Compare commits

...
11 Commits
Author SHA1 Message Date
achilles4828 bb05888795 Update scan_eset.go 2023-01-22 20:58:57 +05:30
achilles4828 22ec3374e4 updated and removed generic signatures (#14) 2022-11-04 14:23:02 +05:30
Aarush Ahuja 65507a7f6a fix: update Go to 1.19 2022-10-14 21:44:34 +05:30
Aarush Ahuja 8ef2a72985 fix: update limacharlie detection to use rphcp (#12) 2022-10-14 21:41:14 +05:30
achilles4828 e36956da3b Merge pull request #11 from FourCoreLabs/feat-limacharlie
feat: add limacharlie edr scan
2022-09-22 22:31:11 +05:30
achilles4828 c0600ae392 Update README.md 2022-09-22 22:30:51 +05:30
Aarush Ahuja 66c637aabe feat: add limacharlie edr scan 2022-09-20 14:18:06 +05:30
Hardik Manocha e06624ee87 updated main 2022-08-23 01:32:42 +05:30
Hardik Manocha 9671cb0aec Updated elsastic 2022-08-23 00:09:45 +05:30
Hardik Manocha 5004988fbb updated fortinet signatures 2022-08-22 15:58:44 +05:30
achilles4828 763a84e1ef Merge pull request #10 from FourCoreLabs/new-edrs
Added new edr signatures and updated old signatures
2022-08-22 15:53:05 +05:30
24 changed files with 42 additions and 107 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ jobs:
name: Set up Go
uses: actions/setup-go@v2
with:
go-version: 1.18
go-version: 1.19
-
name: Install garble
run: |
+1
View File
@@ -163,6 +163,7 @@ EDR Detections Currently Available
- Sophos EDR
- Fortinet EDR
- MalwareBytes EDR
- LimaCharlie Agent
More to be added soon.
+1 -1
View File
@@ -18,7 +18,7 @@ var (
registry bool
avwmi bool
all bool
versionStr string = "1.4.0"
versionStr string = "1.4.2"
versionCheck bool
)
+1 -1
View File
@@ -1,6 +1,6 @@
module github.com/FourCoreLabs/EDRHunt
go 1.17
go 1.19
require (
github.com/bi-zone/go-fileversion v1.0.0
+4
View File
@@ -869,6 +869,10 @@ var EdrList = []string{
"Notifier.exe",
"qualys",
"qualysagent.exe",
"rphcp.exe",
"lc_sensor.exe",
"refractionPOINT HCP",
"LimaCharlie",
}
var ReconList = []string{
+1
View File
@@ -30,4 +30,5 @@ var (
SophosEDR EDRType = "sophos"
FortinetEDR EDRType = "fortinet"
MalwareBytesEDR EDRType = "malwarebytes"
LimacharlieEDR EDRType = "limacharlie"
)
-3
View File
@@ -40,9 +40,6 @@ var BitDefenderHeuristic = []string{
"bdnc.dll",
"BDSubmit.dll",
"BDSubWiz.exe",
"ProductAgentService.exe",
"ProductAgentUI.exe",
"WatchDog.exe",
"bdch.dll",
"bdec.dll",
"bdreinit.exe",
-1
View File
@@ -15,7 +15,6 @@ func (w *CarbonBlackDetection) Type() resources.EDRType {
var CarbonBlackHeuristic = []string{
"CarbonBlack\\",
"CbDefense\\",
"SensorVersion",
"CarbonBlackClientSetup.exe",
}
-4
View File
@@ -15,7 +15,6 @@ func (w *CheckPointDetection) Type() resources.EDRType {
var CheckPointHeuristic = []string{
"Checkpoint",
"tracsrvwrapper.exe",
"C:\\Program Files\\checkpoint\\endpoint connect\\tracsrvwrapper.exe",
"TrGUI.exe",
"TracCAPI.exe",
"dtplat.dll",
@@ -32,7 +31,6 @@ var CheckPointHeuristic = []string{
"cpmsi_tool.exe",
"DataStruct.dll",
"FileHash_DYN.dll",
"trac.exe",
"TrAPI.dll",
"vna_coinstall.dll - vna",
"vna_install64.exe",
@@ -40,8 +38,6 @@ var CheckPointHeuristic = []string{
"TracSrvWrapper.exe",
"TrGUI.exe",
"TracSrvWrapper.exe",
"vsmon.exe",
"C:\\Program Files\\CheckPoint\\ZoneAlarm\\vsmon.exe",
"TrueVector",
"p95tray.exe",
}
-1
View File
@@ -22,7 +22,6 @@ var CrowdstrikeHeuristic = []string{
"csim.sys",
"csimn.sys",
"csimu.sys",
"imbs.sys",
}
func (w *CrowdstrikeDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
-1
View File
@@ -19,7 +19,6 @@ var CybereasonHeuristic = []string{
"CrAmTray.exe",
"Cybereason",
"crsdll.dll",
"ap.dll",
"CoreMinion.dll",
"CoreMinion",
"minionhost.exe",
+1 -4
View File
@@ -13,10 +13,7 @@ func (w *CylanceDetection) Type() resources.EDRType {
}
var CylanceHeuristic = []string{
"Cylance\\",
"Cylance0",
"Cylance1",
"Cylance2",
"Cylance",
"CylanceProtectSetup.exe",
"cylancesvc.exe",
"CylanceUI.exe",
-1
View File
@@ -13,7 +13,6 @@ func (w *ElasticAgentDetection) Type() resources.EDRType {
}
var ElasticAgentHeuristic = []string{
"Elastic",
"elastic-agent.exe",
"elastic-endpoint.exe",
"elastic-endpoint-driver",
+2 -12
View File
@@ -13,10 +13,8 @@ func (w *ESETEDRDetection) Type() resources.EDRType {
}
var ESETHeuristic = []string{
"ESET",
"ecmd",
"egui.exe",
"ekrn",
"ekrn.exe",
"minodlogin.exe",
"minodlogin",
"emu-rep.exe",
@@ -24,15 +22,9 @@ var ESETHeuristic = []string{
"emu-cci.exe",
"emu-gui.exe",
"emu-uninstall.exe",
"ndep.exe",
"emu-gui.exe",
"spike.exe",
"ESET MSP Utilities",
"ecls.exe",
"ecmd.exe",
"ecomserver.exe",
"eeclnt.exe",
"egui.exe",
"C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\ecmd.exe",
"eguiAmon.dll",
"eguiDevmon.dll",
"eguiDmon.dll",
@@ -46,11 +38,9 @@ var ESETHeuristic = []string{
"eguiScan.dll",
"eguiSmon.dll",
"eguiUpdate.dll",
"eh64.exe",
"EHttpSrv.exe",
"eplgHooks.dll",
"eplgOE.dll",
"cfgres.dll",
"eclsLang.dll",
"eguiAmonLang.dll",
"eguiEpfwLang.dll",
-34
View File
@@ -14,85 +14,58 @@ func (w *FortinetDetection) Type() resources.EDRType {
var FortinetHeuristic = []string{
"Fortinet",
"collectoragent.exe",
"dcagent.dll",
"dcagent_amd64.dll",
"FSAEConfig.exe",
"uninstalldcagent.exe",
"fortilspheuristics.dll",
"mdare.dll",
"fccomintdll.dll",
"fcoeam.dll",
"fmon.exe ",
"fwutil.dll",
"rmon.exe",
"fccomint.exe",
"fclanguageselector.exe",
"fortifw.exe",
"fcreg.exe",
"fortitray.exe",
"libcfg.dll",
"fcappdb.exe",
"fcoehook.dll",
"fcwizard.exe",
"fcp.dll",
"fcresc.dll",
"submitv.exe",
"av_task.exe",
"fortiwf.exe",
"forticlish.dll",
"fortiece.dll",
"libavr.dll",
"fortiwadbd.exe",
"utilsdll.dll",
"fase.dll",
"fcauth.exe",
"fcdblog.exe",
"fcmgr.exe",
"fortiwad.exe",
"libav.dll",
"fortiproxy.exe",
"fortiskin.dll",
"fortiscand.exe",
"fortivpnst.dll",
"fortivpnst.exe",
"fortivpnst64.dll",
"ipsec.exe",
"fasle.dll",
"fcwscd7.exe",
"fcasc.exe",
"fchelper.exe",
"forticlient.exe",
"fcwsc.exe",
"forticlish.dll",
"FortiClient Service Scheduler",
"FortiClient.exe",
"av_task.exe",
"fortiwad.exe",
"fortiproxy.exe",
"fcmgr.exe",
"FortiLSPHeuristics.dll",
"mdare.dll",
"npccpluginex.dll",
"nptcplugin.dll",
"npccplugin.dll",
"FCCOMIntDLL.dll",
"FCOEAM.dll",
"fmon.exe",
"FSSOMA.exe",
"LaunchCacheClean.dll",
"launchcacheclean64.dll",
"rmon.exe",
"FCCOMInt.exe",
"FCVbltScan.exe",
"sslvpnhostcheck.dll",
"sslvpnhostcheck64.dll",
"FortiESNAC.exe",
"FortiTray.exe",
"fcappdb.exe",
"FCConfig.exe",
"FCOEHook.dll",
"fcp.dll",
"FCResc.dll",
"forticachecleaner.dll",
"FortiCacheCleaner64.dll",
@@ -100,30 +73,23 @@ var FortinetHeuristic = []string{
"FortiCredentialProvider2x64.dll",
"forticredentialprovider64.dll",
"FortiTrayResc.dll",
"av_task.exe",
"FortiWF.exe",
"EPCUserAvatar.exe",
"FortiAvatar.exe",
"FortiCliSh.dll",
"FortiCliSh64.dll",
"libavr.dll",
"fortifws.exe",
"FortiWadbd.exe",
"FortiClient_Diagnostic_Tool.exe",
"forticontrol.dll",
"FortiSSLVPNdaemon.exe",
"sslvpnlib.dll",
"utilsdll.dll",
"FCAuth.exe",
"FortiCliSh.dll",
"FortiCliSh64.dll",
"npccpluginex.dll",
"nptcplugin.dll",
"npccplugin.dll",
"FortiClient Service Scheduler",
"av_task.exe",
"FortiESNAC.exe",
"ipsec.exe",
"FortiWad.exe",
"FortiProxy.exe",
}
-4
View File
@@ -14,12 +14,9 @@ func (w *KaskperskyDetection) Type() resources.EDRType {
var KasperskyHeuristic = []string{
"kaspersky",
"avp.exe",
"avpui.exe",
"avpservice.dll",
"avpui.exe",
"avzkrnl.dll",
"cbi.dll",
"cf_anti_malware_facade.dll",
"cf_facade.dll",
"cf_mgmt_facade.dll",
@@ -42,7 +39,6 @@ var KasperskyHeuristic = []string{
"klnsacwsrv.exe",
"klnagent.exe",
"kl_platf.exe",
"stpass.exe",
"klnagwds.exe",
}
+29
View File
@@ -0,0 +1,29 @@
package scanners
import "github.com/FourCoreLabs/EDRHunt/pkg/resources"
type LimacharlieDetection struct{}
func (w *LimacharlieDetection) Name() string {
return "Limacharlie Agent"
}
func (w *LimacharlieDetection) Type() resources.EDRType {
return resources.LimacharlieEDR
}
var LimacharlieHeuristic = []string{
"rphcp.exe",
"lc_sensor.exe",
"refractionPOINT HCP",
"LimaCharlie",
}
func (w *LimacharlieDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
_, ok := data.CountMatchesAll(LimacharlieHeuristic)
if !ok {
return "", false
}
return resources.DeepInstinctEDR, true
}
-3
View File
@@ -15,7 +15,6 @@ func (w *MalwareBytesDetection) Type() resources.EDRType {
var MalwareBytesHeuristic = []string{
"MalwareBytes",
"mbae.exe",
"mbae.dll",
"mbae64.dll",
"mbae64.exe",
"mbae-api.dll",
@@ -41,10 +40,8 @@ var MalwareBytesHeuristic = []string{
"C:\\Program Files\\Malwarebytes Anti-Rootkit",
"mbar-1.08.2.1001.exe ",
"mbeadomain.dll",
"Coreinst.exe",
"mbae-setup.exe",
"MBAMHelper.exe",
"Management Console.exe",
}
func (w *MalwareBytesDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
-7
View File
@@ -15,7 +15,6 @@ func (w *McafeeDetection) Type() resources.EDRType {
var McafeeHeuristic = []string{
"Mcafee\\",
"mcupdate.exe",
"ProtectedModuleHost.exe",
"McAfeeAgent\\",
"APPolicyName",
"EPPolicyName",
@@ -33,26 +32,20 @@ var McafeeHeuristic = []string{
"mfewc.exe",
"mfewch.exe",
"mfewcui.exe",
"fwinfo.exe",
"mfecanary.exe",
"mfefire.exe",
"mfehidin.exe",
"mfemms.exe",
"mfevtps.exe",
"mmsinfo.exe",
"vtpinfo.exe",
"MarSetup.exe",
"mctray.exe",
"masvc.exe",
"macmnsvc.exe",
"MfeServiceMgr.exe ",
"McAPExe.exe",
"McPvTray.exe",
"mcods.exe",
"mcuicnt.exe",
"mcuihost.exe",
"Mcshield.exe",
"xtray.exe",
"McpService.exe",
"epefprtrainer.exe",
"mfeffcoreservice.exe",
-2
View File
@@ -14,8 +14,6 @@ func (w *SentinelOneDetection) Type() resources.EDRType {
var SentinelOneHeuristic = []string{
"SentinelOne\\",
"CbDefense\\",
"SensorVersion",
"C:\\Program Files\\SentinelOne",
"SentinelAgent",
"SentinelMonitor",
-19
View File
@@ -14,43 +14,30 @@ func (w *SophosDetection) Type() resources.EDRType {
var SophosHeuristic = []string{
"Sophos",
"C:\\Program Files\\Sophos\\Sophos Virus Removal Tool\\",
"SVRTgui.exe",
"SVRTcli.exe",
"ResEnu.dll",
"Sophos Virus Removal Tool install.exe",
"SVRTcli.exe",
"SVRTgui.exe",
"SCTCleanupService.exe",
"SUL.dll",
"SVRTservice.exe",
"native.exe",
"osdp.dll",
"SAVI.dll",
"veex.dll",
"rkdisk.dll",
"SCTBootTasks.exe",
"ALMon.exe",
"SAA.exe",
"SUMService.exe",
"SVRTservice.exe",
"ssp.exe",
"SCFService.exe",
"SCFManager.exe",
"spa.exe",
"SpaRmsAdapter.dll",
"cabarc.exe",
"sargui.exe",
"Sophos Computer Security Scan.exe",
"sntpservice.exe",
"C:\\Program Files\\sophos\\management communications system\\endpoint",
"SophosLinkIconHandler32.dll",
"McsClient.exe",
"McsAgent.exe",
"McsHeartbeat.exe",
"SAVAdminService.exe",
"conan.dll",
"sav32cli.exe",
"DCManagement.dll",
"DesktopMessaging.dll",
"DetectionFeedback.dll",
@@ -88,16 +75,11 @@ var SophosHeuristic = []string{
"swc_service.exe",
"swcadapter.dll",
"swi_callout.sys",
"swi_di.exe",
"swi_service.exe",
"swc_service.exe",
"swi_filter.exe",
"ALUpdate.exe",
"SophosUpdate.exe",
"SUL.dll",
"ALMon.exe",
"ALMsg.dll",
"ALsvc.exe",
"ALUpdate.exe",
"AUAdapter.dll",
"ChannelUpdater.dll",
@@ -105,7 +87,6 @@ var SophosHeuristic = []string{
"config.dll",
"crypto.dll",
"EECustomActions.dll",
"inetconn.dll",
"InstlMgr.dll",
"ispsheet.dll",
"SAUConfigDLL.dll",
-3
View File
@@ -22,12 +22,9 @@ var SymantecHeuristic = []string{
"AVSvcPlg.dll",
"NTPAlert.dll",
"NTPFW.dll",
"osCheck.exe",
"N360Downloader.exe",
"bushell.dll",
"InstWrap.exe",
"symbos.exe",
"nss.exe",
"symcorpui.exe",
"isPwdSvc.exe",
"ccsvchst.exe",
-5
View File
@@ -13,15 +13,10 @@ func (w *TrendMicroDetection) Type() resources.EDRType {
}
var TrendMicroHeuristic = []string{
"Deep Security Agent\\",
"dsa",
"Notifier",
"Trend Micro",
"ntrmv.exe",
"pccntmon.exe",
"AosUImanager.exe",
"NTRTScan.exe",
"AddinSentry.exe ",
"tmaseng.dll",
"TMAS_OL.exe",
"TMAS_OLA.dll",
+1
View File
@@ -25,5 +25,6 @@ var (
&SophosDetection{},
&FortinetDetection{},
&MalwareBytesDetection{},
&LimacharlieDetection{},
}
)