mirror of
https://github.com/FourCoreLabs/EDRHunt
synced 2026-08-09 12:06:42 +00:00
Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bde38829cf | ||
|
|
3402394469 | ||
|
|
3c49cb6caa |
@@ -21,13 +21,13 @@ jobs:
|
||||
name: Set up Go
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
go-version: 1.19
|
||||
-
|
||||
name: Install garble
|
||||
run: |
|
||||
go install mvdan.cc/garble@master
|
||||
sudo cp garble-literals.sh /usr/bin/garble-literals
|
||||
sudo chmod +x /usr/bin/garble-literals
|
||||
go-version: 1.24
|
||||
# -
|
||||
# name: Install garble
|
||||
# run: |
|
||||
# go install mvdan.cc/garble@master
|
||||
# sudo cp garble-literals.sh /usr/bin/garble-literals
|
||||
# sudo chmod +x /usr/bin/garble-literals
|
||||
-
|
||||
name: Run GoReleaser
|
||||
uses: goreleaser/goreleaser-action@v2
|
||||
@@ -35,7 +35,7 @@ jobs:
|
||||
# either 'goreleaser' (default) or 'goreleaser-pro'
|
||||
distribution: goreleaser
|
||||
version: latest
|
||||
args: release --rm-dist
|
||||
args: release --clean
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
# Your GoReleaser Pro key, if you are using the 'goreleaser-pro' distribution
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@ builds:
|
||||
goarch:
|
||||
- amd64
|
||||
ldflags:
|
||||
- ""
|
||||
gobinary: "garble-literals"
|
||||
- "-s -w"
|
||||
# gobinary: "garble-literals"
|
||||
main: cmd/EDRHunt/main.go
|
||||
archives:
|
||||
- format: zip
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
module github.com/fourcorelabs/edrhunt
|
||||
|
||||
go 1.19
|
||||
go 1.24
|
||||
|
||||
require (
|
||||
github.com/bi-zone/go-fileversion v1.0.0
|
||||
|
||||
@@ -886,6 +886,8 @@ var EdrList = []string{
|
||||
"hurukai-av.dll",
|
||||
"hlelam.sys",
|
||||
"hlprotect.sys",
|
||||
"cyserver.exe",
|
||||
"Cortex XDR",
|
||||
}
|
||||
|
||||
var ReconList = []string{
|
||||
|
||||
@@ -32,4 +32,5 @@ var (
|
||||
MalwareBytesEDR EDRType = "malwarebytes"
|
||||
LimacharlieEDR EDRType = "limacharlie"
|
||||
HarfangLabEDR EDRType = "harfanglab"
|
||||
CortexXDREDR EDRType = "cortex_xdr"
|
||||
)
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
package scanners
|
||||
|
||||
import "github.com/fourcorelabs/edrhunt/pkg/resources"
|
||||
|
||||
type CortexXDRDetection struct{}
|
||||
|
||||
func (w *CortexXDRDetection) Name() string {
|
||||
return "Cortex XDR"
|
||||
}
|
||||
|
||||
func (w *CortexXDRDetection) Type() resources.EDRType {
|
||||
return resources.CortexXDREDR
|
||||
}
|
||||
|
||||
var CortexXDRHeuristic = []string{
|
||||
"cyserver.exe",
|
||||
"Cortex XDR",
|
||||
}
|
||||
|
||||
func (w *CortexXDRDetection) Detect(data resources.SystemData) (resources.EDRType, bool) {
|
||||
_, ok := data.CountMatchesAll(CortexXDRHeuristic)
|
||||
if !ok {
|
||||
return "", false
|
||||
}
|
||||
|
||||
return resources.CortexXDREDR, true
|
||||
}
|
||||
@@ -27,5 +27,6 @@ var (
|
||||
&FortinetDetection{},
|
||||
&MalwareBytesDetection{},
|
||||
&LimacharlieDetection{},
|
||||
&CortexXDRDetection{},
|
||||
}
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user