mirror of
https://github.com/FourCoreLabs/EDRHunt
synced 2026-08-09 12:06:42 +00:00
Compare commits
11
Commits
new-edrs
...
ESET-Patch
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bb05888795 | ||
|
|
22ec3374e4 | ||
|
|
65507a7f6a | ||
|
|
8ef2a72985 | ||
|
|
e36956da3b | ||
|
|
c0600ae392 | ||
|
|
66c637aabe | ||
|
|
e06624ee87 | ||
|
|
9671cb0aec | ||
|
|
5004988fbb | ||
|
|
763a84e1ef |
@@ -21,7 +21,7 @@ jobs:
|
||||
name: Set up Go
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
go-version: 1.18
|
||||
go-version: 1.19
|
||||
-
|
||||
name: Install garble
|
||||
run: |
|
||||
|
||||
@@ -163,6 +163,7 @@ EDR Detections Currently Available
|
||||
- Sophos EDR
|
||||
- Fortinet EDR
|
||||
- MalwareBytes EDR
|
||||
- LimaCharlie Agent
|
||||
|
||||
More to be added soon.
|
||||
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@ var (
|
||||
registry bool
|
||||
avwmi bool
|
||||
all bool
|
||||
versionStr string = "1.4.0"
|
||||
versionStr string = "1.4.2"
|
||||
versionCheck bool
|
||||
)
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
module github.com/FourCoreLabs/EDRHunt
|
||||
|
||||
go 1.17
|
||||
go 1.19
|
||||
|
||||
require (
|
||||
github.com/bi-zone/go-fileversion v1.0.0
|
||||
|
||||
@@ -869,6 +869,10 @@ var EdrList = []string{
|
||||
"Notifier.exe",
|
||||
"qualys",
|
||||
"qualysagent.exe",
|
||||
"rphcp.exe",
|
||||
"lc_sensor.exe",
|
||||
"refractionPOINT HCP",
|
||||
"LimaCharlie",
|
||||
}
|
||||
|
||||
var ReconList = []string{
|
||||
|
||||
@@ -30,4 +30,5 @@ var (
|
||||
SophosEDR EDRType = "sophos"
|
||||
FortinetEDR EDRType = "fortinet"
|
||||
MalwareBytesEDR EDRType = "malwarebytes"
|
||||
LimacharlieEDR EDRType = "limacharlie"
|
||||
)
|
||||
|
||||
@@ -40,9 +40,6 @@ var BitDefenderHeuristic = []string{
|
||||
"bdnc.dll",
|
||||
"BDSubmit.dll",
|
||||
"BDSubWiz.exe",
|
||||
"ProductAgentService.exe",
|
||||
"ProductAgentUI.exe",
|
||||
"WatchDog.exe",
|
||||
"bdch.dll",
|
||||
"bdec.dll",
|
||||
"bdreinit.exe",
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *CarbonBlackDetection) Type() resources.EDRType {
|
||||
var CarbonBlackHeuristic = []string{
|
||||
"CarbonBlack\\",
|
||||
"CbDefense\\",
|
||||
"SensorVersion",
|
||||
"CarbonBlackClientSetup.exe",
|
||||
}
|
||||
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *CheckPointDetection) Type() resources.EDRType {
|
||||
var CheckPointHeuristic = []string{
|
||||
"Checkpoint",
|
||||
"tracsrvwrapper.exe",
|
||||
"C:\\Program Files\\checkpoint\\endpoint connect\\tracsrvwrapper.exe",
|
||||
"TrGUI.exe",
|
||||
"TracCAPI.exe",
|
||||
"dtplat.dll",
|
||||
@@ -32,7 +31,6 @@ var CheckPointHeuristic = []string{
|
||||
"cpmsi_tool.exe",
|
||||
"DataStruct.dll",
|
||||
"FileHash_DYN.dll",
|
||||
"trac.exe",
|
||||
"TrAPI.dll",
|
||||
"vna_coinstall.dll - vna",
|
||||
"vna_install64.exe",
|
||||
@@ -40,8 +38,6 @@ var CheckPointHeuristic = []string{
|
||||
"TracSrvWrapper.exe",
|
||||
"TrGUI.exe",
|
||||
"TracSrvWrapper.exe",
|
||||
"vsmon.exe",
|
||||
"C:\\Program Files\\CheckPoint\\ZoneAlarm\\vsmon.exe",
|
||||
"TrueVector",
|
||||
"p95tray.exe",
|
||||
}
|
||||
|
||||
@@ -22,7 +22,6 @@ var CrowdstrikeHeuristic = []string{
|
||||
"csim.sys",
|
||||
"csimn.sys",
|
||||
"csimu.sys",
|
||||
"imbs.sys",
|
||||
}
|
||||
|
||||
func (w *CrowdstrikeDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
|
||||
@@ -19,7 +19,6 @@ var CybereasonHeuristic = []string{
|
||||
"CrAmTray.exe",
|
||||
"Cybereason",
|
||||
"crsdll.dll",
|
||||
"ap.dll",
|
||||
"CoreMinion.dll",
|
||||
"CoreMinion",
|
||||
"minionhost.exe",
|
||||
|
||||
@@ -13,10 +13,7 @@ func (w *CylanceDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var CylanceHeuristic = []string{
|
||||
"Cylance\\",
|
||||
"Cylance0",
|
||||
"Cylance1",
|
||||
"Cylance2",
|
||||
"Cylance",
|
||||
"CylanceProtectSetup.exe",
|
||||
"cylancesvc.exe",
|
||||
"CylanceUI.exe",
|
||||
|
||||
@@ -13,7 +13,6 @@ func (w *ElasticAgentDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var ElasticAgentHeuristic = []string{
|
||||
"Elastic",
|
||||
"elastic-agent.exe",
|
||||
"elastic-endpoint.exe",
|
||||
"elastic-endpoint-driver",
|
||||
|
||||
@@ -13,10 +13,8 @@ func (w *ESETEDRDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var ESETHeuristic = []string{
|
||||
"ESET",
|
||||
"ecmd",
|
||||
"egui.exe",
|
||||
"ekrn",
|
||||
"ekrn.exe",
|
||||
"minodlogin.exe",
|
||||
"minodlogin",
|
||||
"emu-rep.exe",
|
||||
@@ -24,15 +22,9 @@ var ESETHeuristic = []string{
|
||||
"emu-cci.exe",
|
||||
"emu-gui.exe",
|
||||
"emu-uninstall.exe",
|
||||
"ndep.exe",
|
||||
"emu-gui.exe",
|
||||
"spike.exe",
|
||||
"ESET MSP Utilities",
|
||||
"ecls.exe",
|
||||
"ecmd.exe",
|
||||
"ecomserver.exe",
|
||||
"eeclnt.exe",
|
||||
"egui.exe",
|
||||
"C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\ecmd.exe",
|
||||
"eguiAmon.dll",
|
||||
"eguiDevmon.dll",
|
||||
"eguiDmon.dll",
|
||||
@@ -46,11 +38,9 @@ var ESETHeuristic = []string{
|
||||
"eguiScan.dll",
|
||||
"eguiSmon.dll",
|
||||
"eguiUpdate.dll",
|
||||
"eh64.exe",
|
||||
"EHttpSrv.exe",
|
||||
"eplgHooks.dll",
|
||||
"eplgOE.dll",
|
||||
"cfgres.dll",
|
||||
"eclsLang.dll",
|
||||
"eguiAmonLang.dll",
|
||||
"eguiEpfwLang.dll",
|
||||
|
||||
@@ -14,85 +14,58 @@ func (w *FortinetDetection) Type() resources.EDRType {
|
||||
|
||||
var FortinetHeuristic = []string{
|
||||
"Fortinet",
|
||||
"collectoragent.exe",
|
||||
"dcagent.dll",
|
||||
"dcagent_amd64.dll",
|
||||
"FSAEConfig.exe",
|
||||
"uninstalldcagent.exe",
|
||||
"fortilspheuristics.dll",
|
||||
"mdare.dll",
|
||||
"fccomintdll.dll",
|
||||
"fcoeam.dll",
|
||||
"fmon.exe ",
|
||||
"fwutil.dll",
|
||||
"rmon.exe",
|
||||
"fccomint.exe",
|
||||
"fclanguageselector.exe",
|
||||
"fortifw.exe",
|
||||
"fcreg.exe",
|
||||
"fortitray.exe",
|
||||
"libcfg.dll",
|
||||
"fcappdb.exe",
|
||||
"fcoehook.dll",
|
||||
"fcwizard.exe",
|
||||
"fcp.dll",
|
||||
"fcresc.dll",
|
||||
"submitv.exe",
|
||||
"av_task.exe",
|
||||
"fortiwf.exe",
|
||||
"forticlish.dll",
|
||||
"fortiece.dll",
|
||||
"libavr.dll",
|
||||
"fortiwadbd.exe",
|
||||
"utilsdll.dll",
|
||||
"fase.dll",
|
||||
"fcauth.exe",
|
||||
"fcdblog.exe",
|
||||
"fcmgr.exe",
|
||||
"fortiwad.exe",
|
||||
"libav.dll",
|
||||
"fortiproxy.exe",
|
||||
"fortiskin.dll",
|
||||
"fortiscand.exe",
|
||||
"fortivpnst.dll",
|
||||
"fortivpnst.exe",
|
||||
"fortivpnst64.dll",
|
||||
"ipsec.exe",
|
||||
"fasle.dll",
|
||||
"fcwscd7.exe",
|
||||
"fcasc.exe",
|
||||
"fchelper.exe",
|
||||
"forticlient.exe",
|
||||
"fcwsc.exe",
|
||||
"forticlish.dll",
|
||||
"FortiClient Service Scheduler",
|
||||
"FortiClient.exe",
|
||||
"av_task.exe",
|
||||
"fortiwad.exe",
|
||||
"fortiproxy.exe",
|
||||
"fcmgr.exe",
|
||||
"FortiLSPHeuristics.dll",
|
||||
"mdare.dll",
|
||||
"npccpluginex.dll",
|
||||
"nptcplugin.dll",
|
||||
"npccplugin.dll",
|
||||
"FCCOMIntDLL.dll",
|
||||
"FCOEAM.dll",
|
||||
"fmon.exe",
|
||||
"FSSOMA.exe",
|
||||
"LaunchCacheClean.dll",
|
||||
"launchcacheclean64.dll",
|
||||
"rmon.exe",
|
||||
"FCCOMInt.exe",
|
||||
"FCVbltScan.exe",
|
||||
"sslvpnhostcheck.dll",
|
||||
"sslvpnhostcheck64.dll",
|
||||
"FortiESNAC.exe",
|
||||
"FortiTray.exe",
|
||||
"fcappdb.exe",
|
||||
"FCConfig.exe",
|
||||
"FCOEHook.dll",
|
||||
"fcp.dll",
|
||||
"FCResc.dll",
|
||||
"forticachecleaner.dll",
|
||||
"FortiCacheCleaner64.dll",
|
||||
@@ -100,30 +73,23 @@ var FortinetHeuristic = []string{
|
||||
"FortiCredentialProvider2x64.dll",
|
||||
"forticredentialprovider64.dll",
|
||||
"FortiTrayResc.dll",
|
||||
"av_task.exe",
|
||||
"FortiWF.exe",
|
||||
"EPCUserAvatar.exe",
|
||||
"FortiAvatar.exe",
|
||||
"FortiCliSh.dll",
|
||||
"FortiCliSh64.dll",
|
||||
"libavr.dll",
|
||||
"fortifws.exe",
|
||||
"FortiWadbd.exe",
|
||||
"FortiClient_Diagnostic_Tool.exe",
|
||||
"forticontrol.dll",
|
||||
"FortiSSLVPNdaemon.exe",
|
||||
"sslvpnlib.dll",
|
||||
"utilsdll.dll",
|
||||
"FCAuth.exe",
|
||||
"FortiCliSh.dll",
|
||||
"FortiCliSh64.dll",
|
||||
"npccpluginex.dll",
|
||||
"nptcplugin.dll",
|
||||
"npccplugin.dll",
|
||||
"FortiClient Service Scheduler",
|
||||
"av_task.exe",
|
||||
"FortiESNAC.exe",
|
||||
"ipsec.exe",
|
||||
"FortiWad.exe",
|
||||
"FortiProxy.exe",
|
||||
}
|
||||
|
||||
@@ -14,12 +14,9 @@ func (w *KaskperskyDetection) Type() resources.EDRType {
|
||||
|
||||
var KasperskyHeuristic = []string{
|
||||
"kaspersky",
|
||||
"avp.exe",
|
||||
"avpui.exe",
|
||||
"avpservice.dll",
|
||||
"avpui.exe",
|
||||
"avzkrnl.dll",
|
||||
"cbi.dll",
|
||||
"cf_anti_malware_facade.dll",
|
||||
"cf_facade.dll",
|
||||
"cf_mgmt_facade.dll",
|
||||
@@ -42,7 +39,6 @@ var KasperskyHeuristic = []string{
|
||||
"klnsacwsrv.exe",
|
||||
"klnagent.exe",
|
||||
"kl_platf.exe",
|
||||
"stpass.exe",
|
||||
"klnagwds.exe",
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
|
||||
|
||||
type LimacharlieDetection struct{}
|
||||
|
||||
func (w *LimacharlieDetection) Name() string {
|
||||
return "Limacharlie Agent"
|
||||
}
|
||||
|
||||
func (w *LimacharlieDetection) Type() resources.EDRType {
|
||||
return resources.LimacharlieEDR
|
||||
}
|
||||
|
||||
var LimacharlieHeuristic = []string{
|
||||
"rphcp.exe",
|
||||
"lc_sensor.exe",
|
||||
"refractionPOINT HCP",
|
||||
"LimaCharlie",
|
||||
}
|
||||
|
||||
func (w *LimacharlieDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(LimacharlieHeuristic)
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
|
||||
return resources.DeepInstinctEDR, true
|
||||
}
|
||||
@@ -15,7 +15,6 @@ func (w *MalwareBytesDetection) Type() resources.EDRType {
|
||||
var MalwareBytesHeuristic = []string{
|
||||
"MalwareBytes",
|
||||
"mbae.exe",
|
||||
"mbae.dll",
|
||||
"mbae64.dll",
|
||||
"mbae64.exe",
|
||||
"mbae-api.dll",
|
||||
@@ -41,10 +40,8 @@ var MalwareBytesHeuristic = []string{
|
||||
"C:\\Program Files\\Malwarebytes Anti-Rootkit",
|
||||
"mbar-1.08.2.1001.exe ",
|
||||
"mbeadomain.dll",
|
||||
"Coreinst.exe",
|
||||
"mbae-setup.exe",
|
||||
"MBAMHelper.exe",
|
||||
"Management Console.exe",
|
||||
}
|
||||
|
||||
func (w *MalwareBytesDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
|
||||
@@ -15,7 +15,6 @@ func (w *McafeeDetection) Type() resources.EDRType {
|
||||
var McafeeHeuristic = []string{
|
||||
"Mcafee\\",
|
||||
"mcupdate.exe",
|
||||
"ProtectedModuleHost.exe",
|
||||
"McAfeeAgent\\",
|
||||
"APPolicyName",
|
||||
"EPPolicyName",
|
||||
@@ -33,26 +32,20 @@ var McafeeHeuristic = []string{
|
||||
"mfewc.exe",
|
||||
"mfewch.exe",
|
||||
"mfewcui.exe",
|
||||
"fwinfo.exe",
|
||||
"mfecanary.exe",
|
||||
"mfefire.exe",
|
||||
"mfehidin.exe",
|
||||
"mfemms.exe",
|
||||
"mfevtps.exe",
|
||||
"mmsinfo.exe",
|
||||
"vtpinfo.exe",
|
||||
"MarSetup.exe",
|
||||
"mctray.exe",
|
||||
"masvc.exe",
|
||||
"macmnsvc.exe",
|
||||
"MfeServiceMgr.exe ",
|
||||
"McAPExe.exe",
|
||||
"McPvTray.exe",
|
||||
"mcods.exe",
|
||||
"mcuicnt.exe",
|
||||
"mcuihost.exe",
|
||||
"Mcshield.exe",
|
||||
"xtray.exe",
|
||||
"McpService.exe",
|
||||
"epefprtrainer.exe",
|
||||
"mfeffcoreservice.exe",
|
||||
|
||||
@@ -14,8 +14,6 @@ func (w *SentinelOneDetection) Type() resources.EDRType {
|
||||
|
||||
var SentinelOneHeuristic = []string{
|
||||
"SentinelOne\\",
|
||||
"CbDefense\\",
|
||||
"SensorVersion",
|
||||
"C:\\Program Files\\SentinelOne",
|
||||
"SentinelAgent",
|
||||
"SentinelMonitor",
|
||||
|
||||
@@ -14,43 +14,30 @@ func (w *SophosDetection) Type() resources.EDRType {
|
||||
|
||||
var SophosHeuristic = []string{
|
||||
"Sophos",
|
||||
"C:\\Program Files\\Sophos\\Sophos Virus Removal Tool\\",
|
||||
"SVRTgui.exe",
|
||||
"SVRTcli.exe",
|
||||
"ResEnu.dll",
|
||||
"Sophos Virus Removal Tool install.exe",
|
||||
"SVRTcli.exe",
|
||||
"SVRTgui.exe",
|
||||
"SCTCleanupService.exe",
|
||||
"SUL.dll",
|
||||
"SVRTservice.exe",
|
||||
"native.exe",
|
||||
"osdp.dll",
|
||||
"SAVI.dll",
|
||||
"veex.dll",
|
||||
"rkdisk.dll",
|
||||
"SCTBootTasks.exe",
|
||||
"ALMon.exe",
|
||||
"SAA.exe",
|
||||
"SUMService.exe",
|
||||
"SVRTservice.exe",
|
||||
"ssp.exe",
|
||||
"SCFService.exe",
|
||||
"SCFManager.exe",
|
||||
"spa.exe",
|
||||
"SpaRmsAdapter.dll",
|
||||
"cabarc.exe",
|
||||
"sargui.exe",
|
||||
"Sophos Computer Security Scan.exe",
|
||||
"sntpservice.exe",
|
||||
"C:\\Program Files\\sophos\\management communications system\\endpoint",
|
||||
"SophosLinkIconHandler32.dll",
|
||||
"McsClient.exe",
|
||||
"McsAgent.exe",
|
||||
"McsHeartbeat.exe",
|
||||
"SAVAdminService.exe",
|
||||
"conan.dll",
|
||||
"sav32cli.exe",
|
||||
"DCManagement.dll",
|
||||
"DesktopMessaging.dll",
|
||||
"DetectionFeedback.dll",
|
||||
@@ -88,16 +75,11 @@ var SophosHeuristic = []string{
|
||||
"swc_service.exe",
|
||||
"swcadapter.dll",
|
||||
"swi_callout.sys",
|
||||
"swi_di.exe",
|
||||
"swi_service.exe",
|
||||
"swc_service.exe",
|
||||
"swi_filter.exe",
|
||||
"ALUpdate.exe",
|
||||
"SophosUpdate.exe",
|
||||
"SUL.dll",
|
||||
"ALMon.exe",
|
||||
"ALMsg.dll",
|
||||
"ALsvc.exe",
|
||||
"ALUpdate.exe",
|
||||
"AUAdapter.dll",
|
||||
"ChannelUpdater.dll",
|
||||
@@ -105,7 +87,6 @@ var SophosHeuristic = []string{
|
||||
"config.dll",
|
||||
"crypto.dll",
|
||||
"EECustomActions.dll",
|
||||
"inetconn.dll",
|
||||
"InstlMgr.dll",
|
||||
"ispsheet.dll",
|
||||
"SAUConfigDLL.dll",
|
||||
|
||||
@@ -22,12 +22,9 @@ var SymantecHeuristic = []string{
|
||||
"AVSvcPlg.dll",
|
||||
"NTPAlert.dll",
|
||||
"NTPFW.dll",
|
||||
"osCheck.exe",
|
||||
"N360Downloader.exe",
|
||||
"bushell.dll",
|
||||
"InstWrap.exe",
|
||||
"symbos.exe",
|
||||
"nss.exe",
|
||||
"symcorpui.exe",
|
||||
"isPwdSvc.exe",
|
||||
"ccsvchst.exe",
|
||||
|
||||
@@ -13,15 +13,10 @@ func (w *TrendMicroDetection) Type() resources.EDRType {
|
||||
}
|
||||
|
||||
var TrendMicroHeuristic = []string{
|
||||
"Deep Security Agent\\",
|
||||
"dsa",
|
||||
"Notifier",
|
||||
"Trend Micro",
|
||||
"ntrmv.exe",
|
||||
"pccntmon.exe",
|
||||
"AosUImanager.exe",
|
||||
"NTRTScan.exe",
|
||||
"AddinSentry.exe ",
|
||||
"tmaseng.dll",
|
||||
"TMAS_OL.exe",
|
||||
"TMAS_OLA.dll",
|
||||
|
||||
@@ -25,5 +25,6 @@ var (
|
||||
&SophosDetection{},
|
||||
&FortinetDetection{},
|
||||
&MalwareBytesDetection{},
|
||||
&LimacharlieDetection{},
|
||||
}
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user