eset.go (#15) 2023-01-24 01:13:52 +05:30
achilles4828 22ec3374e4 updated and removed generic signatures (#14) 2022-11-04 14:23:02 +05:30
Aarush Ahuja 65507a7f6a fix: update Go to 1.19 2022-10-14 21:44:34 +05:30
Aarush Ahuja 8ef2a72985 fix: update limacharlie detection to use rphcp (#12) 2022-10-14 21:41:14 +05:30
achilles4828 e36956da3b Merge pull request #11 from FourCoreLabs/feat-limacharlie
feat: add limacharlie edr scan
2022-09-22 22:31:11 +05:30
42 changed files with 173 additions and 179 deletions
+8 -8
View File
@@ -21,13 +21,13 @@ jobs:
name: Set up Go
uses: actions/setup-go@v2
with:
go-version: 1.18
-
name: Install garble
run: |
go install mvdan.cc/garble@master
sudo cp garble-literals.sh /usr/bin/garble-literals
sudo chmod +x /usr/bin/garble-literals
go-version: 1.24
# -
# name: Install garble
# run: |
# go install mvdan.cc/garble@master
# sudo cp garble-literals.sh /usr/bin/garble-literals
# sudo chmod +x /usr/bin/garble-literals
-
name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2
@@ -35,7 +35,7 @@ jobs:
# either 'goreleaser' (default) or 'goreleaser-pro'
distribution: goreleaser
version: latest
args: release --rm-dist
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Your GoReleaser Pro key, if you are using the 'goreleaser-pro' distribution
+2 -2
View File
@@ -5,8 +5,8 @@ builds:
goarch:
- amd64
ldflags:
- ""
gobinary: "garble-literals"
- "-s -w"
# gobinary: "garble-literals"
main: cmd/EDRHunt/main.go
archives:
- format: zip
+6 -6
View File
@@ -1,14 +1,14 @@
all: build
build:
go build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
go build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
garble-build:
garble -literals build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
garble -literals build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
local:
go build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
go build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
run:
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt all
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt all
drivers:
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt -d
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt -d
avwmi:
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt -w
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt -w
+3 -3
View File
@@ -1,6 +1,6 @@
# EDRHunt
[![goreleaser](https://github.com/FourCoreLabs/EDRHunt/actions/workflows/goreleaser.yml/badge.svg)](https://github.com/FourCoreLabs/EDRHunt/actions/workflows/goreleaser.yml)
[![goreleaser](https://github.com/fourcorelabs/edrhunt/actions/workflows/goreleaser.yml/badge.svg)](https://github.com/fourcorelabs/edrhunt/actions/workflows/goreleaser.yml)
EDRHunt scans Windows services, drivers, processes, registry, wmi for installed EDRs (Endpoint Detection And Response). Read more about EDRHunt [here](https://www.fourcore.vision/blogs/red-team-adventure-windows-endpoints-edr-edrhunt).
@@ -13,7 +13,7 @@ EDRHunt scans Windows services, drivers, processes, registry, wmi for installed
- Go
- Requires Go to be installed on system. Tested on Go1.17+.
- `go install github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt@master`
- `go install github.com/fourcorelabs/edrhunt/cmd/EDRHunt@master`
## Usage
@@ -163,7 +163,7 @@ EDR Detections Currently Available
- Sophos EDR
- Fortinet EDR
- MalwareBytes EDR
- LimaCharlie EDR
- LimaCharlie Agent
More to be added soon.
+5 -5
View File
@@ -5,9 +5,9 @@ import (
"fmt"
"os"
"github.com/FourCoreLabs/EDRHunt/pkg/edrRecon"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/FourCoreLabs/EDRHunt/pkg/scanners"
"github.com/fourcorelabs/edrhunt/pkg/edrRecon"
"github.com/fourcorelabs/edrhunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/scanners"
"github.com/spf13/cobra"
)
@@ -18,7 +18,7 @@ var (
registry bool
avwmi bool
all bool
versionStr string = "1.4.2"
versionStr string = "1.4.6"
versionCheck bool
)
@@ -46,7 +46,7 @@ func edrCommand(cmd *cobra.Command, args []string) {
processes = true
drivers = true
services = true
registry = true
registry = false
avwmi = true
fmt.Println("Scanning processes, services, drivers, wmi, and registry...")
}
+2 -2
View File
@@ -1,6 +1,6 @@
module github.com/FourCoreLabs/EDRHunt
module github.com/fourcorelabs/edrhunt
go 1.17
go 1.24
require (
github.com/bi-zone/go-fileversion v1.0.0
+1 -1
View File
@@ -4,7 +4,7 @@ import (
"context"
"fmt"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
)
// GetSystemData collects the parsed list of processes, services, drivers, wmi and registry keys to be used for EDR heuristics.
+1 -1
View File
@@ -8,7 +8,7 @@ import (
"unicode/utf16"
"unsafe"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
"github.com/hashicorp/go-multierror"
)
+1 -1
View File
@@ -6,7 +6,7 @@ import (
"fmt"
"testing"
"github.com/FourCoreLabs/EDRHunt/pkg/scanners"
"github.com/fourcorelabs/edrhunt/pkg/scanners"
)
func TestCheckDrivers(t *testing.T) {
+19
View File
@@ -869,6 +869,25 @@ var EdrList = []string{
"Notifier.exe",
"qualys",
"qualysagent.exe",
"rphcp.exe",
"lc_sensor.exe",
"refractionPOINT HCP",
"LimaCharlie",
"HarfangLab\\",
"C:\\Program Files\\HarfangLab",
"C:\\Program Files\\HarfangLab\\drivers",
"hurukai",
"hurukai-av-update.dll",
"hldevicecontrol.sys",
"hurukai-av",
"hurukai-ui",
"hurukai-av.exe",
"hurukai-ui.exe",
"hurukai-av.dll",
"hlelam.sys",
"hlprotect.sys",
"cyserver.exe",
"Cortex XDR",
}
var ReconList = []string{
+1 -1
View File
@@ -5,8 +5,8 @@ import (
"fmt"
"strings"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/bi-zone/go-fileversion"
"github.com/fourcorelabs/edrhunt/pkg/resources"
)
var (
+1 -1
View File
@@ -4,7 +4,7 @@ import (
"fmt"
"strings"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
"github.com/hashicorp/go-multierror"
"github.com/yusufpapurcu/wmi"
)
+19 -19
View File
@@ -2,13 +2,12 @@ package edrRecon
import (
"context"
"fmt"
"os/exec"
"strings"
"sync"
"syscall"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
)
var (
@@ -68,22 +67,23 @@ func EnumRegistry(ctx context.Context) []string {
func CheckRegistry(ctx context.Context) (resources.RegistryMetaData, error) {
var analysis resources.RegistryMetaData = resources.RegistryMetaData{ScanMatch: make([]string, 0)}
output := strings.Join(EnumRegistry(ctx), " ")
if output != "" {
processedOutput := strings.ToLower(output)
for _, match := range RegistryReconList {
if strings.Contains(
processedOutput,
strings.ToLower(match)) {
analysis.ScanMatch = append(analysis.ScanMatch, match)
}
}
}
if len(analysis.ScanMatch) == 0 {
return analysis, fmt.Errorf("nothing found in registry")
}
return analysis, nil
// output := strings.Join(EnumRegistry(ctx), " ")
// if output != "" {
// processedOutput := strings.ToLower(output)
// for _, match := range RegistryReconList {
// if strings.Contains(
// processedOutput,
// strings.ToLower(match)) {
// analysis.ScanMatch = append(analysis.ScanMatch, match)
// }
// }
// }
// if len(analysis.ScanMatch) == 0 {
// return analysis, fmt.Errorf("nothing found in registry")
// }
// return analysis, nil
}
+1 -1
View File
@@ -4,7 +4,7 @@ import (
"fmt"
"strings"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
"github.com/hashicorp/go-multierror"
"github.com/yusufpapurcu/wmi"
)
+1 -1
View File
@@ -6,7 +6,7 @@ import (
"strings"
"time"
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
"github.com/fourcorelabs/edrhunt/pkg/resources"
"github.com/hashicorp/go-multierror"
"github.com/yusufpapurcu/wmi"
)
+2
View File
@@ -31,4 +31,6 @@ var (
FortinetEDR EDRType = "fortinet"
MalwareBytesEDR EDRType = "malwarebytes"
LimacharlieEDR EDRType = "limacharlie"
HarfangLabEDR EDRType = "harfanglab"
CortexXDREDR EDRType = "cortex_xdr"
)
+1 -1
View File
@@ -1,7 +1,7 @@
package resources
import (
"github.com/FourCoreLabs/EDRHunt/pkg/util"
"github.com/fourcorelabs/edrhunt/pkg/util"
)
type SystemData struct {
+1 -4
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type BitDefenderDetection struct{}
@@ -40,9 +40,6 @@ var BitDefenderHeuristic = []string{
"bdnc.dll",
"BDSubmit.dll",
"BDSubWiz.exe",
"ProductAgentService.exe",
"ProductAgentUI.exe",
"WatchDog.exe",
"bdch.dll",
"bdec.dll",
"bdreinit.exe",
+1 -2
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CarbonBlackDetection struct{}
@@ -15,7 +15,6 @@ func (w *CarbonBlackDetection) Type() resources.EDRType {
var CarbonBlackHeuristic = []string{
"CarbonBlack\\",
"CbDefense\\",
"SensorVersion",
"CarbonBlackClientSetup.exe",
}
+1 -5
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CheckPointDetection struct{}
@@ -15,7 +15,6 @@ func (w *CheckPointDetection) Type() resources.EDRType {
var CheckPointHeuristic = []string{
"Checkpoint",
"tracsrvwrapper.exe",
"C:\\Program Files\\checkpoint\\endpoint connect\\tracsrvwrapper.exe",
"TrGUI.exe",
"TracCAPI.exe",
"dtplat.dll",
@@ -32,7 +31,6 @@ var CheckPointHeuristic = []string{
"cpmsi_tool.exe",
"DataStruct.dll",
"FileHash_DYN.dll",
"trac.exe",
"TrAPI.dll",
"vna_coinstall.dll - vna",
"vna_install64.exe",
@@ -40,8 +38,6 @@ var CheckPointHeuristic = []string{
"TracSrvWrapper.exe",
"TrGUI.exe",
"TracSrvWrapper.exe",
"vsmon.exe",
"C:\\Program Files\\CheckPoint\\ZoneAlarm\\vsmon.exe",
"TrueVector",
"p95tray.exe",
}
+27
View File
@@ -0,0 +1,27 @@
package scanners
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CortexXDRDetection struct{}
func (w *CortexXDRDetection) Name() string {
return "Cortex XDR"
}
func (w *CortexXDRDetection) Type() resources.EDRType {
return resources.CortexXDREDR
}
var CortexXDRHeuristic = []string{
"cyserver.exe",
"Cortex XDR",
}
func (w *CortexXDRDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
_, ok := data.CountMatchesAll(CortexXDRHeuristic)
if !ok {
return "", false
}
return resources.CortexXDREDR, true
}
+1 -2
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CrowdstrikeDetection struct{}
@@ -22,7 +22,6 @@ var CrowdstrikeHeuristic = []string{
"csim.sys",
"csimn.sys",
"csimu.sys",
"imbs.sys",
}
func (w *CrowdstrikeDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
+1 -2
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CybereasonDetection struct{}
@@ -19,7 +19,6 @@ var CybereasonHeuristic = []string{
"CrAmTray.exe",
"Cybereason",
"crsdll.dll",
"ap.dll",
"CoreMinion.dll",
"CoreMinion",
"minionhost.exe",
+2 -5
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CylanceDetection struct{}
@@ -13,10 +13,7 @@ func (w *CylanceDetection) Type() resources.EDRType {
}
var CylanceHeuristic = []string{
"Cylance\\",
"Cylance0",
"Cylance1",
"Cylance2",
"Cylance",
"CylanceProtectSetup.exe",
"cylancesvc.exe",
"CylanceUI.exe",
+1 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type CynetDetection struct{}
+1 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type DeepInstictDetection struct{}
+1 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type ElasticAgentDetection struct{}
+3 -13
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type ESETEDRDetection struct{}
@@ -13,10 +13,8 @@ func (w *ESETEDRDetection) Type() resources.EDRType {
}
var ESETHeuristic = []string{
"ESET",
"ecmd",
"egui.exe",
"ekrn",
"ekrn.exe",
"minodlogin.exe",
"minodlogin",
"emu-rep.exe",
@@ -24,15 +22,9 @@ var ESETHeuristic = []string{
"emu-cci.exe",
"emu-gui.exe",
"emu-uninstall.exe",
"ndep.exe",
"emu-gui.exe",
"spike.exe",
"ESET MSP Utilities",
"ecls.exe",
"ecmd.exe",
"ecomserver.exe",
"eeclnt.exe",
"egui.exe",
"C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\ecmd.exe",
"eguiAmon.dll",
"eguiDevmon.dll",
"eguiDmon.dll",
@@ -46,11 +38,9 @@ var ESETHeuristic = []string{
"eguiScan.dll",
"eguiSmon.dll",
"eguiUpdate.dll",
"eh64.exe",
"EHttpSrv.exe",
"eplgHooks.dll",
"eplgOE.dll",
"cfgres.dll",
"eclsLang.dll",
"eguiAmonLang.dll",
"eguiEpfwLang.dll",
+1 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type FireEyeDetection struct{}
+1 -30
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type FortinetDetection struct{}
@@ -14,62 +14,42 @@ func (w *FortinetDetection) Type() resources.EDRType {
var FortinetHeuristic = []string{
"Fortinet",
"dcagent.dll",
"dcagent_amd64.dll",
"FSAEConfig.exe",
"uninstalldcagent.exe",
"fortilspheuristics.dll",
"mdare.dll",
"fccomintdll.dll",
"fcoeam.dll",
"fwutil.dll",
"fccomint.exe",
"fclanguageselector.exe",
"fortifw.exe",
"fcreg.exe",
"fortitray.exe",
"libcfg.dll",
"fcappdb.exe",
"fcoehook.dll",
"fcwizard.exe",
"fcp.dll",
"fcresc.dll",
"submitv.exe",
"av_task.exe",
"fortiwf.exe",
"forticlish.dll",
"fortiece.dll",
"libavr.dll",
"fortiwadbd.exe",
"utilsdll.dll",
"fase.dll",
"fcauth.exe",
"fcdblog.exe",
"fcmgr.exe",
"fortiwad.exe",
"libav.dll",
"fortiproxy.exe",
"fortiskin.dll",
"fortiscand.exe",
"fortivpnst.dll",
"fortivpnst.exe",
"fortivpnst64.dll",
"ipsec.exe",
"fasle.dll",
"fcwscd7.exe",
"fcasc.exe",
"fchelper.exe",
"forticlient.exe",
"fcwsc.exe",
"forticlish.dll",
"FortiClient Service Scheduler",
"FortiClient.exe",
"av_task.exe",
"fortiwad.exe",
"fortiproxy.exe",
"fcmgr.exe",
"FortiLSPHeuristics.dll",
"mdare.dll",
"npccpluginex.dll",
"nptcplugin.dll",
"npccplugin.dll",
@@ -78,17 +58,14 @@ var FortinetHeuristic = []string{
"FSSOMA.exe",
"LaunchCacheClean.dll",
"launchcacheclean64.dll",
"rmon.exe",
"FCCOMInt.exe",
"FCVbltScan.exe",
"sslvpnhostcheck.dll",
"sslvpnhostcheck64.dll",
"FortiESNAC.exe",
"FortiTray.exe",
"fcappdb.exe",
"FCConfig.exe",
"FCOEHook.dll",
"fcp.dll",
"FCResc.dll",
"forticachecleaner.dll",
"FortiCacheCleaner64.dll",
@@ -96,29 +73,23 @@ var FortinetHeuristic = []string{
"FortiCredentialProvider2x64.dll",
"forticredentialprovider64.dll",
"FortiTrayResc.dll",
"av_task.exe",
"FortiWF.exe",
"EPCUserAvatar.exe",
"FortiAvatar.exe",
"FortiCliSh.dll",
"FortiCliSh64.dll",
"libavr.dll",
"fortifws.exe",
"FortiWadbd.exe",
"FortiClient_Diagnostic_Tool.exe",
"forticontrol.dll",
"FortiSSLVPNdaemon.exe",
"utilsdll.dll",
"FCAuth.exe",
"FortiCliSh.dll",
"FortiCliSh64.dll",
"npccpluginex.dll",
"nptcplugin.dll",
"npccplugin.dll",
"FortiClient Service Scheduler",
"av_task.exe",
"FortiESNAC.exe",
"ipsec.exe",
"FortiWad.exe",
"FortiProxy.exe",
}
+38
View File
@@ -0,0 +1,38 @@
package scanners
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type HarfangLabDetection struct{}
func (w *HarfangLabDetection) Name() string {
return "HarfangLab"
}
func (w *HarfangLabDetection) Type() resources.EDRType {
return resources.HarfangLabEDR
}
var HarfangLabHeuristic = []string{
"HarfangLab\\",
"C:\\Program Files\\HarfangLab",
"C:\\Program Files\\HarfangLab\\drivers",
"hurukai",
"hurukai-av-update.dll",
"hldevicecontrol.sys",
"hurukai-av",
"hurukai-ui",
"hurukai-av.exe",
"hurukai-ui.exe",
"hurukai-av.dll",
"hlelam.sys",
"hlprotect.sys",
}
func (w *HarfangLabDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
_, ok := data.CountMatchesAll(HarfangLabHeuristic)
if !ok {
return "", false
}
return resources.SentinelOneEDR, true
}
+1 -5
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type KaskperskyDetection struct{}
@@ -14,12 +14,9 @@ func (w *KaskperskyDetection) Type() resources.EDRType {
var KasperskyHeuristic = []string{
"kaspersky",
"avp.exe",
"avpui.exe",
"avpservice.dll",
"avpui.exe",
"avzkrnl.dll",
"cbi.dll",
"cf_anti_malware_facade.dll",
"cf_facade.dll",
"cf_mgmt_facade.dll",
@@ -42,7 +39,6 @@ var KasperskyHeuristic = []string{
"klnsacwsrv.exe",
"klnagent.exe",
"kl_platf.exe",
"stpass.exe",
"klnagwds.exe",
}
+3 -2
View File
@@ -1,11 +1,11 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type LimacharlieDetection struct{}
func (w *LimacharlieDetection) Name() string {
return "Limacharlie EDR"
return "Limacharlie Agent"
}
func (w *LimacharlieDetection) Type() resources.EDRType {
@@ -13,6 +13,7 @@ func (w *LimacharlieDetection) Type() resources.EDRType {
}
var LimacharlieHeuristic = []string{
"rphcp.exe",
"lc_sensor.exe",
"refractionPOINT HCP",
"LimaCharlie",
+1 -4
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type MalwareBytesDetection struct{}
@@ -15,7 +15,6 @@ func (w *MalwareBytesDetection) Type() resources.EDRType {
var MalwareBytesHeuristic = []string{
"MalwareBytes",
"mbae.exe",
"mbae.dll",
"mbae64.dll",
"mbae64.exe",
"mbae-api.dll",
@@ -41,10 +40,8 @@ var MalwareBytesHeuristic = []string{
"C:\\Program Files\\Malwarebytes Anti-Rootkit",
"mbar-1.08.2.1001.exe ",
"mbeadomain.dll",
"Coreinst.exe",
"mbae-setup.exe",
"MBAMHelper.exe",
"Management Console.exe",
}
func (w *MalwareBytesDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
+1 -8
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type McafeeDetection struct{}
@@ -15,7 +15,6 @@ func (w *McafeeDetection) Type() resources.EDRType {
var McafeeHeuristic = []string{
"Mcafee\\",
"mcupdate.exe",
"ProtectedModuleHost.exe",
"McAfeeAgent\\",
"APPolicyName",
"EPPolicyName",
@@ -33,26 +32,20 @@ var McafeeHeuristic = []string{
"mfewc.exe",
"mfewch.exe",
"mfewcui.exe",
"fwinfo.exe",
"mfecanary.exe",
"mfefire.exe",
"mfehidin.exe",
"mfemms.exe",
"mfevtps.exe",
"mmsinfo.exe",
"vtpinfo.exe",
"MarSetup.exe",
"mctray.exe",
"masvc.exe",
"macmnsvc.exe",
"MfeServiceMgr.exe ",
"McAPExe.exe",
"McPvTray.exe",
"mcods.exe",
"mcuicnt.exe",
"mcuihost.exe",
"Mcshield.exe",
"xtray.exe",
"McpService.exe",
"epefprtrainer.exe",
"mfeffcoreservice.exe",
+1 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type QualysDetection struct{}
+1 -3
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type SentinelOneDetection struct{}
@@ -14,8 +14,6 @@ func (w *SentinelOneDetection) Type() resources.EDRType {
var SentinelOneHeuristic = []string{
"SentinelOne\\",
"CbDefense\\",
"SensorVersion",
"C:\\Program Files\\SentinelOne",
"SentinelAgent",
"SentinelMonitor",
+1 -20
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type SophosDetection struct{}
@@ -14,43 +14,30 @@ func (w *SophosDetection) Type() resources.EDRType {
var SophosHeuristic = []string{
"Sophos",
"C:\\Program Files\\Sophos\\Sophos Virus Removal Tool\\",
"SVRTgui.exe",
"SVRTcli.exe",
"ResEnu.dll",
"Sophos Virus Removal Tool install.exe",
"SVRTcli.exe",
"SVRTgui.exe",
"SCTCleanupService.exe",
"SUL.dll",
"SVRTservice.exe",
"native.exe",
"osdp.dll",
"SAVI.dll",
"veex.dll",
"rkdisk.dll",
"SCTBootTasks.exe",
"ALMon.exe",
"SAA.exe",
"SUMService.exe",
"SVRTservice.exe",
"ssp.exe",
"SCFService.exe",
"SCFManager.exe",
"spa.exe",
"SpaRmsAdapter.dll",
"cabarc.exe",
"sargui.exe",
"Sophos Computer Security Scan.exe",
"sntpservice.exe",
"C:\\Program Files\\sophos\\management communications system\\endpoint",
"SophosLinkIconHandler32.dll",
"McsClient.exe",
"McsAgent.exe",
"McsHeartbeat.exe",
"SAVAdminService.exe",
"conan.dll",
"sav32cli.exe",
"DCManagement.dll",
"DesktopMessaging.dll",
"DetectionFeedback.dll",
@@ -88,16 +75,11 @@ var SophosHeuristic = []string{
"swc_service.exe",
"swcadapter.dll",
"swi_callout.sys",
"swi_di.exe",
"swi_service.exe",
"swc_service.exe",
"swi_filter.exe",
"ALUpdate.exe",
"SophosUpdate.exe",
"SUL.dll",
"ALMon.exe",
"ALMsg.dll",
"ALsvc.exe",
"ALUpdate.exe",
"AUAdapter.dll",
"ChannelUpdater.dll",
@@ -105,7 +87,6 @@ var SophosHeuristic = []string{
"config.dll",
"crypto.dll",
"EECustomActions.dll",
"inetconn.dll",
"InstlMgr.dll",
"ispsheet.dll",
"SAUConfigDLL.dll",
+1 -4
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type SymantecDetection struct{}
@@ -22,12 +22,9 @@ var SymantecHeuristic = []string{
"AVSvcPlg.dll",
"NTPAlert.dll",
"NTPFW.dll",
"osCheck.exe",
"N360Downloader.exe",
"bushell.dll",
"InstWrap.exe",
"symbos.exe",
"nss.exe",
"symcorpui.exe",
"isPwdSvc.exe",
"ccsvchst.exe",
+1 -6
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type TrendMicroDetection struct{}
@@ -13,15 +13,10 @@ func (w *TrendMicroDetection) Type() resources.EDRType {
}
var TrendMicroHeuristic = []string{
"Deep Security Agent\\",
"dsa",
"Notifier",
"Trend Micro",
"ntrmv.exe",
"pccntmon.exe",
"AosUImanager.exe",
"NTRTScan.exe",
"AddinSentry.exe ",
"tmaseng.dll",
"TMAS_OL.exe",
"TMAS_OLA.dll",
+5 -5
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
type WinDefenderDetection struct{}
@@ -32,10 +32,10 @@ var WinDefenderRegistryHeuristic = []string{
// Detect returnns EDRType `defender`
// If
// - processes list contains WinDefenderProcessHeuristic keywords
// - services list contains WinDefenderServicesHeuristic keywords
// - registry list contains WinDefenderRegistryHeuristic keywords
// - driver list contains WinDefenderDriverHeuristic keywords
// - processes list contains WinDefenderProcessHeuristic keywords
// - services list contains WinDefenderServicesHeuristic keywords
// - registry list contains WinDefenderRegistryHeuristic keywords
// - driver list contains WinDefenderDriverHeuristic keywords
func (w *WinDefenderDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
_, ok := data.CountMatchesAll(WinDefenderDriverHeuristic, WinDefenderProcessHeuristic, WinDefenderRegistryHeuristic, WinDefenderServicesHeuristic)
if !ok {
+3 -1
View File
@@ -1,6 +1,6 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
import "github.com/fourcorelabs/edrhunt/pkg/resources"
var (
Scanners = []resources.EDRDetection{
@@ -8,6 +8,7 @@ var (
&CrowdstrikeDetection{},
&CylanceDetection{},
&FireEyeDetection{},
&HarfangLabDetection{},
&KaskperskyDetection{},
&McafeeDetection{},
&SymantecDetection{},
@@ -26,5 +27,6 @@ var (
&FortinetDetection{},
&MalwareBytesDetection{},
&LimacharlieDetection{},
&CortexXDRDetection{},
}
)