fix(osint): improve OsintSources across all remaining chokepoint files

Applied the same methodology used for clickfix-techniques.yml to evaluate
and improve the OsintSources blocks in all five remaining chokepoint files.

renamed-rmm-tools.yml (moderate):
- Expanded URLScan filename query with support*.exe and verify*.exe pretexts
- Updated Shodan note to also cover SimpleHelp (CISA AA25-163A, June 2025)
- Replaced Censys AnyDesk cert query with SimpleHelp (AnyDesk certs were
  revoked after the Feb 2024 breach, making that query largely historical)
- Added VT Intelligence PE metadata query for renamed RMM binaries in the wild
- Added LOLRMM.io — the community catalog of RMM tool file/network indicators

remote-execution-tools.yml (significant):
- Removed port:445 country:US — returns millions of results with zero
  signal for hunting attack infrastructure; was an exposure audit query,
  not a threat hunting query
- Repositioned WinRM query with clearer notes about its scope (exposure
  audit, not attacker infra hunting)
- Added Shodan JARM fingerprint query for Cobalt Strike team servers —
  the correct approach for hunting C2 infra paired with Impacket/NetExec
- Added hunt.io for real-time C2 infrastructure mapping

ransomware-service-manipulation.yml (minor):
- Fixed ANY.RUN URL from general trends page to the actual public
  submissions feed with ransomware filter
- Added Ransomware.live for real-time ransomware group activity tracking
- VT Intelligence and GitHub queries were solid; kept as-is

web-shells.yml (minor):
- Expanded Shodan title query with FilesMan and Antak Webshell
- Expanded URLScan filename query with webshell.php and cmd.aspx
- Added Censys eval(base64_decode) query for live obfuscated PHP shells
- VT Intelligence tag:webshell query was the strongest in any file; kept

edr-bypass-techniques.yml (minor):
- Added LOLDrivers (loldrivers.io) — the canonical community catalog of
  vulnerable and malicious drivers used in BYOVD attacks; was absent
  entirely despite being the most important resource for this chokepoint
- All three existing queries were solid; kept as-is

https://claude.ai/code/session_01CeEB6yuJimygkCBi7ubSh3
This commit is contained in:
Claude
2026-03-08 15:45:59 +00:00
parent bc3962244c
commit c690e8ad0f
5 changed files with 41 additions and 22 deletions
@@ -280,6 +280,9 @@ OsintSources:
Query: '"EtwEventWrite" "0xC3" path:*.c OR path:*.asm'
URL: "https://github.com/search?q=%22EtwEventWrite%22+%220xC3%22&type=code"
Notes: "Finds ETW patching implementations targeting EtwEventWrite with a RET opcode. New variants appear regularly; use to track new ETW bypass techniques before they reach production campaigns."
- Platform: LOLDrivers
URL: "https://www.loldrivers.io"
Notes: "Community-maintained catalog of known vulnerable (BYOVD) and malicious drivers with hashes, CVE references, and detection guidance. Feed driver hashes from this list into Sysmon EID 6 detection rules and your EDR's driver blocklist. Updated regularly as new BYOVD tools emerge. Filter by 'Type: Vulnerable' for BYOVD drivers; 'Type: Malicious' for purpose-built EDR killers like EDRKillShifter. Essential complement to Microsoft's Vulnerable Driver Blocklist, which lags behind community discovery."
KnownBypasses:
- Bypass: Using a driver signed within days of use (defeats static hash blocklists)
@@ -163,15 +163,17 @@ OsintSources:
- Platform: VirusTotal Intelligence
Query: 'behavior_processes:"sc.exe" tag:ransomware'
URL: "https://www.virustotal.com/gui/search/behavior_processes%3A%22sc.exe%22%20tag%3Aransomware"
Notes: "Requires VT Intelligence subscription. Returns ransomware samples where sc.exe was spawned during dynamic analysis. Pivot to behavior tab on any result to extract the full service kill list for that family."
Notes: "Requires VT Intelligence subscription. Returns ransomware samples where sc.exe was spawned during dynamic analysis. Pivot to behavior tab on any result to extract the full service kill list for that family — feed those service names into the analyst Sigma rule's service name filter list."
- Platform: GitHub Code Search
Query: '"net stop" "sc delete" ransomware path:*.ps1 OR path:*.bat OR path:*.txt'
URL: "https://github.com/search?q=%22net+stop%22+%22sc+delete%22+ransomware&type=code"
Notes: "Finds scripts and extracted kill lists published by researchers after sample analysis. Narrow by filename extension to filter noise; .txt and .md files often contain raw kill lists ripped from decompiled samples."
Notes: "Finds scripts and extracted kill lists published by researchers after sample analysis. Filter by extension — .txt and .md files often contain raw kill lists ripped from decompiled samples. Update the analyst rule's service name list whenever new families are documented."
- Platform: ANY.RUN Public Feed
Query: "ransomware tag:service-stop"
URL: "https://any.run/malware-trends/ransomware"
Notes: "Interactive sandbox with a public malware feed. Filter by ransomware family and inspect process trees live — sc.exe and net.exe child process chains are clearly visible without needing a local sandbox."
URL: "https://app.any.run/submissions#status=public&tag=ransomware"
Notes: "Interactive sandbox with a public task feed. Filter to public ransomware submissions and inspect process trees — sc.exe and net.exe child process chains are clearly visible without needing a local sandbox. Useful for rapid triage of new ransomware samples before full analysis."
- Platform: Ransomware.live
URL: "https://www.ransomware.live"
Notes: "Real-time ransomware group activity tracker sourced from dark web leak sites. Use to identify which ransomware families are currently most active — prioritize hunting for those families' service kill lists in your environment. Also see ransomlook.io (open-source, API access) for programmatic integration."
KnownBypasses:
- Bypass: Tamper protection enabled on EDR (requires kernel-level access to disable)
@@ -186,17 +186,24 @@ RelatedChokepoints:
OsintSources:
- Platform: URLScan
Query: "filename:tax*.exe OR filename:invoice*.exe OR filename:ssn*.exe"
Query: "filename:tax*.exe OR filename:invoice*.exe OR filename:ssn*.exe OR filename:support*.exe OR filename:verify*.exe"
URL: "https://urlscan.io/search/#filename%3Atax*.exe%20OR%20filename%3Ainvoice*.exe%20OR%20filename%3Assn*.exe"
Notes: "Finds download pages serving tax/invoice-themed executables — the most common ClickFix and RMM masquerade pretexts. Expand with 'support*.exe', 'verify*.exe' for additional pretext coverage."
Notes: "Finds download pages serving tax/invoice/support-themed executables — the most common RMM masquerade pretexts. Extend with seasonal pretexts (W2, refund, enrollment) during relevant periods."
- Platform: Shodan
Query: 'product:"ScreenConnect"'
URL: "https://www.shodan.io/search?query=product%3A%22ScreenConnect%22"
Notes: "Find internet-exposed ScreenConnect instances; cross-reference against known legitimate MSP infrastructure to identify attacker-controlled instances. Useful for CVE-2024-1709 exposure assessment."
Notes: "Find internet-exposed ScreenConnect instances; cross-reference against known legitimate MSP infrastructure to identify attacker-controlled instances. Also run product:\"SimpleHelp\" to cover the actively exploited CVE-2024-57727 vector (CISA AA25-163A)."
- Platform: Censys
Query: 'services.tls.certificate.parsed.subject.common_name: "AnyDesk"'
URL: "https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22AnyDesk%22"
Notes: "Updated Censys v2 field syntax (replaces deprecated ssl: prefix). Identifies infrastructure presenting AnyDesk TLS certificates; useful for correlating attacker-controlled AnyDesk relay infrastructure."
Query: 'services.tls.certificate.parsed.subject.common_name: "SimpleHelp"'
URL: "https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22SimpleHelp%22"
Notes: "Finds infrastructure presenting SimpleHelp TLS certificates — currently the most actively exploited RMM platform per CISA AA25-163A (June 2025). For AnyDesk: its certificates were revoked following the February 2024 production server breach, making cert-based hunting less reliable — pivot to the VT PE metadata query below for AnyDesk binary identification instead."
- Platform: VirusTotal Intelligence
Query: 'have:itw tag:peexe (metadata:"AnyDesk" OR metadata:"ScreenConnect" OR metadata:"SimpleHelp" OR metadata:"NetSupport")'
URL: "https://www.virustotal.com/gui/search/have%3Aitw%20tag%3Apeexe%20metadata%3A%22AnyDesk%22"
Notes: "Requires VT Intelligence subscription. Finds PE executables observed in the wild whose internal metadata (OriginalFilename, Company, Product fields) references known RMM vendors. These are renamed or repackaged RMM binaries — the core delivery mechanism. Pivot to Details > PE Info to confirm metadata mismatch between submitted filename and OriginalFilename."
- Platform: LOLRMM
URL: "https://lolrmm.io"
Notes: "Community-maintained catalog of every known RMM tool with file metadata, network indicators, and detection heuristics. Use to extract OriginalFilename values and network destinations for any RMM tool to feed into VT metadata searches and network-based detection rules. Essential reference for keeping the renamed-binary analyst rule current as new tools emerge."
KnownBypasses:
- Bypass: Legitimate business use of the same RMM tool
@@ -185,18 +185,21 @@ RelatedChokepoints:
- ransomware-service-manipulation
OsintSources:
- Platform: Shodan
Query: "port:445 country:US"
URL: "https://www.shodan.io/search?query=port%3A445+country%3AUS"
Notes: "Find internet-exposed SMB — targets for external lateral movement and NTLM relay. Narrow with 'org:' or 'asn:' to scope to specific environments during red team or exposure assessments."
- Platform: Shodan
Query: 'port:5985 product:"Microsoft HTTPAPI"'
URL: "https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22"
Notes: "Find internet-exposed WinRM endpoints (Evil-WinRM targets). Port 5986 is the HTTPS variant — run a second query substituting 5986 for full coverage."
Notes: "Finds internet-exposed WinRM endpoints (Evil-WinRM targets). Use as an exposure audit to identify unintentionally exposed WinRM in your own IP ranges (narrow with 'org:' or 'net:' filters). Port 5986 is the HTTPS variant — run a second query substituting 5986. Note: searching for exposed ports finds your attack surface, not attacker infrastructure — for hunting attacker C2, use the JARM query below."
- Platform: Shodan
Query: 'ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443'
URL: "https://www.shodan.io/search?query=ssl.jarm%3A07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5"
Notes: "Default Cobalt Strike JARM fingerprint. Clusters of hosts sharing this fingerprint are likely Cobalt Strike team servers — the most common C2 framework used alongside Impacket/NetExec in lateral movement chains. JARM fingerprints are more resilient to infrastructure rotation than IP/domain blocklists. Also search for Sliver C2 (ssl.jarm:29d29d00029d29d00042d41d00041d2aa5ce6a70de7ba95aef77a77b00a0af) and check hunt.io for current Havoc signatures."
- Platform: GitHub Code Search
Query: '"wmiexec" OR "smbexec" OR "atexec" path:*.py'
URL: "https://github.com/search?q=%22wmiexec%22+OR+%22smbexec%22+OR+%22atexec%22+path%3A*.py&type=code"
Notes: "Finds community tools and forks built on Impacket execution primitives; more targeted than a keyword search. Monitor for new modules that extend the execution surface beyond the known chokepoint."
Notes: "Finds community tools and forks built on Impacket execution primitives. Monitor for new modules that extend the execution surface beyond the known chokepoint. This is a tool-tracking query (defender awareness), not infrastructure hunting — results are researcher repos, not attacker infrastructure."
- Platform: hunt.io
URL: "https://hunt.io"
Notes: "Specialized threat hunting platform that maps active C2 infrastructure in real time. Use to search for Cobalt Strike, Sliver, Havoc, and Metasploit infrastructure — the C2 frameworks most commonly paired with Impacket/NetExec lateral movement. The AttackCapture feed tags servers by framework based on banner, certificate, and behavioral fingerprints."
KnownBypasses:
- Bypass: Using legitimate service names that blend in with existing services
+9 -5
View File
@@ -283,17 +283,21 @@ RelatedChokepoints:
OsintSources:
- Platform: Shodan
Query: 'http.title:"WSO" OR http.title:"b374k" OR http.title:"c99"'
Query: 'http.title:"WSO" OR http.title:"b374k" OR http.title:"c99" OR http.title:"FilesMan" OR http.title:"Antak Webshell"'
URL: "https://www.shodan.io/search?query=http.title%3A%22WSO%22+OR+http.title%3A%22b374k%22+OR+http.title%3A%22c99%22"
Notes: "Finds internet-exposed web shells with default page titles still intact — common in mass exploitation campaigns where attacker cadence outpaces cleanup. Useful for identifying unprotected shells accessible to any attacker, not just the original deployer."
Notes: "Finds internet-exposed web shells with default page titles intact — common in mass exploitation campaigns where attacker cadence outpaces cleanup. FilesMan and Antak are additional shells frequently left exposed. Also try http.html:\"eval(base64_decode\" to catch obfuscated PHP shells that render without a recognizable title."
- Platform: URLScan
Query: 'page.title:"WSO" OR filename:shell.php'
Query: 'page.title:"WSO" OR filename:shell.php OR filename:webshell.php OR filename:cmd.aspx'
URL: "https://urlscan.io/search/#page.title%3A%22WSO%22+OR+filename%3Ashell.php"
Notes: "Finds recently scanned pages presenting known webshell UI or common shell filenames; useful for tracking active campaign infrastructure and identifying newly deployed shells before cleanup."
Notes: "Finds recently scanned pages presenting known webshell UI or common shell filenames; useful for tracking active campaign infrastructure and identifying newly deployed shells before cleanup. Add filenames specific to recent campaigns (e.g., human2.aspx for LEMURLOOT/MOVEit)."
- Platform: VirusTotal Intelligence
Query: 'tag:webshell positives:0 type:text'
URL: "https://www.virustotal.com/gui/search/tag%3Awebshell%20positives%3A0%20type%3Atext"
Notes: "Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection — the most dangerous variants in active use. Cross-reference with ShellForge paper finding that adversarially generated shells achieve 93.9% evasion rate against commercial engines."
Notes: "Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection — the most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against commercial engines. Sort by submission date to prioritize the newest evasive variants."
- Platform: Censys
Query: 'services.http.response.body: "eval(base64_decode" and services.http.response.status_code: 200'
URL: "https://search.censys.io/search?resource=hosts&q=services.http.response.body%3A+%22eval(base64_decode%22"
Notes: "Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern — a near-universal indicator of a live obfuscated PHP shell. High precision; few legitimate pages contain this pattern. Requires Censys account."
KnownBypasses:
- Bypass: Multi-layer encoding (base64 + gzinflate + XOR + eval) bypasses keyword and signature scanning