Files
itm4n-PrivescCheck/data/EndpointProtectionSignatures.csv
2025-08-25 18:40:02 +02:00

36 lines
2.2 KiB
CSV

"Name", "Signature"
"AMSI", "amsi.dll"
"AppSense", "emcoreservice,emsystem,watchdogagent"
"Avast", "avast"
"Avecto Defendpoint", "avecto,defendpoint,pgeposervice,pgsystemtray,privilegeguard"
"Carbon Black", "carbon,cb.exe,logrhythm"
"Cisco AMP", "ciscoamp"
"CounterTack", "countertack"
"CrowdStrike", "crowdstrike,csagent,csfalcon,csshell,windowssensor"
"Cybereason", "activeconsole,cramtray,crssvc,cybereason"
"Cylance", "cylance,cyoptics,cyupdate"
"Elastic", "elastic-endpoint,elasticendpoint"
"Endgame", "endgame"
"ESET Endpoint Inspector", "inspector"
"eTrust EZ AV", "groundling"
"FireEye", "fireeye,mandiant,xagt"
"ForeScout", "forescout,secureconnector"
"IBM QRadar", "qradar,wincollect"
"Ivanti", "ivanti"
"Kaspersky", "kaspersky"
"Lacuna", "lacuna"
"McAfee", "mcafee"
"Microsoft Defender for Endpoint", "sensendr,sensetvm"
"Morphisec", "morphisec"
"Program Protector", "protectorservice"
"Red Canary", "canary"
"Red Cloak", "procwall,redcloak,cyclorama"
"SentinelOne", "sentinel"
"Sophos", "sophos"
"Symantec Endpoint Protection", "eectrl,semlaunchsvc,sepliveupdate,sisidsservice,sisipsservice,sisipsutil,smc.exe,smcgui,snac64,srtsp,symantec,symcorpui,symefasi"
"Sysinternals Antivirus", "sysinternal"
"Sysinternals Sysmon", "sysmon"
"Tanium Enforce", "tanium,tpython"
"Traps", "cyvera,cyserver,cytray,PaloAltoNetworks,tda.exe,tdawork"
"Trend Micro", "ntrtscan,tmlisten,tmbmsrv,tmssclient,tmccsf,trend"
"Windows Defender", "defender,msascuil,msmpeng,nissrv,securityhealthservice"