mirror of
https://github.com/FourCoreLabs/EDRHunt
synced 2026-08-09 12:06:42 +00:00
Compare commits
13
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4e1f5c8765 | ||
|
|
3402394469 | ||
|
|
3c49cb6caa | ||
|
|
0e2a3915d6 | ||
|
|
e574169768 | ||
|
|
da2b0c6f61 | ||
|
|
b71a13507d | ||
|
|
d84148336f | ||
|
|
4644e4ee07 | ||
|
|
22ec3374e4 | ||
|
|
65507a7f6a | ||
|
|
8ef2a72985 | ||
|
|
e36956da3b |
@@ -21,13 +21,13 @@ jobs:
|
||||
name: Set up Go
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
go-version: 1.18
|
||||
-
|
||||
name: Install garble
|
||||
run: |
|
||||
go install mvdan.cc/garble@master
|
||||
sudo cp garble-literals.sh /usr/bin/garble-literals
|
||||
sudo chmod +x /usr/bin/garble-literals
|
||||
go-version: 1.24
|
||||
# -
|
||||
# name: Install garble
|
||||
# run: |
|
||||
# go install mvdan.cc/garble@master
|
||||
# sudo cp garble-literals.sh /usr/bin/garble-literals
|
||||
# sudo chmod +x /usr/bin/garble-literals
|
||||
-
|
||||
name: Run GoReleaser
|
||||
uses: goreleaser/goreleaser-action@v2
|
||||
@@ -35,7 +35,7 @@ jobs:
|
||||
# either 'goreleaser' (default) or 'goreleaser-pro'
|
||||
distribution: goreleaser
|
||||
version: latest
|
||||
args: release --rm-dist
|
||||
args: release --clean
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
# Your GoReleaser Pro key, if you are using the 'goreleaser-pro' distribution
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@ builds:
|
||||
goarch:
|
||||
- amd64
|
||||
ldflags:
|
||||
- ""
|
||||
gobinary: "garble-literals"
|
||||
- "-s -w"
|
||||
# gobinary: "garble-literals"
|
||||
main: cmd/EDRHunt/main.go
|
||||
archives:
|
||||
- format: zip
|
||||
|
||||
@@ -1,14 +1,14 @@
|
||||
all: build
|
||||
|
||||
build:
|
||||
go build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
|
||||
go build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
|
||||
garble-build:
|
||||
garble -literals build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
|
||||
garble -literals build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
|
||||
local:
|
||||
go build -ldflags="-w -s" -o EDRHunt.exe github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt
|
||||
go build -ldflags="-w -s" -o EDRHunt.exe github.com/fourcorelabs/edrhunt/cmd/EDRHunt
|
||||
run:
|
||||
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt all
|
||||
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt all
|
||||
drivers:
|
||||
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt -d
|
||||
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt -d
|
||||
avwmi:
|
||||
go run -ldflags="-w -s" github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt -w
|
||||
go run -ldflags="-w -s" github.com/fourcorelabs/edrhunt/cmd/EDRHunt -w
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# EDRHunt
|
||||
|
||||
[](https://github.com/FourCoreLabs/EDRHunt/actions/workflows/goreleaser.yml)
|
||||
[](https://github.com/fourcorelabs/edrhunt/actions/workflows/goreleaser.yml)
|
||||
|
||||
EDRHunt scans Windows services, drivers, processes, registry, wmi for installed EDRs (Endpoint Detection And Response). Read more about EDRHunt [here](https://www.fourcore.vision/blogs/red-team-adventure-windows-endpoints-edr-edrhunt).
|
||||
|
||||
@@ -13,7 +13,7 @@ EDRHunt scans Windows services, drivers, processes, registry, wmi for installed
|
||||
|
||||
- Go
|
||||
- Requires Go to be installed on system. Tested on Go1.17+.
|
||||
- `go install github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt@master`
|
||||
- `go install github.com/fourcorelabs/edrhunt/cmd/EDRHunt@master`
|
||||
|
||||
## Usage
|
||||
|
||||
@@ -163,7 +163,7 @@ EDR Detections Currently Available
|
||||
- Sophos EDR
|
||||
- Fortinet EDR
|
||||
- MalwareBytes EDR
|
||||
- LimaCharlie EDR
|
||||
- LimaCharlie Agent
|
||||
|
||||
More to be added soon.
|
||||
|
||||
|
||||
+5
-5
@@ -5,9 +5,9 @@ import (
|
||||
"fmt"
|
||||
"os"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/edrRecon"
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/scanners"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/edrRecon"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/scanners"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
@@ -18,7 +18,7 @@ var (
|
||||
registry bool
|
||||
avwmi bool
|
||||
all bool
|
||||
versionStr string = "1.4.2"
|
||||
versionStr string = "1.4.6"
|
||||
versionCheck bool
|
||||
)
|
||||
|
||||
@@ -46,7 +46,7 @@ func edrCommand(cmd *cobra.Command, args []string) {
|
||||
processes = true
|
||||
drivers = true
|
||||
services = true
|
||||
registry = true
|
||||
registry = false
|
||||
avwmi = true
|
||||
fmt.Println("Scanning processes, services, drivers, wmi, and registry...")
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
module github.com/FourCoreLabs/EDRHunt
|
||||
module github.com/fourcorelabs/edrhunt
|
||||
|
||||
go 1.17
|
||||
go 1.24
|
||||
|
||||
require (
|
||||
github.com/bi-zone/go-fileversion v1.0.0
|
||||
|
||||
@@ -4,7 +4,7 @@ import (
|
||||
"context"
|
||||
"fmt"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
)
|
||||
|
||||
// GetSystemData collects the parsed list of processes, services, drivers, wmi and registry keys to be used for EDR heuristics.
|
||||
|
||||
@@ -8,7 +8,7 @@ import (
|
||||
"unicode/utf16"
|
||||
"unsafe"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
"github.com/hashicorp/go-multierror"
|
||||
)
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"fmt"
|
||||
"testing"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/scanners"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/scanners"
|
||||
)
|
||||
|
||||
func TestCheckDrivers(t *testing.T) {
|
||||
|
||||
@@ -869,6 +869,25 @@ var EdrList = []string{
|
||||
"Notifier.exe",
|
||||
"qualys",
|
||||
"qualysagent.exe",
|
||||
"rphcp.exe",
|
||||
"lc_sensor.exe",
|
||||
"refractionPOINT HCP",
|
||||
"LimaCharlie",
|
||||
"HarfangLab\\",
|
||||
"C:\\Program Files\\HarfangLab",
|
||||
"C:\\Program Files\\HarfangLab\\drivers",
|
||||
"hurukai",
|
||||
"hurukai-av-update.dll",
|
||||
"hldevicecontrol.sys",
|
||||
"hurukai-av",
|
||||
"hurukai-ui",
|
||||
"hurukai-av.exe",
|
||||
"hurukai-ui.exe",
|
||||
"hurukai-av.dll",
|
||||
"hlelam.sys",
|
||||
"hlprotect.sys",
|
||||
"cyserver.exe",
|
||||
"Cortex XDR",
|
||||
}
|
||||
|
||||
var ReconList = []string{
|
||||
|
||||
@@ -5,8 +5,8 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/bi-zone/go-fileversion"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
@@ -4,7 +4,7 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
"github.com/hashicorp/go-multierror"
|
||||
"github.com/yusufpapurcu/wmi"
|
||||
)
|
||||
|
||||
+19
-19
@@ -2,13 +2,12 @@ package edrRecon
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"os/exec"
|
||||
"strings"
|
||||
"sync"
|
||||
"syscall"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -68,22 +67,23 @@ func EnumRegistry(ctx context.Context) []string {
|
||||
|
||||
func CheckRegistry(ctx context.Context) (resources.RegistryMetaData, error) {
|
||||
var analysis resources.RegistryMetaData = resources.RegistryMetaData{ScanMatch: make([]string, 0)}
|
||||
|
||||
output := strings.Join(EnumRegistry(ctx), " ")
|
||||
if output != "" {
|
||||
processedOutput := strings.ToLower(output)
|
||||
for _, match := range RegistryReconList {
|
||||
if strings.Contains(
|
||||
processedOutput,
|
||||
strings.ToLower(match)) {
|
||||
analysis.ScanMatch = append(analysis.ScanMatch, match)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if len(analysis.ScanMatch) == 0 {
|
||||
return analysis, fmt.Errorf("nothing found in registry")
|
||||
}
|
||||
|
||||
return analysis, nil
|
||||
|
||||
// output := strings.Join(EnumRegistry(ctx), " ")
|
||||
// if output != "" {
|
||||
// processedOutput := strings.ToLower(output)
|
||||
// for _, match := range RegistryReconList {
|
||||
// if strings.Contains(
|
||||
// processedOutput,
|
||||
// strings.ToLower(match)) {
|
||||
// analysis.ScanMatch = append(analysis.ScanMatch, match)
|
||||
// }
|
||||
// }
|
||||
// }
|
||||
|
||||
// if len(analysis.ScanMatch) == 0 {
|
||||
// return analysis, fmt.Errorf("nothing found in registry")
|
||||
// }
|
||||
|
||||
// return analysis, nil
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
"github.com/hashicorp/go-multierror"
|
||||
"github.com/yusufpapurcu/wmi"
|
||||
)
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
"github.com/hashicorp/go-multierror"
|
||||
"github.com/yusufpapurcu/wmi"
|
||||
)
|
||||
|
||||
@@ -31,4 +31,6 @@ var (
|
||||
FortinetEDR EDRType = "fortinet"
|
||||
MalwareBytesEDR EDRType = "malwarebytes"
|
||||
LimacharlieEDR EDRType = "limacharlie"
|
||||
HarfangLabEDR EDRType = "harfanglab"
|
||||
CortexXDREDR EDRType = "cortex_xdr"
|
||||
)
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package resources
|
||||
|
||||
import (
|
||||
"github.com/FourCoreLabs/EDRHunt/pkg/util"
|
||||
"github.com/fourcorelabs/edrhunt/pkg/util"
|
||||
)
|
||||
|
||||
type SystemData struct {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type BitDefenderDetection struct{}
|
||||
|
||||
@@ -40,9 +40,6 @@ var BitDefenderHeuristic = []string{
|
||||
"bdnc.dll",
|
||||
"BDSubmit.dll",
|
||||
"BDSubWiz.exe",
|
||||
"ProductAgentService.exe",
|
||||
"ProductAgentUI.exe",
|
||||
"WatchDog.exe",
|
||||
"bdch.dll",
|
||||
"bdec.dll",
|
||||
"bdreinit.exe",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CarbonBlackDetection struct{}
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *CarbonBlackDetection) Type() resources.EDRType {
|
||||
var CarbonBlackHeuristic = []string{
|
||||
"CarbonBlack\\",
|
||||
"CbDefense\\",
|
||||
"SensorVersion",
|
||||
"CarbonBlackClientSetup.exe",
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CheckPointDetection struct{}
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *CheckPointDetection) Type() resources.EDRType {
|
||||
var CheckPointHeuristic = []string{
|
||||
"Checkpoint",
|
||||
"tracsrvwrapper.exe",
|
||||
"C:\\Program Files\\checkpoint\\endpoint connect\\tracsrvwrapper.exe",
|
||||
"TrGUI.exe",
|
||||
"TracCAPI.exe",
|
||||
"dtplat.dll",
|
||||
@@ -32,7 +31,6 @@ var CheckPointHeuristic = []string{
|
||||
"cpmsi_tool.exe",
|
||||
"DataStruct.dll",
|
||||
"FileHash_DYN.dll",
|
||||
"trac.exe",
|
||||
"TrAPI.dll",
|
||||
"vna_coinstall.dll - vna",
|
||||
"vna_install64.exe",
|
||||
@@ -40,8 +38,6 @@ var CheckPointHeuristic = []string{
|
||||
"TracSrvWrapper.exe",
|
||||
"TrGUI.exe",
|
||||
"TracSrvWrapper.exe",
|
||||
"vsmon.exe",
|
||||
"C:\\Program Files\\CheckPoint\\ZoneAlarm\\vsmon.exe",
|
||||
"TrueVector",
|
||||
"p95tray.exe",
|
||||
}
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CortexXDRDetection struct{}
|
||||
|
||||
func (w *CortexXDRDetection) Name() string {
|
||||
return "Cortex XDR"
|
||||
}
|
||||
|
||||
func (w *CortexXDRDetection) Type() resources.EDRType {
|
||||
return resources.CortexXDREDR
|
||||
}
|
||||
|
||||
var CortexXDRHeuristic = []string{
|
||||
"cyserver.exe",
|
||||
"Cortex XDR",
|
||||
}
|
||||
|
||||
func (w *CortexXDRDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(CortexXDRHeuristic)
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
|
||||
return resources.CortexXDREDR, true
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CrowdstrikeDetection struct{}
|
||||
|
||||
@@ -22,7 +22,6 @@ var CrowdstrikeHeuristic = []string{
|
||||
"csim.sys",
|
||||
"csimn.sys",
|
||||
"csimu.sys",
|
||||
"imbs.sys",
|
||||
}
|
||||
|
||||
func (w *CrowdstrikeDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CybereasonDetection struct{}
|
||||
|
||||
@@ -19,7 +19,6 @@ var CybereasonHeuristic = []string{
|
||||
"CrAmTray.exe",
|
||||
"Cybereason",
|
||||
"crsdll.dll",
|
||||
"ap.dll",
|
||||
"CoreMinion.dll",
|
||||
"CoreMinion",
|
||||
"minionhost.exe",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CylanceDetection struct{}
|
||||
|
||||
@@ -13,10 +13,7 @@ func (w *CylanceDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var CylanceHeuristic = []string{
|
||||
"Cylance\\",
|
||||
"Cylance0",
|
||||
"Cylance1",
|
||||
"Cylance2",
|
||||
"Cylance",
|
||||
"CylanceProtectSetup.exe",
|
||||
"cylancesvc.exe",
|
||||
"CylanceUI.exe",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CynetDetection struct{}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type DeepInstictDetection struct{}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type ElasticAgentDetection struct{}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type ESETEDRDetection struct{}
|
||||
|
||||
@@ -13,10 +13,8 @@ func (w *ESETEDRDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var ESETHeuristic = []string{
|
||||
"ESET",
|
||||
"ecmd",
|
||||
"egui.exe",
|
||||
"ekrn",
|
||||
"ekrn.exe",
|
||||
"minodlogin.exe",
|
||||
"minodlogin",
|
||||
"emu-rep.exe",
|
||||
@@ -24,15 +22,9 @@ var ESETHeuristic = []string{
|
||||
"emu-cci.exe",
|
||||
"emu-gui.exe",
|
||||
"emu-uninstall.exe",
|
||||
"ndep.exe",
|
||||
"emu-gui.exe",
|
||||
"spike.exe",
|
||||
"ESET MSP Utilities",
|
||||
"ecls.exe",
|
||||
"ecmd.exe",
|
||||
"ecomserver.exe",
|
||||
"eeclnt.exe",
|
||||
"egui.exe",
|
||||
"C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\ecmd.exe",
|
||||
"eguiAmon.dll",
|
||||
"eguiDevmon.dll",
|
||||
"eguiDmon.dll",
|
||||
@@ -46,11 +38,9 @@ var ESETHeuristic = []string{
|
||||
"eguiScan.dll",
|
||||
"eguiSmon.dll",
|
||||
"eguiUpdate.dll",
|
||||
"eh64.exe",
|
||||
"EHttpSrv.exe",
|
||||
"eplgHooks.dll",
|
||||
"eplgOE.dll",
|
||||
"cfgres.dll",
|
||||
"eclsLang.dll",
|
||||
"eguiAmonLang.dll",
|
||||
"eguiEpfwLang.dll",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type FireEyeDetection struct{}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type FortinetDetection struct{}
|
||||
|
||||
@@ -14,62 +14,42 @@ func (w *FortinetDetection) Type() resources.EDRType {
|
||||
|
||||
var FortinetHeuristic = []string{
|
||||
"Fortinet",
|
||||
"dcagent.dll",
|
||||
"dcagent_amd64.dll",
|
||||
"FSAEConfig.exe",
|
||||
"uninstalldcagent.exe",
|
||||
"fortilspheuristics.dll",
|
||||
"mdare.dll",
|
||||
"fccomintdll.dll",
|
||||
"fcoeam.dll",
|
||||
"fwutil.dll",
|
||||
"fccomint.exe",
|
||||
"fclanguageselector.exe",
|
||||
"fortifw.exe",
|
||||
"fcreg.exe",
|
||||
"fortitray.exe",
|
||||
"libcfg.dll",
|
||||
"fcappdb.exe",
|
||||
"fcoehook.dll",
|
||||
"fcwizard.exe",
|
||||
"fcp.dll",
|
||||
"fcresc.dll",
|
||||
"submitv.exe",
|
||||
"av_task.exe",
|
||||
"fortiwf.exe",
|
||||
"forticlish.dll",
|
||||
"fortiece.dll",
|
||||
"libavr.dll",
|
||||
"fortiwadbd.exe",
|
||||
"utilsdll.dll",
|
||||
"fase.dll",
|
||||
"fcauth.exe",
|
||||
"fcdblog.exe",
|
||||
"fcmgr.exe",
|
||||
"fortiwad.exe",
|
||||
"libav.dll",
|
||||
"fortiproxy.exe",
|
||||
"fortiskin.dll",
|
||||
"fortiscand.exe",
|
||||
"fortivpnst.dll",
|
||||
"fortivpnst.exe",
|
||||
"fortivpnst64.dll",
|
||||
"ipsec.exe",
|
||||
"fasle.dll",
|
||||
"fcwscd7.exe",
|
||||
"fcasc.exe",
|
||||
"fchelper.exe",
|
||||
"forticlient.exe",
|
||||
"fcwsc.exe",
|
||||
"forticlish.dll",
|
||||
"FortiClient Service Scheduler",
|
||||
"FortiClient.exe",
|
||||
"av_task.exe",
|
||||
"fortiwad.exe",
|
||||
"fortiproxy.exe",
|
||||
"fcmgr.exe",
|
||||
"FortiLSPHeuristics.dll",
|
||||
"mdare.dll",
|
||||
"npccpluginex.dll",
|
||||
"nptcplugin.dll",
|
||||
"npccplugin.dll",
|
||||
@@ -78,17 +58,14 @@ var FortinetHeuristic = []string{
|
||||
"FSSOMA.exe",
|
||||
"LaunchCacheClean.dll",
|
||||
"launchcacheclean64.dll",
|
||||
"rmon.exe",
|
||||
"FCCOMInt.exe",
|
||||
"FCVbltScan.exe",
|
||||
"sslvpnhostcheck.dll",
|
||||
"sslvpnhostcheck64.dll",
|
||||
"FortiESNAC.exe",
|
||||
"FortiTray.exe",
|
||||
"fcappdb.exe",
|
||||
"FCConfig.exe",
|
||||
"FCOEHook.dll",
|
||||
"fcp.dll",
|
||||
"FCResc.dll",
|
||||
"forticachecleaner.dll",
|
||||
"FortiCacheCleaner64.dll",
|
||||
@@ -96,29 +73,23 @@ var FortinetHeuristic = []string{
|
||||
"FortiCredentialProvider2x64.dll",
|
||||
"forticredentialprovider64.dll",
|
||||
"FortiTrayResc.dll",
|
||||
"av_task.exe",
|
||||
"FortiWF.exe",
|
||||
"EPCUserAvatar.exe",
|
||||
"FortiAvatar.exe",
|
||||
"FortiCliSh.dll",
|
||||
"FortiCliSh64.dll",
|
||||
"libavr.dll",
|
||||
"fortifws.exe",
|
||||
"FortiWadbd.exe",
|
||||
"FortiClient_Diagnostic_Tool.exe",
|
||||
"forticontrol.dll",
|
||||
"FortiSSLVPNdaemon.exe",
|
||||
"utilsdll.dll",
|
||||
"FCAuth.exe",
|
||||
"FortiCliSh.dll",
|
||||
"FortiCliSh64.dll",
|
||||
"npccpluginex.dll",
|
||||
"nptcplugin.dll",
|
||||
"npccplugin.dll",
|
||||
"FortiClient Service Scheduler",
|
||||
"av_task.exe",
|
||||
"FortiESNAC.exe",
|
||||
"ipsec.exe",
|
||||
"FortiWad.exe",
|
||||
"FortiProxy.exe",
|
||||
}
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type HarfangLabDetection struct{}
|
||||
|
||||
func (w *HarfangLabDetection) Name() string {
|
||||
return "HarfangLab"
|
||||
}
|
||||
|
||||
func (w *HarfangLabDetection) Type() resources.EDRType {
|
||||
return resources.HarfangLabEDR
|
||||
}
|
||||
|
||||
var HarfangLabHeuristic = []string{
|
||||
"HarfangLab\\",
|
||||
"C:\\Program Files\\HarfangLab",
|
||||
"C:\\Program Files\\HarfangLab\\drivers",
|
||||
"hurukai",
|
||||
"hurukai-av-update.dll",
|
||||
"hldevicecontrol.sys",
|
||||
"hurukai-av",
|
||||
"hurukai-ui",
|
||||
"hurukai-av.exe",
|
||||
"hurukai-ui.exe",
|
||||
"hurukai-av.dll",
|
||||
"hlelam.sys",
|
||||
"hlprotect.sys",
|
||||
}
|
||||
|
||||
func (w *HarfangLabDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(HarfangLabHeuristic)
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
|
||||
return resources.SentinelOneEDR, true
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type KaskperskyDetection struct{}
|
||||
|
||||
@@ -14,12 +14,9 @@ func (w *KaskperskyDetection) Type() resources.EDRType {
|
||||
|
||||
var KasperskyHeuristic = []string{
|
||||
"kaspersky",
|
||||
"avp.exe",
|
||||
"avpui.exe",
|
||||
"avpservice.dll",
|
||||
"avpui.exe",
|
||||
"avzkrnl.dll",
|
||||
"cbi.dll",
|
||||
"cf_anti_malware_facade.dll",
|
||||
"cf_facade.dll",
|
||||
"cf_mgmt_facade.dll",
|
||||
@@ -42,7 +39,6 @@ var KasperskyHeuristic = []string{
|
||||
"klnsacwsrv.exe",
|
||||
"klnagent.exe",
|
||||
"kl_platf.exe",
|
||||
"stpass.exe",
|
||||
"klnagwds.exe",
|
||||
}
|
||||
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type LimacharlieDetection struct{}
|
||||
|
||||
func (w *LimacharlieDetection) Name() string {
|
||||
return "Limacharlie EDR"
|
||||
return "Limacharlie Agent"
|
||||
}
|
||||
|
||||
func (w *LimacharlieDetection) Type() resources.EDRType {
|
||||
@@ -13,6 +13,7 @@ func (w *LimacharlieDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var LimacharlieHeuristic = []string{
|
||||
"rphcp.exe",
|
||||
"lc_sensor.exe",
|
||||
"refractionPOINT HCP",
|
||||
"LimaCharlie",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type MalwareBytesDetection struct{}
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *MalwareBytesDetection) Type() resources.EDRType {
|
||||
var MalwareBytesHeuristic = []string{
|
||||
"MalwareBytes",
|
||||
"mbae.exe",
|
||||
"mbae.dll",
|
||||
"mbae64.dll",
|
||||
"mbae64.exe",
|
||||
"mbae-api.dll",
|
||||
@@ -41,10 +40,8 @@ var MalwareBytesHeuristic = []string{
|
||||
"C:\\Program Files\\Malwarebytes Anti-Rootkit",
|
||||
"mbar-1.08.2.1001.exe ",
|
||||
"mbeadomain.dll",
|
||||
"Coreinst.exe",
|
||||
"mbae-setup.exe",
|
||||
"MBAMHelper.exe",
|
||||
"Management Console.exe",
|
||||
}
|
||||
|
||||
func (w *MalwareBytesDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type McafeeDetection struct{}
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *McafeeDetection) Type() resources.EDRType {
|
||||
var McafeeHeuristic = []string{
|
||||
"Mcafee\\",
|
||||
"mcupdate.exe",
|
||||
"ProtectedModuleHost.exe",
|
||||
"McAfeeAgent\\",
|
||||
"APPolicyName",
|
||||
"EPPolicyName",
|
||||
@@ -33,26 +32,20 @@ var McafeeHeuristic = []string{
|
||||
"mfewc.exe",
|
||||
"mfewch.exe",
|
||||
"mfewcui.exe",
|
||||
"fwinfo.exe",
|
||||
"mfecanary.exe",
|
||||
"mfefire.exe",
|
||||
"mfehidin.exe",
|
||||
"mfemms.exe",
|
||||
"mfevtps.exe",
|
||||
"mmsinfo.exe",
|
||||
"vtpinfo.exe",
|
||||
"MarSetup.exe",
|
||||
"mctray.exe",
|
||||
"masvc.exe",
|
||||
"macmnsvc.exe",
|
||||
"MfeServiceMgr.exe ",
|
||||
"McAPExe.exe",
|
||||
"McPvTray.exe",
|
||||
"mcods.exe",
|
||||
"mcuicnt.exe",
|
||||
"mcuihost.exe",
|
||||
"Mcshield.exe",
|
||||
"xtray.exe",
|
||||
"McpService.exe",
|
||||
"epefprtrainer.exe",
|
||||
"mfeffcoreservice.exe",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type QualysDetection struct{}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type SentinelOneDetection struct{}
|
||||
|
||||
@@ -14,8 +14,6 @@ func (w *SentinelOneDetection) Type() resources.EDRType {
|
||||
|
||||
var SentinelOneHeuristic = []string{
|
||||
"SentinelOne\\",
|
||||
"CbDefense\\",
|
||||
"SensorVersion",
|
||||
"C:\\Program Files\\SentinelOne",
|
||||
"SentinelAgent",
|
||||
"SentinelMonitor",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type SophosDetection struct{}
|
||||
|
||||
@@ -14,43 +14,30 @@ func (w *SophosDetection) Type() resources.EDRType {
|
||||
|
||||
var SophosHeuristic = []string{
|
||||
"Sophos",
|
||||
"C:\\Program Files\\Sophos\\Sophos Virus Removal Tool\\",
|
||||
"SVRTgui.exe",
|
||||
"SVRTcli.exe",
|
||||
"ResEnu.dll",
|
||||
"Sophos Virus Removal Tool install.exe",
|
||||
"SVRTcli.exe",
|
||||
"SVRTgui.exe",
|
||||
"SCTCleanupService.exe",
|
||||
"SUL.dll",
|
||||
"SVRTservice.exe",
|
||||
"native.exe",
|
||||
"osdp.dll",
|
||||
"SAVI.dll",
|
||||
"veex.dll",
|
||||
"rkdisk.dll",
|
||||
"SCTBootTasks.exe",
|
||||
"ALMon.exe",
|
||||
"SAA.exe",
|
||||
"SUMService.exe",
|
||||
"SVRTservice.exe",
|
||||
"ssp.exe",
|
||||
"SCFService.exe",
|
||||
"SCFManager.exe",
|
||||
"spa.exe",
|
||||
"SpaRmsAdapter.dll",
|
||||
"cabarc.exe",
|
||||
"sargui.exe",
|
||||
"Sophos Computer Security Scan.exe",
|
||||
"sntpservice.exe",
|
||||
"C:\\Program Files\\sophos\\management communications system\\endpoint",
|
||||
"SophosLinkIconHandler32.dll",
|
||||
"McsClient.exe",
|
||||
"McsAgent.exe",
|
||||
"McsHeartbeat.exe",
|
||||
"SAVAdminService.exe",
|
||||
"conan.dll",
|
||||
"sav32cli.exe",
|
||||
"DCManagement.dll",
|
||||
"DesktopMessaging.dll",
|
||||
"DetectionFeedback.dll",
|
||||
@@ -88,16 +75,11 @@ var SophosHeuristic = []string{
|
||||
"swc_service.exe",
|
||||
"swcadapter.dll",
|
||||
"swi_callout.sys",
|
||||
"swi_di.exe",
|
||||
"swi_service.exe",
|
||||
"swc_service.exe",
|
||||
"swi_filter.exe",
|
||||
"ALUpdate.exe",
|
||||
"SophosUpdate.exe",
|
||||
"SUL.dll",
|
||||
"ALMon.exe",
|
||||
"ALMsg.dll",
|
||||
"ALsvc.exe",
|
||||
"ALUpdate.exe",
|
||||
"AUAdapter.dll",
|
||||
"ChannelUpdater.dll",
|
||||
@@ -105,7 +87,6 @@ var SophosHeuristic = []string{
|
||||
"config.dll",
|
||||
"crypto.dll",
|
||||
"EECustomActions.dll",
|
||||
"inetconn.dll",
|
||||
"InstlMgr.dll",
|
||||
"ispsheet.dll",
|
||||
"SAUConfigDLL.dll",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type SymantecDetection struct{}
|
||||
|
||||
@@ -22,12 +22,9 @@ var SymantecHeuristic = []string{
|
||||
"AVSvcPlg.dll",
|
||||
"NTPAlert.dll",
|
||||
"NTPFW.dll",
|
||||
"osCheck.exe",
|
||||
"N360Downloader.exe",
|
||||
"bushell.dll",
|
||||
"InstWrap.exe",
|
||||
"symbos.exe",
|
||||
"nss.exe",
|
||||
"symcorpui.exe",
|
||||
"isPwdSvc.exe",
|
||||
"ccsvchst.exe",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type TrendMicroDetection struct{}
|
||||
|
||||
@@ -13,15 +13,10 @@ func (w *TrendMicroDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var TrendMicroHeuristic = []string{
|
||||
"Deep Security Agent\\",
|
||||
"dsa",
|
||||
"Notifier",
|
||||
"Trend Micro",
|
||||
"ntrmv.exe",
|
||||
"pccntmon.exe",
|
||||
"AosUImanager.exe",
|
||||
"NTRTScan.exe",
|
||||
"AddinSentry.exe ",
|
||||
"tmaseng.dll",
|
||||
"TMAS_OL.exe",
|
||||
"TMAS_OLA.dll",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type WinDefenderDetection struct{}
|
||||
|
||||
@@ -32,10 +32,10 @@ var WinDefenderRegistryHeuristic = []string{
|
||||
|
||||
// Detect returnns EDRType `defender`
|
||||
// If
|
||||
// - processes list contains WinDefenderProcessHeuristic keywords
|
||||
// - services list contains WinDefenderServicesHeuristic keywords
|
||||
// - registry list contains WinDefenderRegistryHeuristic keywords
|
||||
// - driver list contains WinDefenderDriverHeuristic keywords
|
||||
// - processes list contains WinDefenderProcessHeuristic keywords
|
||||
// - services list contains WinDefenderServicesHeuristic keywords
|
||||
// - registry list contains WinDefenderRegistryHeuristic keywords
|
||||
// - driver list contains WinDefenderDriverHeuristic keywords
|
||||
func (w *WinDefenderDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(WinDefenderDriverHeuristic, WinDefenderProcessHeuristic, WinDefenderRegistryHeuristic, WinDefenderServicesHeuristic)
|
||||
if !ok {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
var (
|
||||
Scanners = []resources.EDRDetection{
|
||||
@@ -8,6 +8,7 @@ var (
|
||||
&CrowdstrikeDetection{},
|
||||
&CylanceDetection{},
|
||||
&FireEyeDetection{},
|
||||
&HarfangLabDetection{},
|
||||
&KaskperskyDetection{},
|
||||
&McafeeDetection{},
|
||||
&SymantecDetection{},
|
||||
@@ -26,5 +27,6 @@ var (
|
||||
&FortinetDetection{},
|
||||
&MalwareBytesDetection{},
|
||||
&LimacharlieDetection{},
|
||||
&CortexXDRDetection{},
|
||||
}
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user