mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
6.5 MiB
6.5 MiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * $domain sirtunnel $domain $serverPort* | .{0,1000}\s\$domain\ssirtunnel\s\$domain\s\$serverPort.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 16 |
| 3 | * ,exec(__import__('base64').b64decode("* | .{0,1000}\s,exec\(__import__\(\'base64\'\)\.b64decode\(\".{0,1000} | greyware_tool_keyword | python | suspicious way of exeuting code | T1059 | TA0005 | pytoileur | N/A | Defense Evasion | https://x.com/Ax_Sharma/status/1795813203500322953/photo/4 | 1 | 0 | N/A | Cool package campaign | 8 | 10 | N/A | N/A | N/A | N/A | 22 |
| 4 | * ./level-darwin-bundle-amd64.pkg* | .{0,1000}\s\.\/level\-darwin\-bundle\-amd64\.pkg.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 23 |
| 5 | * ./level-linux-amd64 * | .{0,1000}\s\.\/level\-linux\-amd64\s.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 24 |
| 6 | * ./level-linux-arm64 * | .{0,1000}\s\.\/level\-linux\-arm64\s.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 25 |
| 7 | * /bin/nc * -e /bin/bash* > cron && crontab cron* | .{0,1000}\s\/bin\/nc\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\s\>\scron\s\&\&\scrontab\scron.{0,1000} | greyware_tool_keyword | nc | Linux Persistence Shell cron | T1053 - T1037 | TA0003 | N/A | Calypso - GALLIUM | Persistence | https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md | 1 | 0 | #linux | N/A | 10 | 10 | 1594 | 198 | 2025-04-16T21:16:51Z | 2021-08-16T17:34:25Z | 38 |
| 8 | * /bin/nc * -e /bin/bash*> * crontab cron* | .{0,1000}\s\/bin\/nc\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\>\s.{0,1000}\scrontab\scron.{0,1000} | greyware_tool_keyword | nc | linux commands abused by attackers | T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136 | TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002 | N/A | Calypso - GALLIUM | Exploitation tool | N/A | 1 | 0 | #linux | greyware_tools high risks of false positives | N/A | N/A | N/A | N/A | N/A | N/A | 39 |
| 9 | * /c echo mar3pora * | .{0,1000}\s\/c\secho\smar3pora\s.{0,1000} | greyware_tool_keyword | anydesk | command line used with anydesk in the notes of the ransomware group | T1486 - T1490 - T1059 - T1213 - T1078 | TA0040 - TA0043 - TA0001 - TA0009 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41 |
| 10 | * /c echo Pa$$w0rd | C:\ProgramData\anydesk.exe* | .{0,1000}\s\/c\secho\sPa\$\$w0rd\s\|\sC\:\\ProgramData\\anydesk\.exe.{0,1000} | greyware_tool_keyword | anydesk | command line used with anydesk in the notes of the ransomware group | T1486 - T1490 - T1059 - T1213 - T1078 | TA0040 - TA0043 - TA0001 - TA0009 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 42 |
| 11 | * /c sc query WinDefend* | .{0,1000}\s\/c\ssc\squery\sWinDefend.{0,1000} | greyware_tool_keyword | sc | Get information about Windows Defender service | T1518.001 - T1049 | TA0007 - TA0009 | N/A | Snatch | Discovery | https://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 44 |
| 12 | * /c start /min powershell -noprofile -w H -c *irw* | .{0,1000}\s\/c\sstart\s\/min\spowershell\s\-noprofile\s\-w\sH\s\-c\s.{0,1000}irw.{0,1000} | greyware_tool_keyword | powershell | Suspicious PowerShell execution behavior often observed in FakeCaptcha phishing attempts | T1059.001 - T1027 - T1564.003 | TA0005 - TA0002 - TA0009 | N/A | N/A | Collection | https://x.com/malware_traffic/status/1884476331821326816/photo/2 | 1 | 0 | N/A | N/A | 7 | 6 | N/A | N/A | N/A | N/A | 45 |
| 13 | * /config:netscan.xml * | .{0,1000}\s\/config\:netscan\.xml\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 51 |
| 14 | * /Create /RU SYSTEM /TN MicrosoftEdgeUpdateTaskMachine /TR * | .{0,1000}\s\/Create\s\/RU\sSYSTEM\s\/TN\sMicrosoftEdgeUpdateTaskMachine\s\/TR\s.{0,1000} | greyware_tool_keyword | schtasks | SSH backdoor creation with schtasks | T1053 - T1059.004 - T1090 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 52 |
| 15 | * /create /tn "SysChecks" /tr c:\temp\sch.bat * | .{0,1000}\s\/create\s\/tn\s\"SysChecks\"\s\/tr\sc\:\\temp\\sch\.bat\s.{0,1000} | greyware_tool_keyword | schtasks | SSH backdoor creation with schtasks | T1053 - T1059.004 - T1090 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 54 |
| 16 | * /Create /TN sch.bat /TR "c:\temp\script.vbs" * | .{0,1000}\s\/Create\s\/TN\ssch\.bat\s\/TR\s\"c\:\\temp\\script\.vbs\"\s.{0,1000} | greyware_tool_keyword | schtasks | SSH backdoor creation with schtasks | T1053 - T1059.004 - T1090 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56 |
| 17 | * /EV"NetSupport School"* | .{0,1000}\s\/EV\"NetSupport\sSchool\".{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 66 |
| 18 | * /f /im RemotePCS* | .{0,1000}\s\/f\s\/im\sRemotePCS.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 67 |
| 19 | * /F /TN "Level\Level Watchdog"* | .{0,1000}\s\/F\s\/TN\s\"Level\\Level\sWatchdog\".{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 68 |
| 20 | * /monitor /from_service /cpu_memory_refresh * /disk_space_refresh * /proc_list_refresh * /semkey * | .{0,1000}\s\/monitor\s\/from_service\s\/cpu_memory_refresh\s.{0,1000}\s\/disk_space_refresh\s.{0,1000}\s\/proc_list_refresh\s.{0,1000}\s\/semkey\s.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 81 |
| 21 | * /r /proxy /proxyport /proxyusername /proxypasswd * | .{0,1000}\s\/r\s\/proxy\s\s\/proxyport\s\s\/proxyusername\s\s\/proxypasswd\s.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 93 |
| 22 | * /register /proxy /proxyport /proxyusername /proxypasswd* | .{0,1000}\s\/register\s\s\/proxy\s\s\/proxyport\s\s\/proxyusername\s\s\/proxypasswd.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 95 |
| 23 | * /usr/local/bin/expose* | .{0,1000}\s\/usr\/local\/bin\/expose.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 0 | #linux | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 114 |
| 24 | * /v "DisableAntiSpyware" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableAntiSpyware\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 115 |
| 25 | * /v "DisableAntiVirus" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableAntiVirus\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 116 |
| 26 | * /v "DisableIOAVProtection" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableIOAVProtection\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 117 |
| 27 | * /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableOnAccessProtection\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 118 |
| 28 | * /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableRealtimeMonitoring\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 119 |
| 29 | * /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f* | .{0,1000}\s\/v\s\"DisableScanOnRealtimeEnable\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 120 |
| 30 | * /v "MpEnablePus" /t REG_DWORD /d "0" /f* | .{0,1000}\s\/v\s\"MpEnablePus\"\s\/t\sREG_DWORD\s\/d\s\"0\"\s\/f.{0,1000} | greyware_tool_keyword | reg | disable protection features of Windows Defender | T1562.001 - T1112 | TA0005 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Defense Evasion | https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c01 | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 121 |
| 31 | * /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f* | .{0,1000}\s\/v\sDisableRealtimeMonitoring\s\/t\sREG_DWORD\s\/d\s1\s\/f.{0,1000} | greyware_tool_keyword | reg | reg command used to disabled real time monitoring defender - often abused by attackers | T1562.001 - T1112 - T1059 - T1036 | TA0005 - TA0040 | N/A | Dispossessor | Defense Evasion | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 126 |
| 32 | * /var/log -type f -exec */tr* -s 0 {} \* | .{0,1000}\/\?\?\?\/\?\?\?\/f\?n\?\s\/var\/log\s\-type\sf\s\-exec\s\/\?\?\?\/\?\?\?\/tr\?\?\?\?\?e\s\-s\s0\s\{\}\s\\.{0,1000} | greyware_tool_keyword | find | truncate every file under /var/log to size 0 - no log content = no forensic. | T1486 - T1553 - T1592.002 - T1081 | TA0005 - TA0007 - TA0009 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 128 |
| 33 | * \\\\localhost /user:Username /pwd:Password \"C:\\InstallMe.bat* | .{0,1000}\s\\\\\\\\localhost\s\/user\:Username\s\/pwd\:Password\s\s\\\"C\:\\\\InstallMe\.bat.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 131 |
| 34 | * | clbin* | .{0,1000}\s\|\sclbin.{0,1000} | greyware_tool_keyword | clbin.com | clbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands. | T1567.002 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://clbin.com/ | 1 | 0 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 134 |
| 35 | * <Data>Received Request Run command *</Data>* | .{0,1000}\s\<Data\>Received\sRequest\sRun\scommand\s.{0,1000}\<\/Data\>.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 138 |
| 36 | * > /var/log/syslog* | .{0,1000}\s\>\s\/var\/log\/syslog.{0,1000} | greyware_tool_keyword | bash | Indicator Removal on Host - clearing logs | T1070.002 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/mthcht/atomic-red-team/blob/master/atomics/T1070.002/T1070.002.md | 1 | 0 | #linux | N/A | 10 | 1 | 0 | 0 | 2025-03-01T22:20:20Z | 2025-03-01T21:01:46Z | 143 |
| 37 | * >/var/log/syslog* | .{0,1000}\s\>\/var\/log\/syslog.{0,1000} | greyware_tool_keyword | bash | Indicator Removal on Host - clearing logs | T1070.002 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/mthcht/atomic-red-team/blob/master/atomics/T1070.002/T1070.002.md | 1 | 0 | #linux | N/A | 10 | 1 | 0 | 0 | 2025-03-01T22:20:20Z | 2025-03-01T21:01:46Z | 150 |
| 38 | * -a tcrmtshellagentmodule_* | .{0,1000}\s\-a\stcrmtshellagentmodule_.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | Dameware Remote Support | 10 | 10 | N/A | N/A | N/A | N/A | 174 |
| 39 | * a.pinggy.io* | .{0,1000}\sa\.pinggy\.io.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 175 |
| 40 | * -accepteula -nobanner -d cmd.exe /c * | .{0,1000}\s\-accepteula\s\-nobanner\s\-d\scmd\.exe\s\/c\s.{0,1000} | greyware_tool_keyword | psexec | Adversaries may place the PsExec executable in the temp directory and execute it from there as part of their offensive activities. By doing so. they can leverage PsExec to execute commands or launch processes on remote systems. enabling Lateral Movement. privilege escalation. or the execution of malicious payloads. | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0008 - TA0009 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Lateral Movement | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 178 |
| 41 | * adaudit.ps1* | .{0,1000}\sadaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 201 |
| 42 | * admin create frontend sqJRAINSiB public * | .{0,1000}\sadmin\screate\sfrontend\ssqJRAINSiB\spublic\s.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 231 |
| 43 | * ADRecon.ps1* | .{0,1000}\sADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 239 |
| 44 | * advfirewall firewall add rule * dir=in protocol=tcp localport=3389 action=allow* | .{0,1000}\sadvfirewall\sfirewall\sadd\srule\s.{0,1000}\sdir\=in\sprotocol\=tcp\slocalport\=3389\saction\=allow.{0,1000} | greyware_tool_keyword | netsh | Opens port 3389 for RDP inbound access through the firewall | T1021.001 - T1562.004 | TA0008 - TA0005 | N/A | N/A | Lateral Movement | N/A | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 240 |
| 45 | * aeroadmin.exe* | .{0,1000}\saeroadmin\.exe.{0,1000} | greyware_tool_keyword | aeroadmin | RMM software - full remote control / file transfer | T1021.001 - T1048.003 | TA0008 - TA0011 - TA0009 - TA0010 | N/A | N/A | RMM | https://ulm.aeroadmin.com/AeroAdmin.exe | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 241 |
| 46 | * Ahk2Exe.exe* | .{0,1000}\sAhk2Exe\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 0 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 250 |
| 47 | * -altgw *.zohoassist.com * | .{0,1000}\s\-altgw\s.{0,1000}\.zohoassist\.com\s.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 260 |
| 48 | * --bin sshx-server* | .{0,1000}\s\-\-bin\ssshx\-server.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 0 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 390 |
| 49 | * boringproxy-client.service* | .{0,1000}\sboringproxy\-client\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 425 |
| 50 | * boringproxy-server.service* | .{0,1000}\sboringproxy\-server\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 426 |
| 51 | * -c 'import pty;pty.spawn("/bin/bash* | .{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\"\/bin\/bash.{0,1000} | greyware_tool_keyword | python | interactive shell | T1059 | TA0002 - TA0011 | N/A | N/A | C2 | N/A | 1 | 0 | #linux | greyware_tools high risks of false positives | 6 | 10 | N/A | N/A | N/A | N/A | 505 |
| 52 | * -c 'import pty;pty.spawn("/bin/sh* | .{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\"\/bin\/sh.{0,1000} | greyware_tool_keyword | python | interactive shell | T1059 | TA0002 - TA0011 | N/A | N/A | C2 | N/A | 1 | 0 | #linux | greyware_tools high risks of false positives | 6 | 10 | N/A | N/A | N/A | N/A | 507 |
| 53 | * -c 'import pty;pty.spawn(\"/bin/sh* | .{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\\\"\/bin\/sh.{0,1000} | greyware_tool_keyword | python | interactive shell | T1059 | TA0002 - TA0011 | N/A | N/A | C2 | N/A | 1 | 0 | #linux | greyware_tools high risks of false positives | 6 | 4 | N/A | N/A | N/A | N/A | 508 |
| 54 | * -c rest_client_zrok -t* | .{0,1000}\s\-c\srest_client_zrok\s\-t.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 512 |
| 55 | * -c1 * --data-string * --icmp * | .{0,1000}\s\-c1\s.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-\-icmp\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 524 |
| 56 | * -c1 * --icmp * --data-string * | .{0,1000}\s\-c1\s.{0,1000}\s\-\-icmp\s.{0,1000}\s\-\-data\-string\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 525 |
| 57 | * c3pool_miner* | .{0,1000}\sc3pool_miner.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 0 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 531 |
| 58 | * chrome-remote-desktop@* | .{0,1000}\schrome\-remote\-desktop\@.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 578 |
| 59 | * CN=Quasar Server CA* | .{0,1000}\sCN\=Quasar\sServer\sCA.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 0 | #content | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 621 |
| 60 | * --coin *--nicehash * | .{0,1000}\s\-\-coin\s.{0,1000}\-\-nicehash\s.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 0 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 633 |
| 61 | * --coin=monero* | .{0,1000}\s\-\-coin\=monero.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 0 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 634 |
| 62 | * --config=*c3pool*config_background.json* | .{0,1000}\s\-\-config\=.{0,1000}c3pool.{0,1000}config_background\.json.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 0 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 675 |
| 63 | * Connection #*. Connection to "*" established. Mode: <Remote control>.* | .{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\sestablished\.\sMode\:\s\<Remote\scontrol\>\..{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #content | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 686 |
| 64 | * Connection #*. Connection to "*". Security check - OK. Mode: <Inventory manager>* | .{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\.\sSecurity\scheck\s\-\sOK\.\sMode\:\s\s\<Inventory\smanager\>.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #content | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 687 |
| 65 | * Connection #*. Connection to "*". Security check - OK. Mode: <Command (command: *)> | .{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\.\sSecurity\scheck\s\-\sOK\.\sMode\:\s\<Command\s\(command\:\s.{0,1000}\)\> | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #content | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 688 |
| 66 | * Connection #*. Direct connection to * (*:5650).* | .{0,1000}\sConnection\s\#.{0,1000}\.\sDirect\sconnection\sto\s.{0,1000}\s\(.{0,1000}\:5650\)\..{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #content | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 689 |
| 67 | * create RPCService start=* | .{0,1000}\screate\sRPCService\sstart\=.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 725 |
| 68 | * create ViewerService start=auto* | .{0,1000}\screate\sViewerService\sstart\=auto.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 726 |
| 69 | * croc-entrypoint.sh* | .{0,1000}\scroc\-entrypoint\.sh.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 0 | #linux | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 739 |
| 70 | * -csrc C:\\Windows\\notepad.exe -c cmd.exe* | .{0,1000}\s\-csrc\sC\:\\\\Windows\\\\notepad\.exe\s\-c\scmd\.exe.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 0 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 746 |
| 71 | * Dameware Mini Remote Control x64 -- Installation completed successfully* | .{0,1000}\sDameware\sMini\sRemote\sControl\sx64\s\-\-\sInstallation\scompleted\ssuccessfully.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | Dameware Remote Support | 10 | 10 | N/A | N/A | N/A | N/A | 776 |
| 72 | * --data-string * -c1 * --icmp * | .{0,1000}\s\-\-data\-string\s.{0,1000}\s\-c1\s.{0,1000}\s\-\-icmp\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 781 |
| 73 | * --data-string * --icmp * -c1 * | .{0,1000}\s\-\-data\-string\s.{0,1000}\s\-\-icmp\s.{0,1000}\s\-c1\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 782 |
| 74 | * dclist * | .{0,1000}\sdclist\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 796 |
| 75 | * del C:\Windows\temp\1 /F /Q* | .{0,1000}\sdel\sC\:\\Windows\\temp\\1\s\/F\s\/Q.{0,1000} | greyware_tool_keyword | del | suspicious deletion made by the Russian Foreign Intelligence Service | T1059.003 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/mthcht/ThreatIntel-Reports | 1 | 0 | N/A | N/A | 8 | 2 | 109 | 9 | 2025-04-22T03:37:27Z | 2024-10-23T11:27:13Z | 814 |
| 76 | * denied AXFR from * | .{0,1000}\sdenied\sAXFR\sfrom\s.{0,1000} | greyware_tool_keyword | dns | Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts | T1071.004 - T1078.004 | TA0011 - TA0006 | N/A | N/A | Exploitation tool | https://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | 10 | 4692 | 1051 | 2025-01-22T01:58:36Z | 2013-09-17T17:07:58Z | 824 |
| 77 | * dir /s */ Microsoft.ActiveDirectory.Management.dll* | .{0,1000}\sdir\s\/s\s.{0,1000}\/\sMicrosoft\.ActiveDirectory\.Management\.dll.{0,1000} | greyware_tool_keyword | dir | threat actors searched for Active Directory related DLLs in directories | T1059 - T1083 - T1018 | TA0002 - TA0009 - TA0040 | N/A | N/A | Discovery | https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 844 |
| 78 | * --donate-level=* | .{0,1000}\s\-\-donate\-level\=.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 0 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 922 |
| 79 | * --doNotTestSMBv1* | .{0,1000}\s\-\-doNotTestSMBv1.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 924 |
| 80 | * downloads.level.io* | .{0,1000}\sdownloads\.level\.io.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 945 |
| 81 | * DownloadServer=https://www.gotomypc.com * | .{0,1000}\sDownloadServer\=https\:\/\/www\.gotomypc\.com\s.{0,1000} | greyware_tool_keyword | GoToMyPC | GoToMyPC is remote desktop software that allows users to access computers remotely using a web browser | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | N/A | RMM | https://www.gotomypc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 946 |
| 82 | * dropping source port zero packet from * | .{0,1000}\sdropping\ssource\sport\szero\spacket\sfrom\s.{0,1000} | greyware_tool_keyword | dns | Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts | T1071.004 - T1078.004 | TA0011 - TA0006 | N/A | N/A | Exploitation tool | https://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | 10 | 4692 | 1051 | 2025-01-22T01:58:36Z | 2013-09-17T17:07:58Z | 967 |
| 83 | * DumpS1.ps1* | .{0,1000}\sDumpS1\.ps1.{0,1000} | greyware_tool_keyword | SentinelAgent | dump a process with SentinelAgent.exe | T1003 - T1055 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e | 1 | 0 | N/A | N/A | 8 | 7 | N/A | N/A | N/A | N/A | 1004 |
| 84 | * ecivreS-potS* | .{0,1000}\secivreS\-potS.{0,1000} | greyware_tool_keyword | _ | reversed string for obfuscation | T1027 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1019 |
| 85 | * -ep Bypass -nop function *[System.Security.Cryptography.Aes]::Create()*.CreateDecryptor()*.TransformFinalBlock*[System.Text.Encoding]::Utf8.GetString* | .{0,1000}\s\-ep\sBypass\-nop\sfunction\s.{0,1000}\[System\.Security\.Cryptography\.Aes\]\:\:Create\(\).{0,1000}\.CreateDecryptor\(\).{0,1000}\.TransformFinalBlock.{0,1000}\[System\.Text\.Encoding\]\:\:Utf8\.GetString.{0,1000} | greyware_tool_keyword | powershell | obfuscation techniques with powershell | T1059.001 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1067 |
| 86 | * -ep Unrestricted -nop function *[System.Security.Cryptography.Aes]::Create()*.CreateDecryptor()*.TransformFinalBlock*[System.Text.Encoding]::Utf8.GetString* | .{0,1000}\s\-ep\sUnrestricted\s\-nop\sfunction\s.{0,1000}\[System\.Security\.Cryptography\.Aes\]\:\:Create\(\).{0,1000}\.CreateDecryptor\(\).{0,1000}\.TransformFinalBlock.{0,1000}\[System\.Text\.Encoding\]\:\:Utf8\.GetString.{0,1000} | greyware_tool_keyword | powershell | obfuscation techniques with powershell | T1059.001 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1068 |
| 87 | * erase /quiet /method=* data dir=* | .{0,1000}\serase\s\/quiet\s\/method\=.{0,1000}\sdata\sdir\=.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 1071 |
| 88 | * erase /quiet /methodName=* data dir=* | .{0,1000}\serase\s\/quiet\s\/methodName\=.{0,1000}\sdata\sdir\=.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 1072 |
| 89 | * -exec bypass -nop -c whoami* | .{0,1000}\s\-exec\sbypass\s\-nop\s\-c\swhoami.{0,1000} | greyware_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0007 | N/A | Black Basta | Discovery | N/A | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 1101 |
| 90 | * exiting (due to fatal error)* | .{0,1000}\sexiting\s\(due\sto\sfatal\serror\).{0,1000} | greyware_tool_keyword | dns | Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts | T1071.004 - T1078.004 | TA0011 - TA0006 | N/A | N/A | Exploitation tool | https://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | 10 | 4692 | 1051 | 2025-01-22T01:58:36Z | 2013-09-17T17:07:58Z | 1131 |
| 91 | * -f "(objectcategory=computer)" -s subtree dn operatingSystem* | .{0,1000}\s\-f\s\"\(objectcategory\=computer\)\"\s\-s\ssubtree\sdn\soperatingSystem.{0,1000} | greyware_tool_keyword | adfind | Enumerate All Computers in the Domain | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1143 |
| 92 | * -f "(objectcategory=person)" -s subtree samaccountname userPrincipalName* | .{0,1000}\s\-f\s\"\(objectcategory\=person\)\"\s\-s\ssubtree\ssamaccountname\suserPrincipalName.{0,1000} | greyware_tool_keyword | adfind | Enumerate All Users in the Domain | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1144 |
| 93 | * -f "(objectcategory=trustedDomain)" -s subtree name trustAttributes trustDirection trustType* | .{0,1000}\s\-f\s\"\(objectcategory\=trustedDomain\)\"\s\-s\ssubtree\sname\strustAttributes\strustDirection\strustType.{0,1000} | greyware_tool_keyword | adfind | Dump All Domain Trusts | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1145 |
| 94 | * -f *.dmp windows.cmdline* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.cmdline.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1148 |
| 95 | * -f *.dmp windows.dlllist --pid * | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.dlllist\s\-\-pid\s.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1149 |
| 96 | * -f *.dmp windows.filescan* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.filescan.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1150 |
| 97 | * -f *.dmp windows.handles --pid * | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.handles\s\-\-pid\s.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1151 |
| 98 | * -f *.dmp windows.info* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.info.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1152 |
| 99 | * -f *.dmp windows.malfind* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.malfind.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1153 |
| 100 | * -f *.dmp windows.netscan* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.netscan.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1154 |
| 101 | * -f *.dmp windows.netstat* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.netstat.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1155 |
| 102 | * -f *.dmp windows.pslist* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.pslist.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1156 |
| 103 | * -f *.dmp windows.psscan* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.psscan.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1157 |
| 104 | * -f *.dmp windows.pstree* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.pstree.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1158 |
| 105 | * -f *.dmp windows.registry.hivelist* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.hivelist.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1159 |
| 106 | * -f *.dmp windows.registry.hivescan* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.hivescan.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1160 |
| 107 | * -f *.dmp windows.registry.printkey* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.printkey.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1161 |
| 108 | * -f *.dmp windows.registry.printkey*Software\Microsoft\Windows\CurrentVersion* | .{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.printkey.{0,1000}Software\\Microsoft\\Windows\\CurrentVersion.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | #registry | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1162 |
| 109 | * Get-AVStatus.ps1* | .{0,1000}\sGet\-AVStatus\.ps1.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 0 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 1315 |
| 110 | * gifnoc cs* | .{0,1000}\sgifnoc\scs.{0,1000} | greyware_tool_keyword | _ | reversed string for obfuscation | T1027 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1340 |
| 111 | * gost.tar.gz* | .{0,1000}\sgost\.tar\.gz.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 0 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 1363 |
| 112 | * gost/cmd/gost* | .{0,1000}\sgost\/cmd\/gost.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 0 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 1364 |
| 113 | * gotoopener://launch.getgo.com/* | .{0,1000}\sgotoopener\:\/\/launch\.getgo\.com\/.{0,1000} | greyware_tool_keyword | GoToMyPC | GoToMyPC is remote desktop software that allows users to access computers remotely using a web browser | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | N/A | RMM | https://www.gotomypc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1366 |
| 114 | * gt-win-x86_64.exe* | .{0,1000}\sgt\-win\-x86_64\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 0 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 1396 |
| 115 | * host -p * --allow-anonymous --protocol https* | .{0,1000}\shost\s\-p\s.{0,1000}\s\-\-allow\-anonymous\s\-\-protocol\shttps.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 1432 |
| 116 | * host -p 443 -allow-anonymous* | .{0,1000}\shost\s\-p\s443\s\-allow\-anonymous.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 1433 |
| 117 | * hostPath="c:\" writable="true" autoMount="true"* | .{0,1000}\shostPath\=\"c\:\\\"\swritable\=\"true\"\sautoMount\=\"true\".{0,1000} | greyware_tool_keyword | VirtualBox | adding the entire C drive as a shared folder for a VM | T1021.001 - T1137 - T1072 | TA0006 - TA0008 - TA0005 | N/A | RagnarLocker | Persistence | https://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1440 |
| 118 | * http-put-server.py* | .{0,1000}\shttp\-put\-server\.py.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | N/A | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 1525 |
| 119 | * -i remotepc.deb* | .{0,1000}\s\-i\sremotepc\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1599 |
| 120 | * --icmp * -c1 * --data-string * | .{0,1000}\s\-\-icmp\s.{0,1000}\s\-c1\s.{0,1000}\s\-\-data\-string\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 1608 |
| 121 | * --icmp * --data-string * -c1 * | .{0,1000}\s\-\-icmp\s.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-c1\s.{0,1000} | greyware_tool_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 1609 |
| 122 | * install bore-cli* | .{0,1000}\sinstall\sbore\-cli.{0,1000} | greyware_tool_keyword | bore | bore is a simple CLI tool for making tunnels to localhost | T1090 - T1090.003 - T1572 - T1572.001 | TA0042 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/ekzhang/bore | 1 | 0 | N/A | N/A | 10 | 10 | 9634 | 410 | 2025-04-14T21:52:18Z | 2022-04-04T02:47:54Z | 1678 |
| 123 | * install -c conda-forge sshtunnel* | .{0,1000}\sinstall\s\-c\sconda\-forge\ssshtunnel.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 1679 |
| 124 | * install c3pool_miner * | .{0,1000}\sinstall\sc3pool_miner\s.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 0 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 1680 |
| 125 | * install localtunnel* | .{0,1000}\sinstall\slocaltunnel.{0,1000} | greyware_tool_keyword | localtunnels | client for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/localtunnel | 1 | 0 | N/A | N/A | 8 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 1694 |
| 126 | * install meshcentral* | .{0,1000}\sinstall\smeshcentral.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 1695 |
| 127 | * install pgrok* | .{0,1000}\sinstall\spgrok.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 0 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 1698 |
| 128 | * install requests_ntlm* | .{0,1000}\sinstall\srequests_ntlm.{0,1000} | greyware_tool_keyword | requests-ntlm | HTTP NTLM Authentication for Requests Library | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://pypi.org/project/requests-ntlm/ | 1 | 0 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 1699 |
| 129 | * install shadowsocks-rust* | .{0,1000}\sinstall\sshadowsocks\-rust.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 1701 |
| 130 | * install softether5* | .{0,1000}\sinstall\ssoftether5.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 0 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 1702 |
| 131 | * install sshuttle* | .{0,1000}\sinstall\ssshuttle.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 0 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 1704 |
| 132 | * install tailscale* | .{0,1000}\sinstall\stailscale.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 0 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 1705 |
| 133 | * install tmate* | .{0,1000}\sinstall\stmate.{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate-ssh-server | 1 | 0 | #linux | N/A | 10 | 10 | 642 | 148 | 2024-06-21T11:52:24Z | 2013-06-09T23:58:55Z | 1706 |
| 134 | * install tunnelto* | .{0,1000}\sinstall\stunnelto.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 0 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 1709 |
| 135 | * install wireguard* | .{0,1000}\sinstall\swireguard.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 0 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 1712 |
| 136 | * install wireguard-tools* | .{0,1000}\sinstall\swireguard\-tools.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 0 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 1713 |
| 137 | * install xvnc4viewer netcat-traditional socat* | .{0,1000}\sinstall\sxvnc4viewer\snetcat\-traditional\ssocat.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 1715 |
| 138 | * install-fleetctl.sh* | .{0,1000}\sinstall\-fleetctl\.sh.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 0 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 1716 |
| 139 | * Invoke-WebRequest -Uri http://download.anydesk.com/AnyDesk.exe* | .{0,1000}\sInvoke\-WebRequest\s\-Uri\shttp\:\/\/download\.anydesk\.com\/AnyDesk\.exe.{0,1000} | greyware_tool_keyword | anydesk | command line used with anydesk in the notes of the Dispossessor ransomware group | T1486 - T1490 - T1059 - T1213 - T1078 | TA0040 - TA0043 - TA0001 - TA0009 | N/A | Dispossessor | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1753 |
| 140 | * IObitUnlocker.exe* | .{0,1000}\sIObitUnlocker\.exe.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 0 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 1756 |
| 141 | * -jar ipscan.exe* | .{0,1000}\s\-jar\sipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | network exploitation tool | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 1798 |
| 142 | * jprq-windows-386.exe* | .{0,1000}\sjprq\-windows\-386\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 1826 |
| 143 | * jprq-windows-amd64.exe* | .{0,1000}\sjprq\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 1827 |
| 144 | * list-recycle-bin.ps1* | .{0,1000}\slist\-recycle\-bin\.ps1.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 0 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 1963 |
| 145 | * localgroup Administrators localadm /ADD * | .{0,1000}\slocalgroup\sAdministrators\slocaladm\s\/ADD\s.{0,1000} | greyware_tool_keyword | net | command used in the Dispossessor ransomware group notes | T1486 - T1490 - T1059 - T1213 - T1078 | TA0040 - TA0043 - TA0001 - TA0009 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2021 |
| 146 | * localtunnel-server* | .{0,1000}\slocaltunnel\-server.{0,1000} | greyware_tool_keyword | localtunnels | server for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/server | 1 | 0 | N/A | N/A | 8 | 10 | 3163 | 1033 | 2024-03-20T09:14:46Z | 2013-06-16T22:30:48Z | 2033 |
| 147 | * LoggingServer=logging.getgo.com ProxyHost=* | .{0,1000}\sLoggingServer\=logging\.getgo\.com\sProxyHost\=.{0,1000} | greyware_tool_keyword | GoToMyPC | GoToMyPC is remote desktop software that allows users to access computers remotely using a web browser | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | N/A | RMM | https://www.gotomypc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2036 |
| 148 | * -log-level trace -dre -log-path * | .{0,1000}\s\-log\-level\strace\s\-dre\s\-log\-path\s.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | Dameware Remote Support | 10 | 10 | N/A | N/A | N/A | N/A | 2038 |
| 149 | * -m boringproxy* | .{0,1000}\s\-m\sboringproxy.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 2058 |
| 150 | * -m SimpleHTTPServer * | .{0,1000}\s\-m\sSimpleHTTPServer\s.{0,1000} | greyware_tool_keyword | simplehttpserver | quick web server in python | T1021.002 - T1059.006 | TA0002 - TA0005 | N/A | N/A | Data Exfiltration | https://docs.python.org/2/library/simplehttpserver.html | 1 | 0 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 2093 |
| 151 | * -m sshtunnel * | .{0,1000}\s\-m\ssshtunnel\s.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 2098 |
| 152 | * -ma lssas.exe* | .{0,1000}\s\-ma\slssas\.exe.{0,1000} | greyware_tool_keyword | Procdump | dump lsass process with procdump | T1003.001 | TA0006 | N/A | LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor | Credential Access | https://learn.microsoft.com/en-us/sysinternals/downloads/procdump | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2109 |
| 153 | * MEGAcmd.sh* | .{0,1000}\sMEGAcmd\.sh.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 2126 |
| 154 | * megasync.exe* | .{0,1000}\smegasync\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2127 |
| 155 | * MEGAsyncSetup32.exe* | .{0,1000}\sMEGAsyncSetup32\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2128 |
| 156 | * MEGAsyncSetup64.exe* | .{0,1000}\sMEGAsyncSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2129 |
| 157 | * meshcentral.service* | .{0,1000}\smeshcentral\.service.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 2141 |
| 158 | * -ms assist.zoho.com -p 443* | .{0,1000}\s\-ms\sassist\.zoho\.com\s\-p\s443.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2189 |
| 159 | * -Name DisableAntiSpyware -Value 1 -PropertyType DWORD -Force* | .{0,1000}\s\-Name\sDisableAntiSpyware\s\-Value\s1\s\-PropertyType\sDWORD\s\-Force.{0,1000} | greyware_tool_keyword | powershell | Defense evasion technique In order to avoid detection at any point of the kill chain. attackers use several ways to disable anti-virus. disable Microsoft firewall and clear logs. | T1562.001 - T1562.002 - T1070.004 | TA0007 - TA0040 - TA0005 | N/A | Dispossessor | Defense Evasion | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 2245 |
| 160 | * --name localtunnel * | .{0,1000}\s\-\-name\slocaltunnel\s.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/NoahShen/gotunnelme | 1 | 0 | N/A | N/A | 10 | 10 | 171 | 45 | 2018-01-06T04:41:15Z | 2013-10-18T02:46:51Z | 2247 |
| 161 | * -name:* -password:* -remoteexecute -filename* | .{0,1000}\s\-name\:.{0,1000}\s\-password\:.{0,1000}\s\-remoteexecute\s\-filename.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2250 |
| 162 | * nc termbin.com * | .{0,1000}\snc\stermbin\.com\s.{0,1000} | greyware_tool_keyword | termbin.com | sending data to a pastebin | T1567.002 | TA0010 | N/A | N/A | Data Exfiltration | termbin.com | 1 | 0 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 2267 |
| 163 | * ncat * -e /bin/bash*|crontab* | .{0,1000}\sncat\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\|crontab.{0,1000} | greyware_tool_keyword | ncat | reverse shell persistence | T1059.004 - T1053.005 - T1059.005 | TA0002 - TA0005 | N/A | Calypso - GALLIUM | Persistence | N/A | 1 | 0 | #linux | greyware_tools high risks of false positives | N/A | N/A | N/A | N/A | N/A | N/A | 2269 |
| 164 | * neoreg.py * | .{0,1000}\sneoreg\.py\s.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 0 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 2284 |
| 165 | * netcat termbin.com * | .{0,1000}\snetcat\stermbin\.com\s.{0,1000} | greyware_tool_keyword | termbin.com | sending data to a pastebin | T1567.002 | TA0010 | N/A | N/A | Data Exfiltration | termbin.com | 1 | 0 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 2292 |
| 166 | * netscan.exe * | .{0,1000}\snetscan\.exe\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2301 |
| 167 | * netscan64.exe * | .{0,1000}\snetscan64\.exe\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2302 |
| 168 | * net-vpn/tailscale* | .{0,1000}\snet\-vpn\/tailscale.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 0 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 2303 |
| 169 | * --nicehash *--coin * | .{0,1000}\s\-\-nicehash\s.{0,1000}\-\-coin\s.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 0 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 2311 |
| 170 | * NimScan.exe* | .{0,1000}\sNimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 2317 |
| 171 | * NimScan.nim* | .{0,1000}\sNimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 2318 |
| 172 | * nircmd.exe* | .{0,1000}\snircmd\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2334 |
| 173 | * nircmdc.exe* | .{0,1000}\snircmdc\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2335 |
| 174 | * -NoExit -Command [Console]::OutputEncoding=[Text.UTF8Encoding]::UTF8* | .{0,1000}\s\-NoExit\s\-Command\s\[Console\]\:\:OutputEncoding\=\[Text\.UTF8Encoding\]\:\:UTF8.{0,1000} | greyware_tool_keyword | powershell | powershell command pattern used by sliver - an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR | C2 | https://github.com/BishopFox/sliver | 1 | 0 | N/A | N/A | 10 | 10 | 9218 | 1249 | 2025-04-21T17:52:43Z | 2019-01-17T22:07:38Z | 2346 |
| 175 | * noitcetorPAUP* | .{0,1000}\snoitcetorPAUP.{0,1000} | greyware_tool_keyword | _ | reversed string for obfuscation | T1027 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2349 |
| 176 | * -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient* | .{0,1000}\s\-NoP\s\-NonI\s\-W\sHidden\s\-Exec\sBypass\s\-Command\sNew\-Object\sSystem\.Net\.Sockets\.TCPClient.{0,1000} | greyware_tool_keyword | powershell | reverse shell powershell | T1059.001 - T1203 - T1105 - T1562.001 | TA0002 - TA0011 | N/A | Black Basta | C2 | https://github.com/mthbernardes/rsg | 1 | 0 | N/A | N/A | 10 | 10 | 561 | 126 | 2024-05-03T16:33:20Z | 2017-12-12T02:57:07Z | 2352 |
| 177 | * -NOP -WIND HIDDeN -eXeC BYPASS -NONI * | .{0,1000}\s\-NOP\s\-WIND\sHIDDeN\s\-eXeC\sBYPASS\s\-NONI\s.{0,1000} | greyware_tool_keyword | powershell | suspicious powershell arguments order used by many exploitation tools | T1059.001 - T1059.003 - T1027.009 | TA0002 - TA0005 | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2356 |
| 178 | * OfflineSamTool.h* | .{0,1000}\sOfflineSamTool\.h.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2436 |
| 179 | * -omeshcmd.exe -imodule1.js* | .{0,1000}\s\-omeshcmd\.exe\s\-imodule1\.js.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshAgent | 1 | 0 | N/A | N/A | 10 | 3 | 264 | 96 | 2025-03-19T18:43:56Z | 2017-10-12T21:26:52Z | 2439 |
| 180 | * on http://localhost:7777* | .{0,1000}\son\shttp\:\/\/localhost\:7777.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 0 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 2444 |
| 181 | * oshi.at * | .{0,1000}\soshi\.at\s.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 0 | #filehostingservice | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 2462 |
| 182 | * pacman -S wireguard-tools* | .{0,1000}\spacman\s\-S\swireguard\-tools.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 0 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 2502 |
| 183 | * PAExec service* | .{0,1000}\sPAExec\sservice.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 0 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 2504 |
| 184 | * pagekite.logging* | .{0,1000}\spagekite\.logging.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 2505 |
| 185 | * pagekite.py* | .{0,1000}\spagekite\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 2506 |
| 186 | * pagekite-gtk.py* | .{0,1000}\spagekite\-gtk\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 2507 |
| 187 | * PCMonitorManager.exe* | .{0,1000}\sPCMonitorManager\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2573 |
| 188 | * PCMonitorSrv.exe* | .{0,1000}\sPCMonitorSrv\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2574 |
| 189 | * pcmontask.exe* | .{0,1000}\spcmontask\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2575 |
| 190 | * -perm -4000 -o -perm -2000* | .{0,1000}\s\-perm\s\-4000\s\-o\s\-perm\s\-2000.{0,1000} | greyware_tool_keyword | find | Look for files with the SGID (Set Group ID) bit set | T1083 - T1069 - T1202 | TA0004 - TA0007 | N/A | N/A | Discovery | N/A | 1 | 0 | #linux | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 2584 |
| 191 | * pgrok.exe* | .{0,1000}\spgrok\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 0 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 2599 |
| 192 | * pgrokd.exe* | .{0,1000}\spgrokd\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 0 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 2600 |
| 193 | * Portr inspector running on * | .{0,1000}\sPortr\sinspector\srunning\son\s.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 0 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 2637 |
| 194 | * portr.exe* | .{0,1000}\sportr\.exe.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 0 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 2638 |
| 195 | * privoxy.exe* | .{0,1000}\sprivoxy\.exe.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 0 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 2675 |
| 196 | * process call create *cmd.exe /c powershell.exe -nop -w hidden -c *IEX ((new-object net.webclient).downloadstring('https://* | .{0,1000}\sprocess\scall\screate\s.{0,1000}cmd\.exe\s\/c\spowershell\.exe\s\-nop\s\-w\shidden\s\-c\s.{0,1000}IEX\s\(\(new\-object\snet\.webclient\)\.downloadstring\(\'https\:\/\/.{0,1000} | greyware_tool_keyword | wmic | Threat Actors ran the following command to download and execute a PowerShell payload | T1059.001 - T1059.003 - T1569.002 - T1021.006 | TA0002 - TA0005 | N/A | MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - Dispossessor | Collection | https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2676 |
| 197 | * ps2exe.ps1* | .{0,1000}\sps2exe\.ps1.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 0 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 2688 |
| 198 | * pulseway_x64.deb* | .{0,1000}\spulseway_x64\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2702 |
| 199 | * Pulseway_x64.msi* | .{0,1000}\sPulseway_x64\.msi.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2703 |
| 200 | * pulseway_x86.deb* | .{0,1000}\spulseway_x86\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2704 |
| 201 | * pwn_tclsh.me* | .{0,1000}\spwn_tclsh\.me.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 2732 |
| 202 | * py2exe* | .{0,1000}\spy2exe.{0,1000} | greyware_tool_keyword | py2exe | py2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attacker | T1027.002 - T1045 - T1059.001 - T1587.001 | TA0005 - TA0042 | Operation Wocao | N/A | Resource Development | https://github.com/py2exe/py2exe | 1 | 0 | N/A | greyware_tools high risks of false positives | N/A | 10 | 927 | 102 | 2024-11-12T19:44:34Z | 2019-03-11T13:16:35Z | 2734 |
| 203 | * py39-sshuttle* | .{0,1000}\spy39\-sshuttle.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 0 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 2735 |
| 204 | * -r rclone:* init* | .{0,1000}\s\-r\srclone\:.{0,1000}\sinit.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 0 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 2757 |
| 205 | * rathole.exe | .{0,1000}\srathole\.exe | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 0 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 2772 |
| 206 | * RDPWInst.exe* | .{0,1000}\sRDPWInst\.exe.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 0 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 2794 |
| 207 | * rdpwrap.dll* | .{0,1000}\srdpwrap\.dll.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 0 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 2795 |
| 208 | * RemCom.exe* | .{0,1000}\sRemCom\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 2825 |
| 209 | * RemComSvc.exe* | .{0,1000}\sRemComSvc\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 2826 |
| 210 | * RemComSvc.h* | .{0,1000}\sRemComSvc\.h.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 2827 |
| 211 | * RemoteDesktop.exe* | .{0,1000}\sRemoteDesktop\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2833 |
| 212 | * remoteit.exe* | .{0,1000}\sremoteit\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 2838 |
| 213 | * remoteit.x86-win.exe* | .{0,1000}\sremoteit\.x86\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 2839 |
| 214 | * remoteit-desktop.exe* | .{0,1000}\sremoteit\-desktop\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 2840 |
| 215 | * RemotePC.exe* | .{0,1000}\sRemotePC\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2844 |
| 216 | * RemotePCAttendedService * | .{0,1000}\sRemotePCAttendedService\s.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2845 |
| 217 | * remotepclauncher.exe* | .{0,1000}\sremotepclauncher\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2846 |
| 218 | * remotepcuiu.exe* | .{0,1000}\sremotepcuiu\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2847 |
| 219 | * RemotePCViewer.msi* | .{0,1000}\sRemotePCViewer\.msi.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2848 |
| 220 | * restic.exe* | .{0,1000}\srestic\.exe.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 0 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 2870 |
| 221 | * restic/restic * | .{0,1000}\srestic\/restic\s.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 0 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 2871 |
| 222 | * rmm-installer.ps1* | .{0,1000}\srmm\-installer\.ps1.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 0 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 2911 |
| 223 | * rpcdownloader.exe* | .{0,1000}\srpcdownloader\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2923 |
| 224 | * rpcperfviewer.exe* | .{0,1000}\srpcperfviewer\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2927 |
| 225 | * RPCWinXP.exe* | .{0,1000}\sRPCWinXP\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2928 |
| 226 | * -rr_flag * -group * -fileTransferGateways *.zohoassist.com -ADMINAGENT* | .{0,1000}\s\-rr_flag\s.{0,1000}\s\-group\s.{0,1000}\s\-fileTransferGateways\s.{0,1000}\.zohoassist\.com\s\-ADMINAGENT.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2929 |
| 227 | * rsocks.pool* | .{0,1000}\srsocks\.pool.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | N/A | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 2931 |
| 228 | * rsocks.server* | .{0,1000}\srsocks\.server.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | N/A | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 2932 |
| 229 | * rsync.stunnel.org::stunnel * | .{0,1000}\srsync\.stunnel\.org\:\:stunnel\s.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 0 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 2933 |
| 230 | * rtun-server-windows-amd64.exe* | .{0,1000}\srtun\-server\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 0 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 2939 |
| 231 | * rtun-windows-amd64.exe* | .{0,1000}\srtun\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 0 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 2940 |
| 232 | * RustDesk.exe* | .{0,1000}\sRustDesk\.exe.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 0 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 2953 |
| 233 | * -s rest_server_zrok -t* | .{0,1000}\s\-s\srest_server_zrok\s\-t.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 2966 |
| 234 | * s3://sshx/* | .{0,1000}\ss3\:\/\/sshx\/.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 0 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 2968 |
| 235 | * -sc getacls -sddlfilter * | .{0,1000}\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2984 |
| 236 | * -sc trustdump* | .{0,1000}\s\-sc\strustdump.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2987 |
| 237 | * --scanner aclcheck* | .{0,1000}\s\-\-scanner\saclcheck.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 2993 |
| 238 | * --scanner laps_bitlocker* | .{0,1000}\s\-\-scanner\slaps_bitlocker.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 2994 |
| 239 | * --scanner nullsession-trust* | .{0,1000}\s\-\-scanner\snullsession\-trust.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 2995 |
| 240 | * --scanner smb3querynetwork* | .{0,1000}\s\-\-scanner\ssmb3querynetwork.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 2996 |
| 241 | * --scanner zerologon* | .{0,1000}\s\-\-scanner\szerologon.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 2997 |
| 242 | * --script smb-vuln-ms08-067,smb-vuln-ms17-010* | .{0,1000}\s\-\-script\ssmb\-vuln\-ms08\-067,smb\-vuln\-ms17\-010.{0,1000} | greyware_tool_keyword | nmap | nmap vuln scan of most used vulnerabilities | T1046 - T1203 - T1210 | TA0007 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3011 |
| 243 | * SELECT ProcessId FROM Win32_Process * Name='ZAAudioClient.exe'* | .{0,1000}\sSELECT\sProcessId\sFROM\sWin32_Process\s.{0,1000}\sName\=\'ZAAudioClient\.exe\'.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3035 |
| 244 | * -service TightVNC Server* | .{0,1000}\s\-service\sTightVNC\sServer.{0,1000} | greyware_tool_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3049 |
| 245 | * -ServiceName "AADInternals"* | .{0,1000}\s\-ServiceName\s\"AADInternals\".{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 0 | #servicename | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 3050 |
| 246 | * set xmrig Type SERVICE_WIN32_OWN_PROCESS* | .{0,1000}\sset\sxmrig\sType\sSERVICE_WIN32_OWN_PROCESS.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708 | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 3057 |
| 247 | * set-proxy.ps1* | .{0,1000}\sset\-proxy\.ps1.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 0 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 3064 |
| 248 | * shadowsocks-divert* | .{0,1000}\sshadowsocks\-divert.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 3073 |
| 249 | * shadowsocks-rust.sslocal-daemon* | .{0,1000}\sshadowsocks\-rust\.sslocal\-daemon.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 3074 |
| 250 | * shadowsocks-tproxy-mark* | .{0,1000}\sshadowsocks\-tproxy\-mark.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 3075 |
| 251 | * sharedfolder add * -hostpath c:\ -automount* | .{0,1000}\ssharedfolder\sadd\s.{0,1000}\s\-hostpath\sc\:\\\s\-automount.{0,1000} | greyware_tool_keyword | VirtualBox | adding the entire C drive as a shared folder for a VM | T1021.001 - T1137 - T1072 | TA0006 - TA0008 - TA0005 | N/A | RagnarLocker | Persistence | https://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3076 |
| 252 | * sirtunnel.py* | .{0,1000}\ssirtunnel\.py.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 3151 |
| 253 | * sish -c date* | .{0,1000}\ssish\s\-c\sdate.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 0 | N/A | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 3152 |
| 254 | * --socks5-hostname 127.0.0.1:9050* | .{0,1000}\s\-\-socks5\-hostname\s127\.0\.0\.1\:9050.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 0 | #filehostingservice | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 3292 |
| 255 | * SoftEtherVPN-*.tar.xz* | .{0,1000}\sSoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 0 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 3297 |
| 256 | * ssh -R* remote.moe* | .{0,1000}\sssh\s\-R.{0,1000}\sremote\.moe.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 0 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 3354 |
| 257 | * sshtunnel.py* | .{0,1000}\ssshtunnel\.py.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 3362 |
| 258 | * SSHTunnelForwarder(* | .{0,1000}\sSSHTunnelForwarder\(.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 0 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 3363 |
| 259 | * sshuttle:sshuttle * | .{0,1000}\ssshuttle\:sshuttle\s.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 0 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 3364 |
| 260 | * start rustdesk://* | .{0,1000}\sstart\srustdesk\:\/\/.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 0 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 3390 |
| 261 | * start SupremoService* | .{0,1000}\sstart\sSupremoService.{0,1000} | greyware_tool_keyword | Supremo | Supremo - Remote access software | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta | RMM | https://www.supremocontrol.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3391 |
| 262 | * start uvnc_service* | .{0,1000}\sstart\suvnc_service.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3392 |
| 263 | * Starting tunneling server* | .{0,1000}\sStarting\stunneling\sserver.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 0 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 3399 |
| 264 | * stop ProxifierDrv* | .{0,1000}\sstop\sProxifierDrv.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 0 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 3413 |
| 265 | * stop uvnc_service* | .{0,1000}\sstop\suvnc_service.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3414 |
| 266 | * Supremo.exe* | .{0,1000}\sSupremo\.exe.{0,1000} | greyware_tool_keyword | Supremo | Supremo - Remote access software | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta | RMM | https://www.supremocontrol.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3432 |
| 267 | * tacticalrmm.exe* | .{0,1000}\stacticalrmm\.exe.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 0 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 3459 |
| 268 | * tailscale.exe* | .{0,1000}\stailscale\.exe.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 0 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 3460 |
| 269 | * tailscale-archive-keyring* | .{0,1000}\stailscale\-archive\-keyring.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 0 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 3461 |
| 270 | * termbin.com 9999* | .{0,1000}\stermbin\.com\s9999.{0,1000} | greyware_tool_keyword | termbin.com | sending data to a pastebin | T1567.002 | TA0010 | N/A | N/A | Data Exfiltration | termbin.com | 1 | 0 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 3501 |
| 271 | * the servers Wireguard interface.* | .{0,1000}\sthe\sservers\sWireguard\sinterface\..{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3512 |
| 272 | * tkc_agent_dre.deb* | .{0,1000}\stkc_agent_dre\.deb.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3523 |
| 273 | * --to bore.pub* | .{0,1000}\s\-\-to\sbore\.pub.{0,1000} | greyware_tool_keyword | bore | bore is a simple CLI tool for making tunnels to localhost | T1090 - T1090.003 - T1572 - T1572.001 | TA0042 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/ekzhang/bore | 1 | 0 | N/A | N/A | 10 | 10 | 9634 | 410 | 2025-04-14T21:52:18Z | 2022-04-04T02:47:54Z | 3529 |
| 274 | * tunneld.service* | .{0,1000}\stunneld\.service.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 0 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 3570 |
| 275 | * tunnelmole.bundle.js* | .{0,1000}\stunnelmole\.bundle\.js.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 3571 |
| 276 | * tunwg.exe* | .{0,1000}\stunwg\.exe.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 0 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 3574 |
| 277 | * ultravnc.ini * | .{0,1000}\sultravnc\.ini\s.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3610 |
| 278 | * upload*.systemmonitor.eu.com*/command/agentprocessor* | .{0,1000}\supload.{0,1000}\.systemmonitor\.eu\.com.{0,1000}\/command\/agentprocessor.{0,1000} | greyware_tool_keyword | Nsight RMM | Nsight RMM usage | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Scattered Spider* | RMM | https://www.n-able.com/products/n-sight-rmm | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3626 |
| 279 | * vnc.ini * | .{0,1000}\svnc\.ini\s.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3673 |
| 280 | * VSAX_x64.msi* | .{0,1000}\sVSAX_x64\.msi.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3679 |
| 281 | * -W Hidden -command *https://*Invoke-WebRequest*; iex $* | .{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}https\:\/\/.{0,1000}Invoke\-WebRequest.{0,1000}\;\siex\s\$.{0,1000} | greyware_tool_keyword | powershell | A PowerShell process downloaded and launched a remote file | T1059.001 - T1105 - T1203 | TA0001 - TA0002 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 3685 |
| 282 | * -W Hidden -command *Invoke-WebRequest*https://*; iex $* | .{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}Invoke\-WebRequest.{0,1000}https\:\/\/.{0,1000}\;\siex\s\$.{0,1000} | greyware_tool_keyword | powershell | A PowerShell process downloaded and launched a remote file | T1059.001 - T1105 - T1203 | TA0001 - TA0002 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 3686 |
| 283 | * -w hidden -ep bypass -nop -Command "iex ((New-Object System.Net.WebClient).DownloadString(* | .{0,1000}\s\-w\shidden\s\-ep\sbypass\s\-nop\s\-Command\s\"iex\s\(\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(.{0,1000} | greyware_tool_keyword | powershell | suspicious powershell command often used in recaptcha phishing campaign (run dialog) | T1086 - T1105 - T1218.003 - T1569.002 | TA0002 - TA0009 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3687 |
| 284 | * We have found at least * potential SUID exploitable file(s)* | .{0,1000}\sWe\shave\sfound\sat\sleast\s.{0,1000}\spotential\sSUID\sexploitable\sfile\(s\).{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 3696 |
| 285 | * --webview-exe-name=QuickAssist.exe* | .{0,1000}\s\-\-webview\-exe\-name\=QuickAssist\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 0 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 3700 |
| 286 | * where /r C:\Windows\WinSxS\ *Microsoft.ActiveDirectory.Management.dll* | .{0,1000}\swhere\s\/r\sC\:\\Windows\\WinSxS\\\s.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000} | greyware_tool_keyword | where | threat actors searched for Active Directory related DLLs in directories | T1059 - T1083 - T1018 | TA0002 - TA0009 - TA0040 | N/A | N/A | Discovery | https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 3704 |
| 287 | * wireguard-installer.exe* | .{0,1000}\swireguard\-installer\.exe.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 0 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 3736 |
| 288 | * wireproxy.service* | .{0,1000}\swireproxy\.service.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 0 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 3737 |
| 289 | * wiretap.exe* | .{0,1000}\swiretap\.exe.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 0 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 3738 |
| 290 | * xmrig.exe* | .{0,1000}\s\sxmrig\.exe.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 0 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 3781 |
| 291 | * ZA_Connect.exe* | .{0,1000}\sZA_Connect\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3788 |
| 292 | * ZAAudioClient.exe* | .{0,1000}\sZAAudioClient\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3789 |
| 293 | * ZAFileTransfer.exe* | .{0,1000}\sZAFileTransfer\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3790 |
| 294 | * ZAService.exe* | .{0,1000}\sZAService\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3791 |
| 295 | * zrok.listener* | .{0,1000}\szrok\.listener.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 3792 |
| 296 | *"%~dp0RDPWInst" -i -o* | .{0,1000}\"\%\~dp0RDPWInst\"\s\-i\s\-o.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 0 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 3813 |
| 297 | *"[IO.File]::WriteAllBytes($*,[Convert]::FromBase64String("* | .{0,1000}\"\[IO\.File\]\:\:WriteAllBytes\(\$.{0,1000},\[Convert\]\:\:FromBase64String\(\".{0,1000} | greyware_tool_keyword | powershell | suspicious behavior powershell script | T1059.001 - T1105 - T1204.002 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https[://]87[.]120[.]120[.]56/crypt/xx.ps1 | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 3814 |
| 298 | *"appName":"eHorus Agent"* | .{0,1000}\"appName\"\:\"eHorus\sAgent\".{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3820 |
| 299 | *"-----BEGIN OpenVPN Static key* | .{0,1000}\"\-\-\-\-\-BEGIN\sOpenVPN\sStatic\skey.{0,1000} | greyware_tool_keyword | OPENVPN | OpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate data | T1071 - T1573 - T1133 | TA0003 - TA0008 - TA0011 | N/A | N/A | Defense Evasion | https://openvpn.net/ | 1 | 0 | #content #VPN | N/A | 6 | 8 | N/A | N/A | N/A | N/A | 3822 |
| 300 | *"C:\Windows\system32\ARP.EXE" /a* | .{0,1000}\"C\:\\Windows\\system32\\ARP\.EXE\"\s\/a.{0,1000} | greyware_tool_keyword | arp | Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache | T1018 | TA0007 | N/A | Turla - APT32 - Orangeworm | Discovery | N/A | 1 | 0 | N/A | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 3825 |
| 301 | *"gost installation completed!"* | .{0,1000}\"gost\sinstallation\scompleted!\".{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 0 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 3840 |
| 302 | *"http://mitm"* | .{0,1000}\"http\:\/\/mitm\".{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 0 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 3845 |
| 303 | *"message":"ably connection state: CONNECTED"}* | .{0,1000}\"message\"\:\"ably\sconnection\sstate\:\sCONNECTED\"\}.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3853 |
| 304 | *"PageKite system service"* | .{0,1000}\"PageKite\ssystem\sservice\".{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 3858 |
| 305 | *"publisher":"uvnc bvba* | .{0,1000}\"publisher\"\:\"uvnc\sbvba.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | #registry | registry value | 10 | 10 | N/A | N/A | N/A | N/A | 3860 |
| 306 | *"RemotePCAttendedService"* | .{0,1000}\"RemotePCAttendedService\".{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3863 |
| 307 | *"SimpleHelp Remote Printer"* | .{0,1000}\"SimpleHelp\sRemote\sPrinter\".{0,1000} | greyware_tool_keyword | SimpleHelp | SimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackCat | RMM | simple-help.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3870 |
| 308 | *"User-Agent", "tunnelto-client"* | .{0,1000}\"User\-Agent\",\s\"tunnelto\-client\".{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 0 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 3880 |
| 309 | *# adiskreader * | .{0,1000}\#\sadiskreader\s.{0,1000} | greyware_tool_keyword | adiskreader | Async Python library to parse local and remote disk images | T1020 - T1048 - T1074 - T1560.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://github.com/skelsec/adiskreader | 1 | 0 | N/A | N/A | 4 | 1 | 76 | 7 | 2025-03-15T19:48:39Z | 2023-12-18T11:54:31Z | 3885 |
| 310 | *$(mega-whoami)* | .{0,1000}\$\(mega\-whoami\).{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 3935 |
| 311 | *$base64adrecon* | .{0,1000}\$base64adrecon.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | #content | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 3945 |
| 312 | *$EHORUS_HOME/.vnc/passwd* | .{0,1000}\$EHORUS_HOME\/\.vnc\/passwd.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3959 |
| 313 | *$env:LEVEL_API_KEY = "*";* | .{0,1000}\$env\:LEVEL_API_KEY\s\=\s\".{0,1000}\"\;.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3963 |
| 314 | *$HOME/.zrok* | .{0,1000}\$HOME\/\.zrok.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 3985 |
| 315 | *$MEGACMDSHELL* | .{0,1000}\$MEGACMDSHELL.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 3998 |
| 316 | *$outputPath = "C:\AnyDesk.exe"* | .{0,1000}\$outputPath\s\=\s\"C\:\\AnyDesk\.exe\".{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps1 | 1 | 0 | N/A | simple backdoor with anydesk | 10 | 1 | 1 | 0 | 2025-04-17T19:04:37Z | 2023-12-05T22:08:51Z | 4004 |
| 317 | *$tempFile = Join-Path ([System.IO.Path]::GetTempPath()) "install_windows.exe";* | .{0,1000}\$tempFile\s\=\sJoin\-Path\s\(\[System\.IO\.Path\]\:\:GetTempPath\(\)\)\s\"install_windows\.exe\"\;.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4021 |
| 318 | *%~dp0RDPWInst.exe* | .{0,1000}\%\~dp0RDPWInst\.exe.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 0 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 4028 |
| 319 | *%COMSPEC%*echo*\pipe\* | .{0,1000}\%COMSPEC\%.{0,1000}echo.{0,1000}\\pipe\\.{0,1000} | greyware_tool_keyword | echo | Detects the use of getsystem Meterpreter/Cobalt Strike command. Getsystem is used to elevate privilege to SYSTEM account. | T1068.003 - T1078.002 | TA0004 - TA0008 | N/A | N/A | Exploitation tool | https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_meterpreter_or_cobaltstrike_getsystem_service_start.yml | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | 10 | 9115 | 2316 | 2025-04-17T19:43:35Z | 2016-12-24T09:48:49Z | 4036 |
| 320 | *%LOCALAPPDATA%\MEGAcmd* | .{0,1000}\%LOCALAPPDATA\%\\MEGAcmd.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 4038 |
| 321 | *%SystemRoot%\\MEMORY.DMP* | .{0,1000}\%SystemRoot\%\\\\MEMORY\.DMP.{0,1000} | greyware_tool_keyword | CIMplant | C# port of WMImplant which uses either CIM or WMI to query remote systems | T1047 - T1059.001 - T1021.006 | TA0002 - TA0007 - TA0008 | N/A | Scattered Spider* | Lateral Movement | https://github.com/RedSiege/CIMplant | 1 | 0 | N/A | N/A | 10 | 2 | 199 | 29 | 2021-07-14T18:18:42Z | 2021-01-29T21:41:58Z | 4041 |
| 322 | *%SYSTEMROOT%\PAExec-* | .{0,1000}\%SYSTEMROOT\%\\PAExec\-.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 0 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 4042 |
| 323 | *%tooRmetsyS%* | .{0,1000}\%tooRmetsyS\%.{0,1000} | greyware_tool_keyword | _ | reversed string for obfuscation | T1027 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4044 |
| 324 | *%USERPROFILE%\\nssm.zip* | .{0,1000}\%USERPROFILE\%\\\\nssm\.zip.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 0 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 4046 |
| 325 | *&& telnet * 2>&1 </dev/console* | .{0,1000}\&\&\stelnet\s.{0,1000}\s2\>\&1\s\<\/dev\/console.{0,1000} | greyware_tool_keyword | telnet | suspicious shell commands used in various Equation Group scripts and tools | T1105 - T1021.001 - T1021.002 | TA0002 - TA0008 | N/A | N/A | C2 | https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_apt_equationgroup_lnx.yml | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | 10 | 9115 | 2316 | 2025-04-17T19:43:35Z | 2016-12-24T09:48:49Z | 4048 |
| 326 | *&browser=tor&api=false* | .{0,1000}\&browser\=tor\&api\=false.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 4049 |
| 327 | *(&(&(objectCategory=person)(objectClass=user))(|(description=*pass*)(comment=*pass*)))* | .{0,1000}\(\&\(\&\(objectCategory\=person\)\(objectClass\=user\)\)\(\|\(description\=.{0,1000}pass.{0,1000}\)\(comment\=.{0,1000}pass.{0,1000}\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | metasploit enum_ad_user_comments | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/824726 | 1 | 0 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 4053 |
| 328 | *(&(objectCategory=computer)(msDS-isRODC=TRUE))* | .{0,1000}\(\&\(objectCategory\=computer\)\(msDS\-isRODC\=TRUE\)\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Read-Only Domain Controllers (RODC) | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4057 |
| 329 | *(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=" + target + "))* | .{0,1000}\(\&\(objectCategory\=computer\)\(ms\-MCS\-AdmPwd\=.{0,1000}\)\(sAMAccountName\=\"\s\+\starget\s\+\s\"\)\).{0,1000} | greyware_tool_keyword | ldap queries | LAPS passwords (from SharpLAPS) | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4058 |
| 330 | *(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)(memberOf=CN=Administrators* | .{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\)\(memberOf\=CN\=Administrators.{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Accounts with Non-Expiring Passwords and Administrative Privileges | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4059 |
| 331 | *(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)* | .{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all users with the account configuration 'Password never expires' | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4060 |
| 332 | *(&(objectClass=group)(managedBy=*)(groupType:1.2.840.113556.1.4.803:=2147483648))* | .{0,1000}\(\&\(objectClass\=group\)\(managedBy\=.{0,1000}\)\(groupType\:1\.2\.840\.113556\.1\.4\.803\:\=2147483648\)\).{0,1000} | greyware_tool_keyword | ldap queries | metasploit enum_ad_managedby_groups.rb | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/rapid7/metasploit-framework/blob/d37a82500d1d08f9d8ab3da9b194653835748fae/modules/post/windows/gather/enum_ad_managedby_groups.rb#L59 | 1 | 0 | N/A | N/A | 8 | 10 | 35400 | 14272 | 2025-04-22T20:14:59Z | 2011-08-30T06:13:20Z | 4061 |
| 333 | *(&(objectclass=group)(samaccountname=*domain admins*))* | .{0,1000}\(\&\(objectclass\=group\)\(samaccountname\=.{0,1000}domain\sadmins.{0,1000}\)\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Domain Administrators Group | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4062 |
| 334 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4063 |
| 335 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4064 |
| 336 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4065 |
| 337 | *([adsisearcher]'(&(objectCategory=computer)(!(primaryGroupID=516)(userAccountControl:1.2.840.113556.1.4.803:=524288)))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(!\(primaryGroupID\=516\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\)\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all servers configured for Unconstrained Delegation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 4067 |
| 338 | *([adsisearcher]'(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all Domain Controllers | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/ | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 4068 |
| 339 | *([adsisearcher]'(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=user\)\(!\(samAccountName\=krbtgt\)\(servicePrincipalName\=.{0,1000}\)\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Search for user accounts with SPN but not TGT accounts | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4069 |
| 340 | *([adsisearcher]'(adminCount=1)').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(adminCount\=1\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Search for all objects with AdminSHHolder | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4070 |
| 341 | *([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Domains* | .{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Domains.{0,1000} | greyware_tool_keyword | ldap queries | Queries for domain level and mode information | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4071 |
| 342 | *([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Sites | * | .{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Sites\s\|\s.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of AD Forest Sites | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4072 |
| 343 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).FindAllDomainControllers() | Select-Object -Property * | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.FindAllDomainControllers\(\)\s\|\sSelect\-Object\s\-Property\s.{0,1000} | greyware_tool_keyword | ldap queries | querying all domain controllers with detailed properties | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4073 |
| 344 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()* | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000} | greyware_tool_keyword | ldap queries | get all trust relationships in the current domain | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4074 |
| 345 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()* | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000} | greyware_tool_keyword | powershell | Powershell enumerate domains and forests | T1482 - T1069.002 | TA0007 - TA0008 | N/A | Black Basta | Discovery | https://medium.com/@simone.kraus/black-basta-playbook-chat-leak-d5036936166d | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4075 |
| 346 | *(Get-ADForest).Domains | %{ Get-ADDomainController -Filter * -Server $_ }* | .{0,1000}\(Get\-ADForest\)\.Domains\s\|\s\%\{\sGet\-ADDomainController\s\-Filter\s.{0,1000}\s\-Server\s\$_\s\}.{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all of the domain controllers for all domains in a forest | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 6 | 6 | N/A | N/A | N/A | N/A | 4077 |
| 347 | *(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))* | .{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | used by Rubeus and S4UTomato tools | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4081 |
| 348 | *(objectCategory=person)(objectClass=user)(serviceAccount=TRUE)* | .{0,1000}\(objectCategory\=person\)\(objectClass\=user\)\(serviceAccount\=TRUE\).{0,1000} | greyware_tool_keyword | ldap queries | Query to find service accounts which are typically high-privileged and targeted for privilege escalation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4085 |
| 349 | *(objectclass=group)(samaccountname=domain admins)* | .{0,1000}\(objectclass\=group\)\(samaccountname\=domain\sadmins\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Domain Admins | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4086 |
| 350 | *(userAccountControl:1.2.840.113556.1.4.803:=524288)* | .{0,1000}\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\).{0,1000} | greyware_tool_keyword | ldap queries | Accounts Trusted for Delegation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4091 |
| 351 | *...::$index_allocation* | .{0,1000}\.\.\.\:\:\$index_allocation.{0,1000} | greyware_tool_keyword | $index_allocation | creation of hidden folders (and file) via ...$.......::$index_allocation | T1027.001 - T1564.001 | TA0005 | N/A | N/A | Defense Evasion | https://soroush.me/blog/2010/12/a-dotty-salty-directory-a-secret-place-in-ntfs-for-secret-files/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4096 |
| 352 | *../tunnelto_lib* | .{0,1000}\.\.\/tunnelto_lib.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 0 | #linux | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 4099 |
| 353 | *..\..\..\..\..\..\Windows\System32\cmd.exe* | .{0,1000}\.\.\\\.\.\\\.\.\\\.\.\\\.\.\\\.\.\\Windows\\System32\\cmd\.exe.{0,1000} | greyware_tool_keyword | _ | attempt to bypass security controls or execute commands from an unexpected location | T1036 - T1059 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://twitter.com/malwrhunterteam/status/1737220172220620854/photo/1 | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 4101 |
| 354 | *./boringproxy server* | .{0,1000}\.\/boringproxy\sserver.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | #linux | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 4109 |
| 355 | *./capsh --gid=0 --uid=0 --* | .{0,1000}\.\/capsh\s\-\-gid\=0\s\-\-uid\=0\s\-\-.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4112 |
| 356 | *./chisel client * | .{0,1000}\.\/chisel\sclient\s.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 0 | #linux | chisel | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 4114 |
| 357 | *./chroot / /bin/sh -p* | .{0,1000}\.\/chroot\s\/\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4115 |
| 358 | *./dropbear * | .{0,1000}\.\/dropbear\s.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 4128 |
| 359 | *./env /bin/sh -p* | .{0,1000}\.\/env\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4131 |
| 360 | *./expect -c 'spawn /bin/sh -p;interact'* | .{0,1000}\.\/expect\s\-c\s\'spawn\s\/bin\/sh\s\-p\;interact\'.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4134 |
| 361 | *./flock -u / /bin/sh -p* | .{0,1000}\.\/flock\s\-u\s\/\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4139 |
| 362 | *./nice /bin/sh -p* | .{0,1000}\.\/nice\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4171 |
| 363 | *./nmap* | .{0,1000}\.\/nmap.{0,1000} | greyware_tool_keyword | nmap | A very common tool. Network host vuln and port detector. | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap | 1 | 1 | #linux | greyware tool - risks of False positive ! | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 4173 |
| 364 | *./rview -c ':py3 import os*os.execl(\"/bin/sh\* | .{0,1000}\.\/rview\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4195 |
| 365 | *./staqlab-tunnel * | .{0,1000}\.\/staqlab\-tunnel\s.{0,1000} | greyware_tool_keyword | staqlab-tunnel | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/cocoflan/Staqlab-tunnel | 1 | 0 | #linux | N/A | 10 | 10 | 1 | 0 | 2020-05-19T06:43:14Z | 2020-05-19T06:19:31Z | 4211 |
| 366 | *./test/nmap*/*.nse* | .{0,1000}\.\/test\/nmap.{0,1000}\/.{0,1000}\.nse.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 0 | #linux | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 4216 |
| 367 | *./tunwg --* | .{0,1000}\.\/tunwg\s\-\-.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 0 | #linux | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 4217 |
| 368 | *./wiretap remove* | .{0,1000}\.\/wiretap\sremove.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 0 | #linux | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 4221 |
| 369 | *.\RemComSvc\* | .{0,1000}\.\\RemComSvc\\.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 4229 |
| 370 | *.\TightVNC1* | .{0,1000}\.\\TightVNC1.{0,1000} | greyware_tool_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 4231 |
| 371 | *.\TightVNC2* | .{0,1000}\.\\TightVNC2.{0,1000} | greyware_tool_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 4232 |
| 372 | *.\TightVNC3* | .{0,1000}\.\\TightVNC3.{0,1000} | greyware_tool_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 4233 |
| 373 | *._tcp.argotunnel.com* | .{0,1000}\._tcp\.argotunnel\.com.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 4234 |
| 374 | *.a.pinggy.online* | .{0,1000}\.a\.pinggy\.online.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4237 |
| 375 | *.api.mega.co.nz* | .{0,1000}\.api\.mega\.co\.nz.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4242 |
| 376 | *.api.splashtop.com* | .{0,1000}\.api\.splashtop\.com.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c72 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4243 |
| 377 | *.apitest.barracudamsp.com* | .{0,1000}\.apitest\.barracudamsp\.com.{0,1000} | greyware_tool_keyword | BarracudaRMM | Deliver remote support services - formely AVG | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.barracudamsp.com/products/rmm/barracuda-rmm | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4244 |
| 378 | *.asse.devtunnels.ms* | .{0,1000}\.asse\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4249 |
| 379 | *.aweray.net* | .{0,1000}\.aweray\.net.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4252 |
| 380 | *.bash_history >/dev/null 2>&1* | .{0,1000}\.bash_history\s\>\/dev\/null\s2\>\&1.{0,1000} | greyware_tool_keyword | bash | Indicator Removal on Host | T1070.002 - T1562.004 - T1059.004 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4255 |
| 381 | *.beyondtrustcloud.com/session_complete* | .{0,1000}\.beyondtrustcloud\.com\/session_complete.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4258 |
| 382 | *.bin/tmole* | .{0,1000}\.bin\/tmole.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 4265 |
| 383 | *.bin/tunnelmole* | .{0,1000}\.bin\/tunnelmole.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 4266 |
| 384 | *.chrome-remote-desktop-session* | .{0,1000}\.chrome\-remote\-desktop\-session.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4269 |
| 385 | *.comodo.com/static/frontend/static-pages/enroll-wizard/token* | .{0,1000}\.comodo\.com\/static\/frontend\/static\-pages\/enroll\-wizard\/token.{0,1000} | greyware_tool_keyword | ComodoRMM (Itarian RMM) | Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://one.comodo.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4275 |
| 386 | *.config/systemd/user/remotemoe.service* | .{0,1000}\.config\/systemd\/user\/remotemoe\.service.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 0 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 4276 |
| 387 | *.config/telebit/telebitd.yml* | .{0,1000}\.config\/telebit\/telebitd\.yml.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4277 |
| 388 | *.configrclonerclone.conf* | .{0,1000}\.configrclonerclone\.conf.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 4278 |
| 389 | *.console.gotoassist.com* | .{0,1000}\.console\.gotoassist\.com.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4279 |
| 390 | *.d.requestbin.net* | .{0,1000}\.d\.requestbin\.net.{0,1000} | greyware_tool_keyword | requestbin.net | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://requestbin.net | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 4282 |
| 391 | *.dev1.fleetdeck.io* | .{0,1000}\.dev1\.fleetdeck\.io.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 4285 |
| 392 | *.dnslog.cn:* | .{0,1000}\.dnslog\.cn\:.{0,1000} | greyware_tool_keyword | dnslog.cn | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://dnslog.cn | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 4289 |
| 393 | *.exe * /hide * /range:* /auto:*.* | .{0,1000}\.exe\s.{0,1000}\s\/hide\s.{0,1000}\s\/range\:.{0,1000}\s\/auto\:.{0,1000}\..{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4325 |
| 394 | *.exe /hide /range:all* | .{0,1000}\.exe\s\/hide\s\/range\:all.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4334 |
| 395 | *.exe /i /s cmd * | .{0,1000}\.exe\s\/i\s\/s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4336 |
| 396 | *.exe /i /s cmd.exe* | .{0,1000}\.exe\s\/i\s\/s\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4337 |
| 397 | *.exe /i /s powershell* | .{0,1000}\.exe\s\/i\s\/s\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4338 |
| 398 | *.exe /i /s pwsh* | .{0,1000}\.exe\s\/i\s\/s\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4339 |
| 399 | *.exe /s /i cmd.exe* | .{0,1000}\.exe\s\/s\s\/i\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4344 |
| 400 | *.exe /s /i powershell* | .{0,1000}\.exe\s\/s\s\/i\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4345 |
| 401 | *.exe /s /i pwsh* | .{0,1000}\.exe\s\/s\s\/i\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4346 |
| 402 | *.exe /s:ip_ranges.txt /f:scan_results.txt* | .{0,1000}\.exe\s\/s\:ip_ranges\.txt\s\/f\:scan_results\.txt.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 4347 |
| 403 | *.exe /wakeall* | .{0,1000}\.exe\s\/wakeall.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4348 |
| 404 | *.exe delete shadows* | .{0,1000}\.exe\sdelete\sshadows.{0,1000} | greyware_tool_keyword | vssadmin | inhibiting recovery by deleting backup and recovery data to prevent system recovery after an attack | T1490 | TA0040 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4424 |
| 405 | *.exe -gcb -sc trustdmp > * | .{0,1000}\.exe\s\-gcb\s\-sc\strustdmp\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4443 |
| 406 | *.exe host -p * - allow-anonymous* | .{0,1000}\.exe\shost\s\-p\s.{0,1000}\s\-\sallow\-anonymous.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4468 |
| 407 | *.exe -i -s cmd * | .{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4471 |
| 408 | *.exe -i -s cmd * | .{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4472 |
| 409 | *.exe -i -s cmd.exe* | .{0,1000}\.exe\s\-i\s\-s\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4473 |
| 410 | *.exe -i -s powershell* | .{0,1000}\.exe\s\-i\s\-s\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4474 |
| 411 | *.exe -i -s pwsh* | .{0,1000}\.exe\s\-i\s\-s\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4475 |
| 412 | *.exe --IPCport 5939 --Module 1* | .{0,1000}\.exe\s\-\-IPCport\s5939\s\-\-Module\s1.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 0 | N/A | https://github.com/SigmaHQ/sigma/pull/4759 | 10 | 10 | N/A | N/A | N/A | N/A | 4487 |
| 413 | *.exe --pn dre_video_uploader --logpath logs* | .{0,1000}\.exe\s\-\-pn\sdre_video_uploader\s\-\-logpath\slogs.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4570 |
| 414 | *.exe port create -p * | .{0,1000}\.exe\sport\screate\s\-p\s.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4571 |
| 415 | *.exe -s -i cmd.exe* | .{0,1000}\.exe\s\-s\s\-i\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4591 |
| 416 | *.exe -s -i powershell* | .{0,1000}\.exe\s\-s\s\-i\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4592 |
| 417 | *.exe -s -i pwsh* | .{0,1000}\.exe\s\-s\s\-i\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4593 |
| 418 | *.exe -sc adinfo > * | .{0,1000}\.exe\s\-sc\sadinfo\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4598 |
| 419 | *.exe -sc dclist > * | .{0,1000}\.exe\s\-sc\sdclist\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4599 |
| 420 | *.exe -sc getacls -sddlfilter * | .{0,1000}\.exe\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4600 |
| 421 | *.exe -sc trustdmp > * | .{0,1000}\.exe\s\-sc\strustdmp\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4601 |
| 422 | *.exe shadowcopy delete* | .{0,1000}\.exe\sshadowcopy\sdelete.{0,1000} | greyware_tool_keyword | wmic | VSS is a feature in Windows that allows for the creation of snapshots of a volume capturing its state at a specific point in time. Adversaries may abuse the wmic shadowcopy command to interact with these shadow copies for defense evasion purposes. | T1490 - T1562.002 | TA0040 - TA0007 | N/A | MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - Dispossessor | Defense Evasion | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4608 |
| 423 | *.exe -subnets -f (objectCategory=subnet) > * | .{0,1000}\.exe\s\-subnets\s\-f\s\(objectCategory\=subnet\)\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4623 |
| 424 | *.exec*.interact.sh* | .{0,1000}\.exec.{0,1000}\.interact\.sh.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 4660 |
| 425 | *.free.pinggy.online* | .{0,1000}\.free\.pinggy\.online.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4665 |
| 426 | *.gofile.io/uploadFile* | .{0,1000}\.gofile\.io\/uploadFile.{0,1000} | greyware_tool_keyword | gofile.io | legitimate service abused by lots of stealer to exfiltrate data | T1567.002 | TA0010 | N/A | Hive - Royal - LockBit - Vice Society - BlackSuit - Conti | Data Exfiltration | https://gofile.io | 1 | 1 | #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4670 |
| 427 | *.in.zrok.io* | .{0,1000}\.in\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4677 |
| 428 | *.interactsh.com | .{0,1000}\.interactsh\.com | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C7 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 0 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 4678 |
| 429 | *.l.tunwg.com* | .{0,1000}\.l\.tunwg\.com.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 4686 |
| 430 | *.localltunnel.me* | .{0,1000}\.localltunnel\.me.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 4696 |
| 431 | *.loclx.io:* | .{0,1000}\.loclx\.io\:.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 4697 |
| 432 | *.meshagent.pid* | .{0,1000}\.meshagent\.pid.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshAgent | 1 | 0 | N/A | N/A | 10 | 3 | 264 | 96 | 2025-03-19T18:43:56Z | 2017-10-12T21:26:52Z | 4701 |
| 433 | *.mspa.n-able.com* | .{0,1000}\.mspa\.n\-able\.com.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4703 |
| 434 | *.myftp.biz* | .{0,1000}\.myftp\.biz.{0,1000} | greyware_tool_keyword | myftp.biz | dyndns - lots of subdomains associated with malwares - could be used in various ways for both legitimate and malicious activities (malicious mostly) | T1071 - T1021 - T1095 - T1059 | TA0010 - TA0008 - TA0009 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/hagezi/dns-blocklists/blob/9d6562bddc175b59241d5935531f648cd6b6d9c8/rpz/dyndns.txt#L103 | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | 10725 | 340 | 2025-04-22T19:18:32Z | 2022-04-25T07:13:09Z | 4704 |
| 435 | *.myftp.org* | .{0,1000}\.myftp\.org.{0,1000} | greyware_tool_keyword | myftp.org | dyndns - lots of subdomains associated with malwares - myftp.org could be used in various ways for both legitimate and malicious activities (malicious mostly) | T1071 - T1021 - T1095 - T1059 | TA0010 - TA0008 - TA0009 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/pan-unit42/iocs/blob/master/rat_nest/iocs.csv | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 8 | 711 | 152 | 2025-04-05T02:03:37Z | 2015-06-04T13:37:09Z | 4705 |
| 436 | *.ngrok.me* | .{0,1000}\.ngrok\.me.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 4709 |
| 437 | *.ps1 -sysinfo Enum* | .{0,1000}\.ps1\s\-sysinfo\sEnum.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 0 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 4766 |
| 438 | *.py *--proxy socks5://* | .{0,1000}\.py\s.{0,1000}\-\-proxy\ssocks5\:\/\/.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 0 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 4811 |
| 439 | *.rclone.exe config* | .{0,1000}\.rclone\.exe\sconfig.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 4860 |
| 440 | *.realtime.services.box.net* | .{0,1000}\.realtime\.services\.box\.net.{0,1000} | greyware_tool_keyword | Box | Attackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackers | T1567.002 - T1071.001 - T1036 - T1048.002 | TA0005 - TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://app.box.com/ | 1 | 1 | #dnsquery | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 4861 |
| 441 | *.rel.tunnels.api.visualstudio.com* | .{0,1000}\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4862 |
| 442 | *.relay.splashtop.com* | .{0,1000}\.relay\.splashtop\.com.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c72 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4863 |
| 443 | *.remotepc.com* | .{0,1000}\.remotepc\.com.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4864 |
| 444 | *.remotepc.com* | .{0,1000}\.remotepc\.com.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | network | 10 | 10 | N/A | N/A | N/A | N/A | 4865 |
| 445 | *.remoteutilities.com* | .{0,1000}\.remoteutilities\.com.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4866 |
| 446 | *.remoteview.logmein.com* | .{0,1000}\.remoteview\.logmein\.com.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4867 |
| 447 | *.router.teamviewer.com* | .{0,1000}\.router\.teamviewer\.com.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 1 | N/A | FP risk - teamviewer usage | 10 | 10 | N/A | N/A | N/A | N/A | 4871 |
| 448 | *.rsocks.plist* | .{0,1000}\.rsocks\.plist.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | N/A | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 4872 |
| 449 | *.server_DoElevationRequest((Get-NtProcess -ProcessId $pid)*"cmd.exe"*C:\"* | .{0,1000}\.server_DoElevationRequest\(\(Get\-NtProcess\s\-ProcessId\s\$pid\).{0,1000}\"cmd\.exe\".{0,1000}C\:\\\".{0,1000} | greyware_tool_keyword | sudo | sudo on windows allowing privilege escalation | T1068 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html | 1 | 0 | #linux | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 4884 |
| 450 | *.servicedesk.atera.com/GetAgent* | .{0,1000}\.servicedesk\.atera\.com\/GetAgent.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4885 |
| 451 | *.share.zrok.io* | .{0,1000}\.share\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4904 |
| 452 | *.srv.browser.lol* | .{0,1000}\.srv\.browser\.lol.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 4910 |
| 453 | *.static.mega.co.nz* | .{0,1000}\.static\.mega\.co\.nz.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4915 |
| 454 | *.tailscale-keyring.list* | .{0,1000}\.tailscale\-keyring\.list.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 0 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 4920 |
| 455 | *.trycloudfare.com*DavWWWRoot* | .{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4923 |
| 456 | *.tunnel.pyjam.as* | .{0,1000}\.tunnel\.pyjam\.as.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4924 |
| 457 | *.tunnelto.dev* | .{0,1000}\.tunnelto\.dev.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 4929 |
| 458 | *.userstorage.mega.co.nz/ul/* | .{0,1000}\.userstorage\.mega\.co\.nz\/ul\/.{0,1000} | greyware_tool_keyword | mega.co.nz | uploading data to mega cloud | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR - Dispossessor | Data Exfiltration | https://mega.io/ | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4944 |
| 459 | *.v2.argotunnel.com* | .{0,1000}\.v2\.argotunnel\.com.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 4945 |
| 460 | *.vm.sshx.internal:8051* | .{0,1000}\.vm\.sshx\.internal\:8051.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 0 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 4948 |
| 461 | *.vsax.net* | .{0,1000}\.vsax\.net.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4950 |
| 462 | *.xeox.com* | .{0,1000}\.xeox\.com.{0,1000} | greyware_tool_keyword | xeox | Easily access and manage Windows devices remotely within XEOX - RMM abused by threat actors | T1021 - T1078 - T1219 - T1105 - T1046 | TA0011 - TA0010 - TA0003 - TA0005 | N/A | Dispossessor | RMM | https://xeox.com/remote-access/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4956 |
| 463 | *.zohoassist.com.cn* | .{0,1000}\.zohoassist\.com\.cn.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4979 |
| 464 | *.zohoassist.jp* | .{0,1000}\.zohoassist\.jp.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4980 |
| 465 | *.zrok.quigley.com* | .{0,1000}\.zrok\.quigley\.com.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4981 |
| 466 | */*.loclx.io* | .{0,1000}\/.{0,1000}\.loclx\.io.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 4983 |
| 467 | */.anydesk/.anydesk.trace* | .{0,1000}\/\.anydesk\/\.anydesk\.trace.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5004 |
| 468 | */.anydesk/service.conf* | .{0,1000}\/\.anydesk\/service\.conf.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5005 |
| 469 | */.anydesk/system.conf* | .{0,1000}\/\.anydesk\/system\.conf.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5006 |
| 470 | */.anydesk/user.conf* | .{0,1000}\/\.anydesk\/user\.conf.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5007 |
| 471 | */.btunnel.* | .{0,1000}\/\.btunnel\..{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 0 | #linux | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 5008 |
| 472 | */.fleetctl/fleetctl* | .{0,1000}\/\.fleetctl\/fleetctl.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 0 | #linux | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 5015 |
| 473 | */.ltproxy.yml* | .{0,1000}\/\.ltproxy\.yml.{0,1000} | greyware_tool_keyword | LTProxy | Linux Transparent Proxy (Similar to Proxifiter) | T1090 - T1573.001 - T1571 - T1071.001 | TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://github.com/L-codes/LTProxy | 1 | 0 | #linux | N/A | 10 | 1 | 31 | 5 | 2024-11-27T05:09:47Z | 2021-11-11T15:17:54Z | 5022 |
| 474 | */.ssh/dropbear* | .{0,1000}\/\.ssh\/dropbear.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 5038 |
| 475 | */.tmate.conf* | .{0,1000}\/\.tmate\.conf.{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate-ssh-server | 1 | 0 | #linux | N/A | 10 | 10 | 642 | 148 | 2024-06-21T11:52:24Z | 2013-06-09T23:58:55Z | 5040 |
| 476 | */.tunneld/*.key* | .{0,1000}\/\.tunneld\/.{0,1000}\.key.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 0 | #linux | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 5041 |
| 477 | */.zrok/*.json* | .{0,1000}\/\.zrok\/.{0,1000}\.json.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 5043 |
| 478 | */.zrok:/.zrok* | .{0,1000}\/\.zrok\:\/\.zrok.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 5044 |
| 479 | *// NewHTTPClient creates a new zrok HTTP client.* | .{0,1000}\/\/\sNewHTTPClient\screates\sa\snew\szrok\sHTTP\sclient\..{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #content #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 5049 |
| 480 | *// Package tunnel is a server/client package that enables to proxy public* | .{0,1000}\/\/\sPackage\stunnel\sis\sa\sserver\/client\spackage\sthat\senables\sto\sproxy\spublic.{0,1000} | greyware_tool_keyword | tunnel | Tunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outside | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/koding/tunnel | 1 | 0 | #linux #content | N/A | 10 | 10 | 328 | 72 | 2023-10-20T13:43:58Z | 2015-05-28T07:26:42Z | 5050 |
| 481 | */_sish/console* | .{0,1000}\/_sish\/console.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 0 | #linux | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 5065 |
| 482 | */3proxy-*.deb* | .{0,1000}\/3proxy\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5088 |
| 483 | */3proxy-*.rpm* | .{0,1000}\/3proxy\-.{0,1000}\.rpm.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5089 |
| 484 | */3proxy-*.zip* | .{0,1000}\/3proxy\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5090 |
| 485 | */3proxy.exe* | .{0,1000}\/3proxy\.exe.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5091 |
| 486 | */3proxy.git* | .{0,1000}\/3proxy\.git.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5092 |
| 487 | */3proxy.log* | .{0,1000}\/3proxy\.log.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | #logfile #linux | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5093 |
| 488 | */a.pinggy.io* | .{0,1000}\/a\.pinggy\.io.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5100 |
| 489 | */AADInternals.git* | .{0,1000}\/AADInternals\.git.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 5102 |
| 490 | */action1_agent(My_Organization).msi* | .{0,1000}\/action1_agent\(My_Organization\)\.msi.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | product name | 10 | 10 | N/A | N/A | N/A | N/A | 5123 |
| 491 | */AD_Miner.git* | .{0,1000}\/AD_Miner\.git.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5127 |
| 492 | */AD_Miner/releases/* | .{0,1000}\/AD_Miner\/releases\/.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5128 |
| 493 | */adaudit.git* | .{0,1000}\/adaudit\.git.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5138 |
| 494 | */adaudit.ps1* | .{0,1000}\/adaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5140 |
| 495 | */AD-common-queries.git* | .{0,1000}\/AD\-common\-queries\.git.{0,1000} | greyware_tool_keyword | AD-common-queries | Collection of common ADSI queries for Domain Account enumeration | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 1 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 5147 |
| 496 | */AdFind.zip* | .{0,1000}\/AdFind\.zip.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5186 |
| 497 | */ADGet.exe* | .{0,1000}\\ADGet\.exe.{0,1000} | greyware_tool_keyword | adget | gather valuable informations about the AD environment | T1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482 | TA0001 - TA0002 - TA0003 - TA0007 - TA0011 | N/A | N/A | Discovery | https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5198 |
| 498 | */ADRecon* | .{0,1000}\/ADRecon.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commands | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/sense-of-security/ADRecon | 1 | 1 | N/A | N/A | 10 | 10 | 1786 | 292 | 2020-06-15T05:23:14Z | 2017-11-29T23:01:53Z | 5212 |
| 499 | */ADRecon.git* | .{0,1000}\/ADRecon\.git.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 5213 |
| 500 | */ADRecon.ps1* | .{0,1000}\/ADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 5214 |
| 501 | */Advanced_Port_Scanner_*.exe* | .{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 5218 |
| 502 | */aeroadmin.exe* | .{0,1000}\/aeroadmin\.exe.{0,1000} | greyware_tool_keyword | aeroadmin | RMM software - full remote control / file transfer | T1021.001 - T1048.003 | TA0008 - TA0011 - TA0009 - TA0010 | N/A | N/A | RMM | https://ulm.aeroadmin.com/AeroAdmin.exe | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5219 |
| 503 | */Agent/AcknowledgeCommands/* | .{0,1000}\/Agent\/AcknowledgeCommands\/.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5229 |
| 504 | */Agent/GetCommandsFallback/* | .{0,1000}\/Agent\/GetCommandsFallback\/.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5231 |
| 505 | */Agent/GetEnvironmentStatus/* | .{0,1000}\/Agent\/GetEnvironmentStatus\/.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5232 |
| 506 | */Agent/GetRecurringPackages/* | .{0,1000}\/Agent\/GetRecurringPackages\/.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5233 |
| 507 | */Ahk2Exe.exe* | .{0,1000}\/Ahk2Exe\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5255 |
| 508 | */Ahk2Exe.git* | .{0,1000}\/Ahk2Exe\.git.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5256 |
| 509 | */Ahk2Exe.zip* | .{0,1000}\/Ahk2Exe\.zip.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5257 |
| 510 | */Ahk2Exe1.*.zip* | .{0,1000}\/Ahk2Exe1\..{0,1000}\.zip.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5258 |
| 511 | */ahk-install.exe* | .{0,1000}\/ahk\-install\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5259 |
| 512 | */ahk-v2.exe* | .{0,1000}\/ahk\-v2\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5260 |
| 513 | */Alpemix.zip* | .{0,1000}\/Alpemix\.zip.{0,1000} | greyware_tool_keyword | Alpemix | connect to your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.alpemix.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5281 |
| 514 | */amalshaji/portr-admin/* | .{0,1000}\/amalshaji\/portr\-admin\/.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 5282 |
| 515 | */amidaware/rmmagent/releases/download/* | .{0,1000}\/amidaware\/rmmagent\/releases\/download\/.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 5288 |
| 516 | */Amperage.exe* | .{0,1000}\/Amperage\.exe.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5291 |
| 517 | */AmperageKit.git* | .{0,1000}\/AmperageKit\.git.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5292 |
| 518 | */AmperageKit/releases/* | .{0,1000}\/AmperageKit\/releases\/.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5293 |
| 519 | */Anydesk.exe | .{0,1000}\/Anydesk\.exe | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://anydesk.com/ | 1 | 1 | N/A | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5333 |
| 520 | */anyplace-control/data2/*.exe* | .{0,1000}\/anyplace\-control\/data2\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | AnyplaceControl | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyplace-control[.]com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5334 |
| 521 | */anyproxy.log* | .{0,1000}\/anyproxy\.log.{0,1000} | greyware_tool_keyword | CursedChrome | Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victims | T1176 - T1219 - T1090 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/mandatoryprogrammer/CursedChrome | 1 | 0 | #linux | anyproxy | 10 | 10 | 1533 | 226 | 2024-10-26T19:06:54Z | 2020-04-26T20:55:05Z | 5335 |
| 522 | */AnyViewerSetup.exe* | .{0,1000}\/AnyViewerSetup\.exe.{0,1000} | greyware_tool_keyword | anyviewer | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyviewer.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5336 |
| 523 | */apache-megacmd.conf* | .{0,1000}\/apache\-megacmd\.conf.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | #linux | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 5338 |
| 524 | */Apemix.exe* | .{0,1000}\/Apemix\.exe.{0,1000} | greyware_tool_keyword | Alpemix | connect to your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.alpemix.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5342 |
| 525 | */api/latest/fleet/mdm/bootstrap?token=* | .{0,1000}\/api\/latest\/fleet\/mdm\/bootstrap\?token\=.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 5350 |
| 526 | */api/v1/fleet/mdm/sso/callback* | .{0,1000}\/api\/v1\/fleet\/mdm\/sso\/callback.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 5365 |
| 527 | */app/pgrokd/* | .{0,1000}\/app\/pgrokd\/.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 0 | #linux | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 5381 |
| 528 | */AppFiles/ipscan.exe* | .{0,1000}\/AppFiles\/ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 5382 |
| 529 | */Applications/Anydesk.app/* | .{0,1000}\/Applications\/Anydesk\.app\/.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #macos | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5383 |
| 530 | */Applications/Managed Workplace/Onsite Manager/logs/* | .{0,1000}\/Applications\/Managed\sWorkplace\/Onsite\sManager\/logs\/.{0,1000} | greyware_tool_keyword | BarracudaRMM | Deliver remote support services - formely AVG | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.barracudamsp.com/products/rmm/barracuda-rmm | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5384 |
| 531 | */Applications/MEGAcmd.app* | .{0,1000}\/Applications\/MEGAcmd\.app.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | #macos | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 5385 |
| 532 | */Applications/remoteit.app/* | .{0,1000}\/Applications\/remoteit\.app\/.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | #macos | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 5386 |
| 533 | */Assistance rapide Installer.exe* | .{0,1000}\/Assistance\srapide\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 5428 |
| 534 | */Assistenza rapida Installer.exe* | .{0,1000}\/Assistenza\srapida\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 5429 |
| 535 | */atnow.exe* | .{0,1000}\/atnow\.exe.{0,1000} | greyware_tool_keyword | atnow | AtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TA | T1053 - T1059 | TA0002 | N/A | APT18 - APT29 - APT32 - Cobalt - RTM | Persistence | https://www.nirsoft.net/utils/atnow.html | 1 | 1 | N/A | N/A | 7 | 7 | N/A | N/A | N/A | N/A | 5454 |
| 536 | */atnow.zip* | .{0,1000}\/atnow\.zip.{0,1000} | greyware_tool_keyword | atnow | AtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TA | T1053 - T1059 | TA0002 | N/A | APT18 - APT29 - APT32 - Cobalt - RTM | Persistence | https://www.nirsoft.net/utils/atnow.html | 1 | 1 | N/A | N/A | 7 | 7 | N/A | N/A | N/A | N/A | 5455 |
| 537 | */AttendedUDP.zip* | .{0,1000}\/AttendedUDP\.zip.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5466 |
| 538 | */AutoHotkey.exe* | .{0,1000}\/AutoHotkey\.exe.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5478 |
| 539 | */AutoHotkey.git* | .{0,1000}\/AutoHotkey\.git.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5479 |
| 540 | */AutoHotkey/releases/download/* | .{0,1000}\/AutoHotkey\/releases\/download\/.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5480 |
| 541 | */AutoHotkey_*.zip* | .{0,1000}\/AutoHotkey_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5481 |
| 542 | */AutoHotkey_1*_setup.exe* | .{0,1000}\/AutoHotkey_1.{0,1000}_setup\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5482 |
| 543 | */AutoHotkey_2*_setup.exe* | .{0,1000}\/AutoHotkey_2.{0,1000}_setup\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5483 |
| 544 | */AutoHotkey64.exe* | .{0,1000}\/AutoHotkey64\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5484 |
| 545 | */AutoHotkey64.exe* | .{0,1000}\/AutoHotkey64\.exe.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5485 |
| 546 | */Aweray_Remote_*.exe* | .{0,1000}\/Aweray_Remote_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5505 |
| 547 | */Aweray_Remote_*.zip* | .{0,1000}\/Aweray_Remote_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5506 |
| 548 | */bin/bash -c 'wg addconf * | .{0,1000}\/bin\/bash\s\-c\s\'wg\saddconf\s.{0,1000} | greyware_tool_keyword | tunnel.pyjam.as | SSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5623 |
| 549 | */bin/boringproxy* | .{0,1000}\/bin\/boringproxy.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | #linux | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5624 |
| 550 | */bin/dataplicity* | .{0,1000}\/bin\/dataplicity.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 5625 |
| 551 | */bin/dropbear* | .{0,1000}\/bin\/dropbear.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 5626 |
| 552 | */bin/meshagent* | .{0,1000}\/bin\/meshagent.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | #linux | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 5635 |
| 553 | */bin/MeshCommander* | .{0,1000}\/bin\/MeshCommander.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | #linux | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 5636 |
| 554 | */bin/portr* | .{0,1000}\/bin\/portr.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 0 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 5638 |
| 555 | */bin/rsocks* | .{0,1000}\/bin\/rsocks.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | #linux | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 5651 |
| 556 | */bin/sh | nc* | .{0,1000}\/bin\/sh\s\|\snc.{0,1000} | greyware_tool_keyword | shell | Reverse Shell Command Line | T1105 - T1021.001 - T1021.002 | TA0002 - TA0008 | N/A | N/A | C2 | https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_shell_susp_rev_shells.yml | 1 | 0 | #linux | greyware tool - risks of False positive ! | N/A | 10 | 9115 | 2316 | 2025-04-17T19:43:35Z | 2016-12-24T09:48:49Z | 5652 |
| 557 | */bin/sh -i <&3 >&3 2>&3* | .{0,1000}\/bin\/sh\s\-i\s\<\&3\s\>\&3\s2\>\&3.{0,1000} | greyware_tool_keyword | shell | Reverse Shell Command Line | T1105 - T1021.001 - T1021.002 | TA0002 - TA0008 | N/A | N/A | C2 | https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_shell_susp_rev_shells.yml | 1 | 0 | #linux | greyware tool - risks of False positive ! | N/A | 10 | 9115 | 2316 | 2025-04-17T19:43:35Z | 2016-12-24T09:48:49Z | 5654 |
| 558 | */bin/staqlab-tunnel* | .{0,1000}\/bin\/staqlab\-tunnel.{0,1000} | greyware_tool_keyword | staqlab-tunnel | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/cocoflan/Staqlab-tunnel | 1 | 0 | #linux | N/A | 10 | 10 | 1 | 0 | 2020-05-19T06:43:14Z | 2020-05-19T06:19:31Z | 5656 |
| 559 | */bin/syncthing* | .{0,1000}\/bin\/syncthing.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 0 | #linux | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 5657 |
| 560 | */bin/tunnelmole.js* | .{0,1000}\/bin\/tunnelmole\.js.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 0 | #linux | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 5661 |
| 561 | */bin/tunwg* | .{0,1000}\/bin\/tunwg.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 0 | #linux | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 5662 |
| 562 | */bin/wireproxy* | .{0,1000}\/bin\/wireproxy.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 0 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 5665 |
| 563 | */bin/x64/connectd.exe* | .{0,1000}\/bin\/x64\/connectd\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | #linux | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 5666 |
| 564 | */BitLockerToGo.exe* | .{0,1000}\/BitLockerToGo\.exe.{0,1000} | greyware_tool_keyword | BitLockerToGo | BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data | T1218 - T1055 - T1112 - T1056 - T1555 | TA0005 - TA0007 - TA0009 | Lumma Stealer | N/A | Defense Evasion | https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/ | 0 | 1 | N/A | high FP - hunting only | 3 | 8 | N/A | N/A | N/A | N/A | 5676 |
| 565 | */bomgar-rep.exe* | .{0,1000}\/bomgar\-rep\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5761 |
| 566 | */bomgar-rep-installer.exe* | .{0,1000}\/bomgar\-rep\-installer\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5762 |
| 567 | */bomgar-scc-*.exe* | .{0,1000}\/bomgar\-scc\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5763 |
| 568 | */bomgar-scc.exe* | .{0,1000}\/bomgar\-scc\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5764 |
| 569 | */boringproxy.git* | .{0,1000}\/boringproxy\.git.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5767 |
| 570 | */boringproxy-client.service* | .{0,1000}\/boringproxy\-client\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5768 |
| 571 | */boringproxy-server.service* | .{0,1000}\/boringproxy\-server\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5769 |
| 572 | */BoxDrive.msi* | .{0,1000}\/BoxDrive\.msi.{0,1000} | greyware_tool_keyword | Box | Attackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackers | T1567.002 - T1071.001 - T1036 - T1048.002 | TA0005 - TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://app.box.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 5770 |
| 573 | */btunnel.exe* | .{0,1000}\/btunnel\.exe.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 5847 |
| 574 | */btunnel.log* | .{0,1000}\/btunnel\.log.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 0 | #linux | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 5848 |
| 575 | */cloud.telebit.remote.plist* | .{0,1000}\/cloud\.telebit\.remote\.plist.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6086 |
| 576 | */cloudflared.git* | .{0,1000}\/cloudflared\.git.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6091 |
| 577 | */cloudflared/tunnel/* | .{0,1000}\/cloudflared\/tunnel\/.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 0 | #linux | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6092 |
| 578 | */cloudflared-linux-*.deb* | .{0,1000}\/cloudflared\-linux\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | #linux | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6093 |
| 579 | */cloudflared-linux-*.rpm* | .{0,1000}\/cloudflared\-linux\-.{0,1000}\.rpm.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | #linux | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6094 |
| 580 | */cmd/tailscaled* | .{0,1000}\/cmd\/tailscaled.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 6105 |
| 581 | */com.tonyseek.rsocks.plist* | .{0,1000}\/com\.tonyseek\.rsocks\.plist.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | #linux | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 6153 |
| 582 | */config/apps/http/servers/sirtunnel/routes* | .{0,1000}\/config\/apps\/http\/servers\/sirtunnel\/routes.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 6181 |
| 583 | */connectd.aarch64-win.exe* | .{0,1000}\/connectd\.aarch64\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 6189 |
| 584 | */connectd.x86_64-win.exe* | .{0,1000}\/connectd\.x86_64\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 6190 |
| 585 | */Create /TN TVInstallRestore /TR * | .{0,1000}\/Create\s\/TN\sTVInstallRestore\s\/TR\s.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 0 | N/A | FP risk - teamviewer usage | 10 | 10 | N/A | N/A | N/A | N/A | 6229 |
| 586 | */croc.exe* | .{0,1000}\/croc\.exe.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6271 |
| 587 | */croc.service* | .{0,1000}\/croc\.service.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 0 | #linux | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6272 |
| 588 | */croc/releases/download/v10* | .{0,1000}\/croc\/releases\/download\/v10.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6273 |
| 589 | */croc/releases/latest* | .{0,1000}\/croc\/releases\/latest.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6274 |
| 590 | */croc-entrypoint.sh* | .{0,1000}\/croc\-entrypoint\.sh.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 0 | #linux | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6275 |
| 591 | */crowbar.git* | .{0,1000}\/crowbar\.git.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6285 |
| 592 | */crowbar_1.0.0_darwin_386.zip* | .{0,1000}\/crowbar_1\.0\.0_darwin_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6286 |
| 593 | */crowbar_1.0.0_darwin_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_darwin_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6287 |
| 594 | */crowbar_1.0.0_freebsd_386.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6288 |
| 595 | */crowbar_1.0.0_freebsd_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6289 |
| 596 | */crowbar_1.0.0_freebsd_arm.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_arm\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6290 |
| 597 | */crowbar_1.0.0_linux_386.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_386\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6291 |
| 598 | */crowbar_1.0.0_linux_amd64.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6292 |
| 599 | */crowbar_1.0.0_linux_arm.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_arm\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6293 |
| 600 | */crowbar_1.0.0_openbsd_386.zip* | .{0,1000}\/crowbar_1\.0\.0_openbsd_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6294 |
| 601 | */crowbar_1.0.0_openbsd_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_openbsd_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6295 |
| 602 | */crowbar_1.0.0_windows_386.zip* | .{0,1000}\/crowbar_1\.0\.0_windows_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6296 |
| 603 | */crowbar_1.0.0_windows_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_windows_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6297 |
| 604 | */damewareagent.exe* | .{0,1000}\/damewareagent\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6397 |
| 605 | */dataplicity.app* | .{0,1000}\/dataplicity\.app.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6436 |
| 606 | */dataplicity.conf* | .{0,1000}\/dataplicity\.conf.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6437 |
| 607 | */dataplicity.log* | .{0,1000}\/dataplicity\.log.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6438 |
| 608 | */dataplicity-agent.git* | .{0,1000}\/dataplicity\-agent\.git.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6439 |
| 609 | */dataplicity-agent/releases/download* | .{0,1000}\/dataplicity\-agent\/releases\/download.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6440 |
| 610 | */docker/compose/zrok-instance/* | .{0,1000}\/docker\/compose\/zrok\-instance\/.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 6707 |
| 611 | */download*mediafire.com/ | .{0,1000}\/download.{0,1000}mediafire\.com\/ | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1083 - T1560 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 6750 |
| 612 | */download/fiddler/fiddler-everywhere-windows* | .{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 6751 |
| 613 | */download/pcunlocker* | .{0,1000}\/download\/pcunlocker.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6754 |
| 614 | */downloads/ultravnc.html* | .{0,1000}\/downloads\/ultravnc\.html.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6771 |
| 615 | */dropbear.git* | .{0,1000}\/dropbear\.git.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 1 | N/A | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6792 |
| 616 | */dropbear.init* | .{0,1000}\/dropbear\.init.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6793 |
| 617 | */dropbear.log* | .{0,1000}\/dropbear\.log.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6794 |
| 618 | */dropbear/releases/* | .{0,1000}\/dropbear\/releases\/.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 1 | N/A | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6795 |
| 619 | */dropbear_dss_host_key* | .{0,1000}\/dropbear_dss_host_key.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6796 |
| 620 | */dropbear_rsa_host_key* | .{0,1000}\/dropbear_rsa_host_key.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6797 |
| 621 | */dropbear-sshj.git* | .{0,1000}\/dropbear\-sshj\.git.{0,1000} | greyware_tool_keyword | SSH-J.com | This is Dropbear SSH server modified to be used as a public SSH jump & port forwarding service | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://bitbucket.org/ValdikSS/dropbear-sshj/src/master/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6798 |
| 622 | */DuckDNS.7z* | .{0,1000}\/DuckDNS\.7z.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6809 |
| 623 | */DuckDNS.git* | .{0,1000}\/DuckDNS\.git.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6810 |
| 624 | */DuckDNS.zip"* | .{0,1000}\/DuckDNS\.zip\".{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6811 |
| 625 | */duckdns/duck.log* | .{0,1000}\/duckdns\/duck\.log.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | #logfile #linux | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6812 |
| 626 | */duckdns/duck.sh* | .{0,1000}\/duckdns\/duck\.sh.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6813 |
| 627 | */duckdns-powershell.git* | .{0,1000}\/duckdns\-powershell\.git.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6814 |
| 628 | */DumpS1.ps1* | .{0,1000}\/DumpS1\.ps1.{0,1000} | greyware_tool_keyword | SentinelAgent | dump a process with SentinelAgent.exe | T1003 - T1055 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e | 1 | 0 | N/A | N/A | 8 | 7 | N/A | N/A | N/A | N/A | 6841 |
| 629 | */dwagent.desktop* | .{0,1000}\/dwagent\.desktop.{0,1000} | greyware_tool_keyword | dwagent | The DWService to remotly control your machine - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://github.com/dwservice/agent | 1 | 0 | #linux | N/A | 10 | 5 | 471 | 83 | 2023-03-22T08:45:16Z | 2019-01-23T10:40:24Z | 6857 |
| 630 | */dwagent.service* | .{0,1000}\/dwagent\.service.{0,1000} | greyware_tool_keyword | dwagent | The DWService to remotly control your machine - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://github.com/dwservice/agent | 1 | 0 | #linux | N/A | 10 | 5 | 471 | 83 | 2023-03-22T08:45:16Z | 2019-01-23T10:40:24Z | 6858 |
| 631 | */dwagsystray* | .{0,1000}\/dwagsystray.{0,1000} | greyware_tool_keyword | dwagent | The DWService to remotly control your machine - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://github.com/dwservice/agent | 1 | 0 | #linux | N/A | 10 | 5 | 471 | 83 | 2023-03-22T08:45:16Z | 2019-01-23T10:40:24Z | 6859 |
| 632 | */DWMRC_St_64.msi* | .{0,1000}\/DWMRC_St_64\.msi.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6860 |
| 633 | */DWRCC.exe* | .{0,1000}\/DWRCC\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6861 |
| 634 | */DWRCCMD.exe* | .{0,1000}\/DWRCCMD\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6862 |
| 635 | */DWRCS.exe* | .{0,1000}\/DWRCS\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6863 |
| 636 | */ehorus_agent_installer-* | .{0,1000}\/ehorus_agent_installer\-.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6906 |
| 637 | */Eraser 5.8.8.exe* | .{0,1000}\/Eraser\s5\.8\.8\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6979 |
| 638 | */Eraser 6.0.10.2620.exe* | .{0,1000}\/Eraser\s6\.0\.10\.2620\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6980 |
| 639 | */Eraser 6.0.8.2273.exe* | .{0,1000}\/Eraser\s6\.0\.8\.2273\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6981 |
| 640 | */Eraser 6.0.9.2343.exe* | .{0,1000}\/Eraser\s6\.0\.9\.2343\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6982 |
| 641 | */Eraser 6.2.0.2994.exe* | .{0,1000}\/Eraser\s6\.2\.0\.2994\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6983 |
| 642 | */EraserSetup.exe* | .{0,1000}\/EraserSetup\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6984 |
| 643 | */etc/3proxy/conf* | .{0,1000}\/etc\/3proxy\/conf.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 0 | #linux | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 6989 |
| 644 | */etc/capabilities/shadowsocks.json* | .{0,1000}\/etc\/capabilities\/shadowsocks\.json.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | #linux | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 6990 |
| 645 | */etc/crowbar/* | .{0,1000}\/etc\/crowbar\/.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 0 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6993 |
| 646 | */etc/crowbard.conf* | .{0,1000}\/etc\/crowbard\.conf.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 0 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6994 |
| 647 | */etc/dataplicity* | .{0,1000}\/etc\/dataplicity.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6995 |
| 648 | */etc/default/dropbear* | .{0,1000}\/etc\/default\/dropbear.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6996 |
| 649 | */etc/dropbear/* | .{0,1000}\/etc\/dropbear\/.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6998 |
| 650 | */etc/ehorus/ehorus_agent* | .{0,1000}\/etc\/ehorus\/ehorus_agent.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6999 |
| 651 | */etc/fleet/fleet.env* | .{0,1000}\/etc\/fleet\/fleet\.env.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 0 | #linux | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7000 |
| 652 | */etc/init.d/ehorus_agent_daemon* | .{0,1000}\/etc\/init\.d\/ehorus_agent_daemon.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7002 |
| 653 | */etc/letsencrypt/live/jprq.site/* | .{0,1000}\/etc\/letsencrypt\/live\/jprq\.site\/.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 7010 |
| 654 | */etc/level/config.yaml* | .{0,1000}\/etc\/level\/config\.yaml.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7011 |
| 655 | */etc/ltproxy.yml* | .{0,1000}\/etc\/ltproxy\.yml.{0,1000} | greyware_tool_keyword | LTProxy | Linux Transparent Proxy (Similar to Proxifiter) | T1090 - T1573.001 - T1571 - T1071.001 | TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://github.com/L-codes/LTProxy | 1 | 0 | #linux | N/A | 10 | 1 | 31 | 5 | 2024-11-27T05:09:47Z | 2021-11-11T15:17:54Z | 7012 |
| 656 | */etc/pagekite.d* | .{0,1000}\/etc\/pagekite\.d.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | #linux | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 7014 |
| 657 | */etc/pulseway/config.xml* | .{0,1000}\/etc\/pulseway\/config\.xml.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7017 |
| 658 | */etc/remoteit/* | .{0,1000}\/etc\/remoteit\/.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | #linux | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 7018 |
| 659 | */etc/shadowsocks-rust* | .{0,1000}\/etc\/shadowsocks\-rust.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | #linux | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 7021 |
| 660 | */etc/sshuttle* | .{0,1000}\/etc\/sshuttle.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 0 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 7022 |
| 661 | */etc/systemd/system/anydesk.service* | .{0,1000}\/etc\/systemd\/system\/anydesk\.service.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 7026 |
| 662 | */etc/systemd/system/localtunnel.service* | .{0,1000}\/etc\/systemd\/system\/localtunnel\.service.{0,1000} | greyware_tool_keyword | Rust Localtunnels | Localtunnel implementation in Rust - exposes your localhost endpoint to the world | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/kaichaosun/rlt | 1 | 0 | #linux | N/A | 7 | 2 | 119 | 13 | 2024-12-16T09:09:34Z | 2022-06-27T05:57:34Z | 7028 |
| 663 | */etc/wireguard/*.conf* | .{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000} | greyware_tool_keyword | tunnel | Tunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outside | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/koding/tunnel | 1 | 0 | #linux | N/A | 10 | 10 | 328 | 72 | 2023-10-20T13:43:58Z | 2015-05-28T07:26:42Z | 7031 |
| 664 | */etc/wireguard/*.conf* | .{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7032 |
| 665 | */etc/wireguard/*.conf* | .{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000} | greyware_tool_keyword | tunnel.pyjam.as | SSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7033 |
| 666 | */etc/zrok.env* | .{0,1000}\/etc\/zrok\.env.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 7035 |
| 667 | */etc/zrok/* | .{0,1000}\/etc\/zrok\/.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 7036 |
| 668 | */expose/database/expose.db* | .{0,1000}\/expose\/database\/expose\.db.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 7151 |
| 669 | */expose/raw/master/builds/expose* | .{0,1000}\/expose\/raw\/master\/builds\/expose.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 7152 |
| 670 | */Fiddler Everywhere *.*.*.exe* | .{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 7190 |
| 671 | */FileZilla_*_sponsored-setup.exe* | .{0,1000}\/FileZilla_.{0,1000}_sponsored\-setup\.exe.{0,1000} | greyware_tool_keyword | FileZilla | FileZilla admintool used by threat actors for persistence and data exfiltration | T1505 - T1041 | TA0003 - TA0009 -TA0010 | N/A | Dispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155 | Data Exfiltration | https://filezilla-project.org/ | 1 | 1 | N/A | PUA risk of legitimate usage | 5 | 7 | N/A | N/A | N/A | N/A | 7199 |
| 672 | */FileZilla_Server_*.deb* | .{0,1000}\/FileZilla_Server_.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | FileZilla | FileZilla admintool used by threat actors for persistence and data exfiltration | T1505 - T1041 | TA0003 - TA0009 -TA0010 | N/A | Dispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155 | Data Exfiltration | https://filezilla-project.org/ | 1 | 1 | N/A | PUA risk of legitimate usage | 5 | 7 | N/A | N/A | N/A | N/A | 7200 |
| 673 | */fleet_v*_linux.tar.gz* | .{0,1000}\/fleet_v.{0,1000}_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | #linux | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7216 |
| 674 | */fleetd.crx* | .{0,1000}\/fleetd\.crx.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7217 |
| 675 | */fleetdm/fleet/releases/download/* | .{0,1000}\/fleetdm\/fleet\/releases\/download\/.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7218 |
| 676 | */fleetdm/fleet/releases/latest* | .{0,1000}\/fleetdm\/fleet\/releases\/latest.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7219 |
| 677 | */FreeFileSync.exe* | .{0,1000}\/FreeFileSync\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7247 |
| 678 | */FreeFileSync.tar.gz* | .{0,1000}\/FreeFileSync\.tar\.gz.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7248 |
| 679 | */FreeFileSync_*.tar.gz* | .{0,1000}\/FreeFileSync_.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7249 |
| 680 | */FreeFileSync_*_Windows_Setup.exe* | .{0,1000}\/FreeFileSync_.{0,1000}_Windows_Setup\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7250 |
| 681 | */FreeFileSync_x64.exe* | .{0,1000}\/FreeFileSync_x64\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7251 |
| 682 | */FreeFileSyncPortable_*.exe* | .{0,1000}\/FreeFileSyncPortable_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7252 |
| 683 | */frp.git* | .{0,1000}\/frp\.git.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7258 |
| 684 | */frp_0.*.*_darwin_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7259 |
| 685 | */frp_0.*.*_darwin_arm64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7260 |
| 686 | */frp_0.*.*_freebsd_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_freebsd_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7261 |
| 687 | */frp_0.*.*_linux_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7262 |
| 688 | */frp_0.*.*_linux_arm.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7263 |
| 689 | */frp_0.*.*_linux_arm64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7264 |
| 690 | */frp_0.*.*_linux_mips.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7265 |
| 691 | */frp_0.*.*_linux_mips64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7266 |
| 692 | */frp_0.*.*_linux_mips64le.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64le\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7267 |
| 693 | */frp_0.*.*_linux_mipsle.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mipsle\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7268 |
| 694 | */frpc.exe* | .{0,1000}\/frpc\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7270 |
| 695 | */frpc-mem.log* | .{0,1000}\/frpc\-mem\.log.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 0 | #linux | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 7271 |
| 696 | */frps-mem.log* | .{0,1000}\/frps\-mem\.log.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 0 | #linux | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 7272 |
| 697 | */genacl_proxy_gfw_bypass_china_ip.py | .{0,1000}\/genacl_proxy_gfw_bypass_china_ip\.py | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | #linux | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 7347 |
| 698 | */github.com*.exe?raw=true* | .{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7414 |
| 699 | */github.com/*/archive/refs/tags/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7415 |
| 700 | */github.com/*/raw/main/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7416 |
| 701 | */github.com/*/raw/main/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7417 |
| 702 | */github.com/*/raw/main/*.app* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7418 |
| 703 | */github.com/*/raw/main/*.as* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7419 |
| 704 | */github.com/*/raw/main/*.asc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7420 |
| 705 | */github.com/*/raw/main/*.asp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7421 |
| 706 | */github.com/*/raw/main/*.bash* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | #linux | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7422 |
| 707 | */github.com/*/raw/main/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7423 |
| 708 | */github.com/*/raw/main/*.beacon* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7424 |
| 709 | */github.com/*/raw/main/*.bin* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7425 |
| 710 | */github.com/*/raw/main/*.bpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7426 |
| 711 | */github.com/*/raw/main/*.c* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7427 |
| 712 | */github.com/*/raw/main/*.cer* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7428 |
| 713 | */github.com/*/raw/main/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7429 |
| 714 | */github.com/*/raw/main/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7430 |
| 715 | */github.com/*/raw/main/*.cpp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7431 |
| 716 | */github.com/*/raw/main/*.crt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7432 |
| 717 | */github.com/*/raw/main/*.cs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7433 |
| 718 | */github.com/*/raw/main/*.csh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7434 |
| 719 | */github.com/*/raw/main/*.dat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7435 |
| 720 | */github.com/*/raw/main/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7436 |
| 721 | */github.com/*/raw/main/*.docm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7437 |
| 722 | */github.com/*/raw/main/*.dos* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7438 |
| 723 | */github.com/*/raw/main/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7439 |
| 724 | */github.com/*/raw/main/*.go* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7440 |
| 725 | */github.com/*/raw/main/*.gz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7441 |
| 726 | */github.com/*/raw/main/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7442 |
| 727 | */github.com/*/raw/main/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7443 |
| 728 | */github.com/*/raw/main/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7444 |
| 729 | */github.com/*/raw/main/*.js* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7445 |
| 730 | */github.com/*/raw/main/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7446 |
| 731 | */github.com/*/raw/main/*.log* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7447 |
| 732 | */github.com/*/raw/main/*.mac* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7448 |
| 733 | */github.com/*/raw/main/*.mam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7449 |
| 734 | */github.com/*/raw/main/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7450 |
| 735 | */github.com/*/raw/main/*.msp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7451 |
| 736 | */github.com/*/raw/main/*.nexe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7452 |
| 737 | */github.com/*/raw/main/*.nim* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7453 |
| 738 | */github.com/*/raw/main/*.otm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7454 |
| 739 | */github.com/*/raw/main/*.out* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7455 |
| 740 | */github.com/*/raw/main/*.ova* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7456 |
| 741 | */github.com/*/raw/main/*.pem* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7457 |
| 742 | */github.com/*/raw/main/*.pfx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7458 |
| 743 | */github.com/*/raw/main/*.pl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7459 |
| 744 | */github.com/*/raw/main/*.plx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7460 |
| 745 | */github.com/*/raw/main/*.pm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7461 |
| 746 | */github.com/*/raw/main/*.ppk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7462 |
| 747 | */github.com/*/raw/main/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7463 |
| 748 | */github.com/*/raw/main/*.psm1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7464 |
| 749 | */github.com/*/raw/main/*.pub* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7465 |
| 750 | */github.com/*/raw/main/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7466 |
| 751 | */github.com/*/raw/main/*.pyc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7467 |
| 752 | */github.com/*/raw/main/*.pyo* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7468 |
| 753 | */github.com/*/raw/main/*.rar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7469 |
| 754 | */github.com/*/raw/main/*.raw* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7470 |
| 755 | */github.com/*/raw/main/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7471 |
| 756 | */github.com/*/raw/main/*.rgs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7472 |
| 757 | */github.com/*/raw/main/*.RGS* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7473 |
| 758 | */github.com/*/raw/main/*.run* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7474 |
| 759 | */github.com/*/raw/main/*.scpt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7475 |
| 760 | */github.com/*/raw/main/*.script* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7476 |
| 761 | */github.com/*/raw/main/*.sct* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7477 |
| 762 | */github.com/*/raw/main/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7478 |
| 763 | */github.com/*/raw/main/*.ssh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7479 |
| 764 | */github.com/*/raw/main/*.sys* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7480 |
| 765 | */github.com/*/raw/main/*.teamserver* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7481 |
| 766 | */github.com/*/raw/main/*.temp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7482 |
| 767 | */github.com/*/raw/main/*.tgz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7483 |
| 768 | */github.com/*/raw/main/*.tmp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7484 |
| 769 | */github.com/*/raw/main/*.vb* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7485 |
| 770 | */github.com/*/raw/main/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7486 |
| 771 | */github.com/*/raw/main/*.vbscript* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7487 |
| 772 | */github.com/*/raw/main/*.ws* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7488 |
| 773 | */github.com/*/raw/main/*.wsf* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7489 |
| 774 | */github.com/*/raw/main/*.wsh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7490 |
| 775 | */github.com/*/raw/main/*.X86* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7491 |
| 776 | */github.com/*/raw/main/*.X86_64* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7492 |
| 777 | */github.com/*/raw/main/*.xlam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7493 |
| 778 | */github.com/*/raw/main/*.xlm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7494 |
| 779 | */github.com/*/raw/main/*.xlsm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7495 |
| 780 | */github.com/*/raw/main/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7496 |
| 781 | */github.com/*/raw/refs/heads/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7497 |
| 782 | */github.com/*/raw/refs/heads/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7498 |
| 783 | */github.com/*/raw/refs/heads/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7499 |
| 784 | */github.com/*/raw/refs/heads/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7500 |
| 785 | */github.com/*/raw/refs/heads/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7501 |
| 786 | */github.com/*/raw/refs/heads/*.cpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7502 |
| 787 | */github.com/*/raw/refs/heads/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7503 |
| 788 | */github.com/*/raw/refs/heads/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7504 |
| 789 | */github.com/*/raw/refs/heads/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7505 |
| 790 | */github.com/*/raw/refs/heads/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7506 |
| 791 | */github.com/*/raw/refs/heads/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7507 |
| 792 | */github.com/*/raw/refs/heads/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7508 |
| 793 | */github.com/*/raw/refs/heads/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7509 |
| 794 | */github.com/*/raw/refs/heads/*.pif* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7510 |
| 795 | */github.com/*/raw/refs/heads/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7511 |
| 796 | */github.com/*/raw/refs/heads/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7512 |
| 797 | */github.com/*/raw/refs/heads/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7513 |
| 798 | */github.com/*/raw/refs/heads/*.scr* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7514 |
| 799 | */github.com/*/raw/refs/heads/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7515 |
| 800 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7516 |
| 801 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7517 |
| 802 | */github.com/*/raw/refs/heads/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7518 |
| 803 | */go-gost/core/* | .{0,1000}\/go\-gost\/core\/.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7563 |
| 804 | */go-http-tunnel.git.git* | .{0,1000}\/go\-http\-tunnel\.git\.git.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 7564 |
| 805 | */go-http-tunnel/cmd/* | .{0,1000}\/go\-http\-tunnel\/cmd\/.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 7565 |
| 806 | */go-localtunnel.git* | .{0,1000}\/go\-localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/NoahShen/gotunnelme | 1 | 1 | N/A | N/A | 10 | 10 | 171 | 45 | 2018-01-06T04:41:15Z | 2013-10-18T02:46:51Z | 7570 |
| 807 | */GoodSync-vsub-Setup.exe* | .{0,1000}\/GoodSync\-vsub\-Setup\.exe.{0,1000} | greyware_tool_keyword | Goodsync | GoodSync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | N/A | Data Exfiltration | https://www.goodsync.com/ | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7579 |
| 808 | */gost.tar.gz* | .{0,1000}\/gost\.tar\.gz.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7597 |
| 809 | */gost/raw/master/install.sh* | .{0,1000}\/gost\/raw\/master\/install\.sh.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7598 |
| 810 | */gost/releases/download/*.tar.gz* | .{0,1000}\/gost\/releases\/download\/.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7599 |
| 811 | */gotunnelme.git* | .{0,1000}\/gotunnelme\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/NoahShen/gotunnelme | 1 | 1 | N/A | N/A | 10 | 10 | 171 | 45 | 2018-01-06T04:41:15Z | 2013-10-18T02:46:51Z | 7603 |
| 812 | */gt server -c ./config.yml* | .{0,1000}\/gt\sserver\s\-c\s\.\/config\.yml.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 0 | #linux | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 7671 |
| 813 | */gt-win-x86_64.exe* | .{0,1000}\/gt\-win\-x86_64\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 7682 |
| 814 | */home/*/.anydesk/* | .{0,1000}\/home\/.{0,1000}\/\.anydesk\/.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 7790 |
| 815 | */home/boringproxy* | .{0,1000}\/home\/boringproxy.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 0 | #linux | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 7792 |
| 816 | */home/sshuttle* | .{0,1000}\/home\/sshuttle.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 0 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 7798 |
| 817 | */home/user/rustdesk* | .{0,1000}\/home\/user\/rustdesk.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 0 | #linux | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 7801 |
| 818 | */host-7.2.2.0.msi* | .{0,1000}\/host\-7\.2\.2\.0\.msi.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7810 |
| 819 | */http-put-server.py* | .{0,1000}\/http\-put\-server\.py.{0,1000} | greyware_tool_keyword | exegol | Fully featured and community-driven hacking environment with hundreds of offensive tools | T1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559 | TA0043 - TA0002 - TA0004 - TA0011 - TA0003 | N/A | Black Basta | Exploitation tool | https://github.com/ThePorgs/Exegol | 1 | 0 | #linux | N/A | 10 | 10 | 2354 | 209 | 2025-04-09T16:56:24Z | 2020-03-09T19:12:11Z | 7914 |
| 820 | */hypertunnel.git* | .{0,1000}\/hypertunnel\.git.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7992 |
| 821 | */hypertunnel-tcp-relay*.tar.gz* | .{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7993 |
| 822 | */hypertunnel-tcp-relay*.zip* | .{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7994 |
| 823 | */install-fleetctl.sh* | .{0,1000}\/install\-fleetctl\.sh.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 8101 |
| 824 | */interactsh/* | .{0,1000}\/interactsh\/.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C5 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8106 |
| 825 | */interactsh-client* | .{0,1000}\/interactsh\-client.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C6 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8107 |
| 826 | */interactsh-collaborator* | .{0,1000}\/interactsh\-collaborator.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C15 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8108 |
| 827 | */interactsh-server* | .{0,1000}\/interactsh\-server.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C8 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8109 |
| 828 | */Invoke-Maldaptive.git* | .{0,1000}\/Invoke\-Maldaptive\.git.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 1 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 8153 |
| 829 | */IObitUnlocker.exe* | .{0,1000}\/IObitUnlocker\.exe.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 1 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 8172 |
| 830 | */ipscan.exe* | .{0,1000}\/ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8199 |
| 831 | */ipscan.git* | .{0,1000}\/ipscan\.git.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8200 |
| 832 | */ipscan_*_amd64.deb* | .{0,1000}\/ipscan_.{0,1000}_amd64\.deb.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #linux | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8201 |
| 833 | */ipscan2-binary/*.exe* | .{0,1000}\/ipscan2\-binary\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8202 |
| 834 | */ipscan-any-*.jar* | .{0,1000}\/ipscan\-any\-.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #linux | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8203 |
| 835 | */jprq.git* | .{0,1000}\/jprq\.git.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8251 |
| 836 | */jprq.log* | .{0,1000}\/jprq\.log.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8252 |
| 837 | */jprq.service* | .{0,1000}\/jprq\.service.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8253 |
| 838 | */jprq/server/*.go* | .{0,1000}\/jprq\/server\/.{0,1000}\.go.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8254 |
| 839 | */jprq-darwin-arm64* | .{0,1000}\/jprq\-darwin\-arm64.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8255 |
| 840 | */jprq-linux-386* | .{0,1000}\/jprq\-linux\-386.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8256 |
| 841 | */jprq-linux-arm64* | .{0,1000}\/jprq\-linux\-arm64.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8257 |
| 842 | */jprq-windows-386.exe* | .{0,1000}\/jprq\-windows\-386\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8258 |
| 843 | */jprq-windows-amd64.exe* | .{0,1000}\/jprq\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8259 |
| 844 | */keygen.exe* | .{0,1000}\/keygen\.exe.{0,1000} | greyware_tool_keyword | _ | generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwares | T1204 - T1027 - T1059 - T1055 - T1060 - T1195 | TA0005 - TA0002 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8341 |
| 845 | */killProcessPOC.git* | .{0,1000}\/killProcessPOC\.git.{0,1000} | greyware_tool_keyword | killProcessPOC | use Avast (aswArPot.sys) to kill process - exploited by MONTI ransomware | T1055 - T1106 - T1560.002 - T1569 | TA0005 | Monti ransomware | N/A | Defense Evasion | https://github.com/timwhitez/killProcessPOC | 1 | 0 | N/A | https://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf | 10 | 1 | 67 | 8 | 2022-08-26T03:20:09Z | 2022-04-27T08:25:50Z | 8368 |
| 846 | */lansearch.exe* | .{0,1000}\/lansearch\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8435 |
| 847 | */LansweeperSetup_*.exe* | .{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 8436 |
| 848 | */latest/download/tunwg* | .{0,1000}\/latest\/download\/tunwg.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 8453 |
| 849 | */ld.so /bin/sh -p* | .{0,1000}\/ld\.so\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 8463 |
| 850 | */level-windows-amd64.exe* | .{0,1000}\/level\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8492 |
| 851 | */level-windows-arm64.exe* | .{0,1000}\/level\-windows\-arm64\.exe.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8493 |
| 852 | */libexec/softether/vpnserver/vpnserver* | .{0,1000}\/libexec\/softether\/vpnserver\/vpnserver.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 0 | #VPN #linux | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 8502 |
| 853 | */Library/Logs/SPLog.txt* | .{0,1000}\/Library\/Logs\/SPLog\.txt.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://ruler-project.github.io/ruler-project/RULER/remote/Splashtop/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8507 |
| 854 | */linux_x64_admin* | .{0,1000}\/linux_x64_admin.{0,1000} | greyware_tool_keyword | stowaway | Stowaway -- Multi-hop Proxy Tool for pentesters | T1021 - T1090 - T1071 - T1573 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/ph4ntonn/Stowaway | 1 | 0 | #linux | N/A | 10 | 10 | 2989 | 422 | 2025-04-05T14:48:38Z | 2019-11-15T03:25:50Z | 8542 |
| 855 | */linux_x64_agent* | .{0,1000}\/linux_x64_agent.{0,1000} | greyware_tool_keyword | stowaway | Stowaway -- Multi-hop Proxy Tool for pentesters | T1021 - T1090 - T1071 - T1573 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/ph4ntonn/Stowaway | 1 | 0 | #linux | N/A | 10 | 10 | 2989 | 422 | 2025-04-05T14:48:38Z | 2019-11-15T03:25:50Z | 8543 |
| 856 | */linux_x86_admin* | .{0,1000}\/linux_x86_admin.{0,1000} | greyware_tool_keyword | stowaway | Stowaway -- Multi-hop Proxy Tool for pentesters | T1021 - T1090 - T1071 - T1573 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/ph4ntonn/Stowaway | 1 | 0 | #linux | N/A | 10 | 10 | 2989 | 422 | 2025-04-05T14:48:38Z | 2019-11-15T03:25:50Z | 8544 |
| 857 | */linux_x86_agent* | .{0,1000}\/linux_x86_agent.{0,1000} | greyware_tool_keyword | stowaway | Stowaway -- Multi-hop Proxy Tool for pentesters | T1021 - T1090 - T1071 - T1573 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/ph4ntonn/Stowaway | 1 | 0 | #linux | N/A | 10 | 10 | 2989 | 422 | 2025-04-05T14:48:38Z | 2019-11-15T03:25:50Z | 8545 |
| 858 | */LMI_Rescue.exe* | .{0,1000}\/LMI_Rescue\.exe.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8558 |
| 859 | */LMIRTechConsole.exe* | .{0,1000}\/LMIRTechConsole\.exe.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8559 |
| 860 | */localtunnel.git* | .{0,1000}\/localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8596 |
| 861 | */localtunnel.git* | .{0,1000}\/localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnels | client for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 8 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8597 |
| 862 | */localtunnel.js* | .{0,1000}\/localtunnel\.js.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8598 |
| 863 | */localtunnel-linux-*.tar* | .{0,1000}\/localtunnel\-linux\-.{0,1000}\.tar.{0,1000} | greyware_tool_keyword | Rust Localtunnels | Localtunnel implementation in Rust - exposes your localhost endpoint to the world | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/kaichaosun/rlt | 1 | 0 | #linux | N/A | 7 | 2 | 119 | 13 | 2024-12-16T09:09:34Z | 2022-06-27T05:57:34Z | 8599 |
| 864 | */localtunnel-server.git* | .{0,1000}\/localtunnel\-server\.git.{0,1000} | greyware_tool_keyword | localtunnels | server for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/server | 1 | 1 | N/A | N/A | 8 | 10 | 3163 | 1033 | 2024-03-20T09:14:46Z | 2013-06-16T22:30:48Z | 8600 |
| 865 | */loclx.exe* | .{0,1000}\/loclx\.exe.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 8606 |
| 866 | */loclx-windows-amd64.zip* | .{0,1000}\/loclx\-windows\-amd64\.zip.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 8607 |
| 867 | */log/anydesk.trace* | .{0,1000}\/log\/anydesk\.trace.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/ | 1 | 0 | #linux | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 8608 |
| 868 | */lsa-whisperer-*.zip* | .{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8658 |
| 869 | */lsa-whisperer.git* | .{0,1000}\/lsa\-whisperer\.git.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8659 |
| 870 | */LTProxy.git* | .{0,1000}\/LTProxy\.git.{0,1000} | greyware_tool_keyword | LTProxy | Linux Transparent Proxy (Similar to Proxifiter) | T1090 - T1573.001 - T1571 - T1071.001 | TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://github.com/L-codes/LTProxy | 1 | 1 | #linux | N/A | 10 | 1 | 31 | 5 | 2024-11-27T05:09:47Z | 2021-11-11T15:17:54Z | 8660 |
| 871 | */MEGAclient.exe* | .{0,1000}\/MEGAclient\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8734 |
| 872 | */MEGAcmd.exe* | .{0,1000}\/MEGAcmd\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8735 |
| 873 | */MEGAcmd.sh* | .{0,1000}\/MEGAcmd\.sh.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8736 |
| 874 | */MEGAcmdServer.exe* | .{0,1000}\/MEGAcmdServer\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8737 |
| 875 | */MEGAcmdSetup.exe* | .{0,1000}\/MEGAcmdSetup\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8738 |
| 876 | */MEGAcmdSetup32.exe* | .{0,1000}\/MEGAcmdSetup32\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8739 |
| 877 | */MEGAcmdSetup64.exe* | .{0,1000}\/MEGAcmdSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8740 |
| 878 | */MEGAcmdSetup64.exe* | .{0,1000}\/MEGAcmdSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8741 |
| 879 | */MEGAcmdShell.exe* | .{0,1000}\/MEGAcmdShell\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8742 |
| 880 | */MEGAcmdUpdater.app* | .{0,1000}\/MEGAcmdUpdater\.app.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | #macos | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8743 |
| 881 | */megasync.exe* | .{0,1000}\/megasync\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8744 |
| 882 | */MEGAsyncSetup32.exe* | .{0,1000}\/MEGAsyncSetup32\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8745 |
| 883 | */MEGAsyncSetup64.exe* | .{0,1000}\/MEGAsyncSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8746 |
| 884 | */megatools.exe* | .{0,1000}\/megatools\.exe.{0,1000} | greyware_tool_keyword | megatools | Megatools is a collection of free and open source programs for accessing Mega service from a command line. Abused by attackers for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/megous/megatools | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 8747 |
| 885 | */MeshAgent --* | .{0,1000}\/MeshAgent\s\-\-.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | #linux | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8774 |
| 886 | */MeshAgent.git* | .{0,1000}\/MeshAgent\.git.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshAgent | 1 | 1 | N/A | N/A | 10 | 3 | 264 | 96 | 2025-03-19T18:43:56Z | 2017-10-12T21:26:52Z | 8775 |
| 887 | */MeshCentral.git* | .{0,1000}\/MeshCentral\.git.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8776 |
| 888 | */meshcentral.service* | .{0,1000}\/meshcentral\.service.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 0 | #linux | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8777 |
| 889 | */meshinstall.sh* | .{0,1000}\/meshinstall\.sh.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8778 |
| 890 | */meshinstall-bsd-rcd.sh* | .{0,1000}\/meshinstall\-bsd\-rcd\.sh.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8779 |
| 891 | */Microsoft Azure Storage Explorer.app* | .{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.app.{0,1000} | greyware_tool_keyword | Azure Storage Explorer | legitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data Exfiltration | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Rhysida | Data Exfiltration | https://azure.microsoft.com/en-us/products/storage/storage-explorer | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 8812 |
| 892 | */Microsoft Azure Storage Explorer.zip* | .{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.zip.{0,1000} | greyware_tool_keyword | Azure Storage Explorer | legitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data Exfiltration | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Rhysida | Data Exfiltration | https://azure.microsoft.com/en-us/products/storage/storage-explorer | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 8813 |
| 893 | */MITMPluginLogViewer* | .{0,1000}\/MITMPluginLogViewer.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 8865 |
| 894 | */MITMServerHijacking* | .{0,1000}\/MITMServerHijacking.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 8867 |
| 895 | */mzcv.exe* | .{0,1000}\/mzcv\.exe.{0,1000} | greyware_tool_keyword | MozillaCookiesView | nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors | T1070 - T1552.001 - T1125 - T1005 | TA0009 - TA0005 | N/A | MuddyWater | Credential Access | https://www.nirsoft.net/utils/mzcv.html | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8993 |
| 896 | */mzcv-x64.zip* | .{0,1000}\/mzcv\-x64\.zip.{0,1000} | greyware_tool_keyword | MozillaCookiesView | nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors | T1070 - T1552.001 - T1125 - T1005 | TA0009 - TA0005 | N/A | MuddyWater | Credential Access | https://www.nirsoft.net/utils/mzcv.html | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8994 |
| 897 | */NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True* | .{0,1000}\/NAMESPACE\:\\\\root\\Microsoft\\Windows\\Defender\sPATH\sMSFT_MpPreference\scall\sAdd\sExclusionExtension\=exe\sForce\=True.{0,1000} | greyware_tool_keyword | wmic | Windows Defender Tampering Via Wmic | T1489 | TA0005 | N/A | MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR | Defense Evasion | https://www.virustotal.com/gui/file/00820a1f0972678cfe7885bc989ab3e5602b0febc96baf9bf3741d56aa374f03/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9007 |
| 898 | */nats-rmm.conf* | .{0,1000}\/nats\-rmm\.conf.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 9019 |
| 899 | */nc64 -i * | .{0,1000}\/nc64\s\-i\s.{0,1000} | greyware_tool_keyword | nc | backdoor with netcat - used by the Ransomware group Dispossessor | T1547.001 - T1059.003 - T1105 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9027 |
| 900 | */nc64 -lvp * | .{0,1000}\/nc64\s\-lvp\s.{0,1000} | greyware_tool_keyword | nc | backdoor with netcat - used by the Ransomware group Dispossessor | T1547.001 - T1059.003 - T1105 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9028 |
| 901 | */nc64 -zv * | .{0,1000}\/nc64\s\-zv\s.{0,1000} | greyware_tool_keyword | nc | backdoor with netcat - used by the Ransomware group Dispossessor | T1547.001 - T1059.003 - T1105 | TA0003 - TA0005 - TA0011 | N/A | Dispossessor | Persistence | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9029 |
| 902 | */neoreg.py* | .{0,1000}\/neoreg\.py.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9047 |
| 903 | */Neo-reGeorg.git* | .{0,1000}\/Neo\-reGeorg\.git.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9048 |
| 904 | */NeoreGeorg.java* | .{0,1000}\/NeoreGeorg\.java.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9049 |
| 905 | */Neo-reGeorg/tarball* | .{0,1000}\/Neo\-reGeorg\/tarball.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9050 |
| 906 | */Neo-reGeorg/zipball* | .{0,1000}\/Neo\-reGeorg\/zipball.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9051 |
| 907 | */netcat-win32-*.zip* | .{0,1000}\/netcat\-win32\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | netcat | ncat reverse shell | T1105 - T1021.001 - T1021.002 | TA0002 - TA0008 | N/A | APT15 - Calypso - EMBER BEAR - Black Basta | C2 | https://nmap.org/ncat/ | 1 | 0 | #linux | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 9086 |
| 908 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 9108 |
| 909 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9109 |
| 910 | */netscan_linux.tar.gz* | .{0,1000}\/netscan_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9110 |
| 911 | */netscan_macos.dmg* | .{0,1000}\/netscan_macos\.dmg.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #macos | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9111 |
| 912 | */netscan_setup.exe* | .{0,1000}\/netscan_setup\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9112 |
| 913 | */netscan64.exe* | .{0,1000}\/netscan64\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9113 |
| 914 | */netshrun.c* | .{0,1000}\/netshrun\.c.{0,1000} | greyware_tool_keyword | NetshRun | Netsh.exe relies on extensions taken from Registry which means it may be used as a persistence and you go one step further extending netsh with a DLL allowing you to do whatever you want | T1546.008 - T1112 - T1037 - T1055 - T1218.001 | TA0003 - TA0002 - TA0008 | N/A | N/A | Exploitation tool | https://github.com/gtworek/PSBits/blob/master/NetShRun | 1 | 1 | N/A | N/A | N/A | 10 | 3337 | 542 | 2025-03-12T19:59:23Z | 2019-06-29T13:22:36Z | 9117 |
| 915 | */ngrok.exe* | .{0,1000}\/ngrok\.exe.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md | 1 | 0 | N/A | N/A | 10 | 10 | 1594 | 198 | 2025-04-16T21:16:51Z | 2021-08-16T17:34:25Z | 9136 |
| 916 | */ngrok.git* | .{0,1000}\/ngrok\.git.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9137 |
| 917 | */ngrok.go* | .{0,1000}\/ngrok\.go.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9138 |
| 918 | */ngrok.log* | .{0,1000}\/ngrok\.log.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 0 | #linux | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9139 |
| 919 | */ngrokd.go* | .{0,1000}\/ngrokd\.go.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9140 |
| 920 | */ngrokroot.crt* | .{0,1000}\/ngrokroot\.crt.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 0 | #linux | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9143 |
| 921 | */NimScan.exe* | .{0,1000}\/NimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9175 |
| 922 | */NimScan.git* | .{0,1000}\/NimScan\.git.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9176 |
| 923 | */NimScan.nim* | .{0,1000}\/NimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9177 |
| 924 | */nircmd.exe* | .{0,1000}\/nircmd\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9184 |
| 925 | */nircmd.zip* | .{0,1000}\/nircmd\.zip.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9185 |
| 926 | */nircmdc.exe* | .{0,1000}\/nircmdc\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9186 |
| 927 | */nircmd-x64.zip* | .{0,1000}\/nircmd\-x64\.zip.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9187 |
| 928 | */Nmap/folder/check15* | .{0,1000}\/Nmap\/folder\/check15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9198 |
| 929 | */Nmap/folder/check16* | .{0,1000}\/Nmap\/folder\/check16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9199 |
| 930 | */Nmap/folder/check17* | .{0,1000}\/Nmap\/folder\/check17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9200 |
| 931 | */nmaplowercheck15* | .{0,1000}\/nmaplowercheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://nmap.org/book/nse-usage.html | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | N/A | N/A | N/A | N/A | 9204 |
| 932 | */nmaplowercheck16* | .{0,1000}\/nmaplowercheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9205 |
| 933 | */nmaplowercheck17* | .{0,1000}\/nmaplowercheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9206 |
| 934 | */nmap-nse-scripts* | .{0,1000}\/nmap\-nse\-scripts.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 0 | #linux | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9207 |
| 935 | */nmap-scada* | .{0,1000}\/nmap\-scada.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9208 |
| 936 | */NmapUpperCheck15* | .{0,1000}\/NmapUpperCheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9209 |
| 937 | */NmapUpperCheck16* | .{0,1000}\/NmapUpperCheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9210 |
| 938 | */NmapUpperCheck17* | .{0,1000}\/NmapUpperCheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9211 |
| 939 | */nmap-vulners* | .{0,1000}\/nmap\-vulners.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9212 |
| 940 | */nse_install/* | .{0,1000}\/nse_install\/.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 0 | #linux | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9259 |
| 941 | */nse-install.git* | .{0,1000}\/nse\-install\.git.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9260 |
| 942 | */nspowershell.exe* | .{0,1000}\/nspowershell\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9264 |
| 943 | */nssadmui.exe* | .{0,1000}\/nssadmui\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9265 |
| 944 | */OfflineSamTool.exe* | .{0,1000}\/OfflineSamTool\.exe.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9370 |
| 945 | */openvpn.exe* | .{0,1000}\/openvpn\.exe.{0,1000} | greyware_tool_keyword | OPENVPN | OpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate data | T1071 - T1573 - T1133 | TA0003 - TA0008 - TA0011 | N/A | N/A | Defense Evasion | https://openvpn.net/ | 1 | 1 | #VPN | N/A | 6 | 8 | N/A | N/A | N/A | N/A | 9396 |
| 946 | */opt/config/aonetwork-client.yml* | .{0,1000}\/opt\/config\/aonetwork\-client\.yml.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 0 | #linux | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 9404 |
| 947 | */opt/dataplicity/* | .{0,1000}\/opt\/dataplicity\/.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 0 | #linux | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 9406 |
| 948 | */opt/duckdns/* | .{0,1000}\/opt\/duckdns\/.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 0 | #linux | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 9408 |
| 949 | */opt/entrypoint.sh* | .{0,1000}\/opt\/entrypoint\.sh.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 0 | #linux | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 9409 |
| 950 | */opt/remoteit/remoteit* | .{0,1000}\/opt\/remoteit\/remoteit.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 0 | #linux | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 9428 |
| 951 | */opt/rsocks/* | .{0,1000}\/opt\/rsocks\/.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | #linux | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 9429 |
| 952 | */opt/telebit* | .{0,1000}\/opt\/telebit.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9433 |
| 953 | */oset.exe* | .{0,1000}\/oset\.exe.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9447 |
| 954 | */oset.zip* | .{0,1000}\/oset\.zip.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9448 |
| 955 | */oshi_run.pl* | .{0,1000}\/oshi_run\.pl.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 0 | #linux #filehostingservice | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 9449 |
| 956 | */OshiUpload.git* | .{0,1000}\/OshiUpload\.git.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 9450 |
| 957 | */PAExec.cpp* | .{0,1000}\/PAExec\.cpp.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9480 |
| 958 | */paexec.exe | .{0,1000}\/paexec\.exe | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9481 |
| 959 | */PAExec.git* | .{0,1000}\/PAExec\.git.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9482 |
| 960 | */paexec_eula.txt* | .{0,1000}\/paexec_eula\.txt.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 0 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9483 |
| 961 | */pagekite-*.log* | .{0,1000}\/pagekite\-.{0,1000}\.log.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | #linux | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9484 |
| 962 | */pagekite.log* | .{0,1000}\/pagekite\.log.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | #linux | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9485 |
| 963 | */pagekite.py* | .{0,1000}\/pagekite\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9486 |
| 964 | */pagekite-0.3.21.py* | .{0,1000}\/pagekite\-0\.3\.21\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9487 |
| 965 | */pagekite-0.4.6a.py* | .{0,1000}\/pagekite\-0\.4\.6a\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9488 |
| 966 | */pagekite-0.5.6d.py* | .{0,1000}\/pagekite\-0\.5\.6d\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9489 |
| 967 | */pagekite-0.5.8a.py* | .{0,1000}\/pagekite\-0\.5\.8a\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9490 |
| 968 | */pagekite-gtk.py* | .{0,1000}\/pagekite\-gtk\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9491 |
| 969 | */pagekite-tmp.py* | .{0,1000}\/pagekite\-tmp\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 0 | #linux | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9492 |
| 970 | */PAYMENTS.exe* | .{0,1000}\/PAYMENTS\.exe.{0,1000} | greyware_tool_keyword | _ | suspicious file name - has been used by threat actors | T1566 | TA0001 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9567 |
| 971 | */PCHunter.exe* | .{0,1000}\/PCHunter\.exe.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9569 |
| 972 | */PCHunter_free.zip* | .{0,1000}\/PCHunter_free\.zip.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9570 |
| 973 | */pcictlui.exe* | .{0,1000}\/pcictlui\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9571 |
| 974 | */PCIDEPLY.exe* | .{0,1000}\/PCIDEPLY\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9572 |
| 975 | */PCMonitorManager.exe* | .{0,1000}\/PCMonitorManager\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9573 |
| 976 | */PCMonitorSrv.exe* | .{0,1000}\/PCMonitorSrv\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9574 |
| 977 | */pcmontask.exe* | .{0,1000}\/pcmontask\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9575 |
| 978 | */pcmrdp-client.dll* | .{0,1000}\/pcmrdp\-client\.dll.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9576 |
| 979 | */pcunlocker.iso* | .{0,1000}\/pcunlocker\.iso.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9577 |
| 980 | */pcunlocker_trial.zip* | .{0,1000}\/pcunlocker_trial\.zip.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9578 |
| 981 | */perf stat /bin/sh -p* | .{0,1000}\/perf\sstat\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 9602 |
| 982 | */perl -e 'exec \"/bin/sh\"* | .{0,1000}\/perl\s\-e\s\'exec\s\\\"\/bin\/sh\\\".{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 9607 |
| 983 | */pgrok.exe* | .{0,1000}\/pgrok\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 9651 |
| 984 | */pgrok.git* | .{0,1000}\/pgrok\.git.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9652 |
| 985 | */pgrok.yml* | .{0,1000}\/pgrok\.yml.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 0 | #linux | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9653 |
| 986 | */pgrokd.exe* | .{0,1000}\/pgrokd\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 9654 |
| 987 | */pgrokd.yml | .{0,1000}\/pgrokd\.yml | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 0 | #linux | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9655 |
| 988 | */pgrokd_*.zip* | .{0,1000}\/pgrokd_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9656 |
| 989 | */pingcastle.git* | .{0,1000}\/pingcastle\.git.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9695 |
| 990 | */PingCastle.zip* | .{0,1000}\/PingCastle\.zip.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9696 |
| 991 | */pingcastle/releases/download/* | .{0,1000}\/pingcastle\/releases\/download\/.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9697 |
| 992 | */PortQry.exe* | .{0,1000}\/PortQry\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9748 |
| 993 | */PortQryV2.exe* | .{0,1000}\/PortQryV2\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9749 |
| 994 | */portr.exe* | .{0,1000}\/portr\.exe.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9750 |
| 995 | */portr.git* | .{0,1000}\/portr\.git.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9751 |
| 996 | */portr/releases* | .{0,1000}\/portr\/releases.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9752 |
| 997 | */portr_*_Darwin_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Darwin_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9753 |
| 998 | */portr_*_Darwin_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Darwin_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9754 |
| 999 | */portr_*_Linux_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Linux_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9755 |
| 1000 | */portr_*_Linux_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Linux_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9756 |
| 1001 | */portr_*_Windows_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Windows_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9757 |
| 1002 | */portr_*_Windows_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Windows_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9758 |
| 1003 | */portr_admin/*.py* | .{0,1000}\/portr_admin\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9759 |
| 1004 | */privoxy.exe* | .{0,1000}\/privoxy\.exe.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 9904 |
| 1005 | */Procdump.zip* | .{0,1000}\/Procdump\.zip.{0,1000} | greyware_tool_keyword | Procdump | dump lsass process with procdump | T1003.001 | TA0006 | N/A | LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor | Credential Access | https://learn.microsoft.com/en-us/sysinternals/downloads/procdump | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9907 |
| 1006 | */processhacker-*-bin.zip* | .{0,1000}\/processhacker\-.{0,1000}\-bin\.zip.{0,1000} | greyware_tool_keyword | processhacker | Interactions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injection | T1055.001 - T1055.012 - T1003.001 - T1056.005 | TA0005 - TA0003 - TA0040 - TA0006 - TA0009 | N/A | N/A | Persistence | https://processhacker.sourceforge.io/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 9910 |
| 1007 | */processhacker/files/latest/download* | .{0,1000}\/processhacker\/files\/latest\/download.{0,1000} | greyware_tool_keyword | processhacker | Interactions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injection | T1055.001 - T1055.012 - T1003.001 - T1056.005 | TA0005 - TA0003 - TA0040 - TA0006 - TA0009 | N/A | N/A | Persistence | https://processhacker.sourceforge.io/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 9911 |
| 1008 | */ProduKey.exe* | .{0,1000}\/ProduKey\.exe.{0,1000} | greyware_tool_keyword | produkey | ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer. | T1003.001 - T1003.002 - T1012 - T1057 - T1518 | TA0006 - TA0007 - TA0009 | N/A | Evilnum | Credential Access | https://www.nirsoft.net/utils/product_cd_key_viewer.html | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 9915 |
| 1009 | */Proxifier.app/Contents/MacOS/Proxifier* | .{0,1000}\/Proxifier\.app\/Contents\/MacOS\/Proxifier.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 0 | #macos | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9928 |
| 1010 | */Proxifier.exe* | .{0,1000}\/Proxifier\.exe.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9929 |
| 1011 | */Proxifier/Proxifier.app/* | .{0,1000}\/Proxifier\/Proxifier\.app\/.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 0 | #macos | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9930 |
| 1012 | */ProxifierPE.zip* | .{0,1000}\/ProxifierPE\.zip.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9931 |
| 1013 | */ProxifierSetup.exe* | .{0,1000}\/ProxifierSetup\.exe.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9932 |
| 1014 | */ps2exe.ps1* | .{0,1000}\/ps2exe\.ps1.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 1 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 9952 |
| 1015 | */pslist.exe* | .{0,1000}\/pslist\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9972 |
| 1016 | */pslist64.exe* | .{0,1000}\/pslist64\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9973 |
| 1017 | */pulseway_x64.deb* | .{0,1000}\/pulseway_x64\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10002 |
| 1018 | */Pulseway_x64.msi* | .{0,1000}\/Pulseway_x64\.msi.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10003 |
| 1019 | */pulseway_x86.deb* | .{0,1000}\/pulseway_x86\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10004 |
| 1020 | */pwn_tclsh.me* | .{0,1000}\/pwn_tclsh\.me.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10046 |
| 1021 | */py2exe/* | .{0,1000}\/py2exe\/.{0,1000} | greyware_tool_keyword | py2exe | py2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attacker | T1027.002 - T1045 - T1059.001 - T1587.001 | TA0005 - TA0042 | Operation Wocao | N/A | Resource Development | https://github.com/py2exe/py2exe | 1 | 1 | N/A | greyware_tools high risks of false positives | N/A | 10 | 927 | 102 | 2024-11-12T19:44:34Z | 2019-03-11T13:16:35Z | 10061 |
| 1022 | */pyinstaller/* | .{0,1000}\/pyinstaller\/.{0,1000} | greyware_tool_keyword | pyinstaller | PyInstaller bundles a Python application and all its dependencies into a single package executable. | T1027.002 - T1045 - T1059.001 - T1587.001 | TA0005 - TA0042 | N/A | N/A | Resource Development | https://www.pyinstaller.org/ | 1 | 0 | #linux | greyware_tools high risks of false positives | N/A | N/A | N/A | N/A | N/A | N/A | 10069 |
| 1023 | */pyjam.as/tunnel* | .{0,1000}\/pyjam\.as\/tunnel.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10070 |
| 1024 | */PyPagekite.git* | .{0,1000}\/PyPagekite\.git.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10083 |
| 1025 | */PyPagekite/tarball/* | .{0,1000}\/PyPagekite\/tarball\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10084 |
| 1026 | */PyPagekite/zipball/* | .{0,1000}\/PyPagekite\/zipball\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10085 |
| 1027 | */pyshark.git* | .{0,1000}\/pyshark\.git.{0,1000} | greyware_tool_keyword | pyshark | Python wrapper for tshark allowing python packet parsing using wireshark dissectors | T1040 - T1213 - T1105 - T1572 | TA0009 - TA0007 | N/A | N/A | Discovery | https://github.com/KimiNewt/pyshark | 1 | 1 | N/A | N/A | 6 | 10 | 2355 | 439 | 2024-12-04T15:41:20Z | 2013-12-28T14:38:22Z | 10096 |
| 1028 | */QNAP_NAS/megacmdpkg* | .{0,1000}\/QNAP_NAS\/megacmdpkg.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 10116 |
| 1029 | */Quasar.git* | .{0,1000}\/Quasar\.git.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10125 |
| 1030 | */Quasar.v*.zip* | .{0,1000}\/Quasar\.v.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10126 |
| 1031 | */Quasar/releases* | .{0,1000}\/Quasar\/releases.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10127 |
| 1032 | */Quick Assist Installer.exe* | .{0,1000}\/Quick\sAssist\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 10129 |
| 1033 | */Quick%20Assist%20Installer.exe* | .{0,1000}\/Quick\%20Assist\%20Installer\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 10130 |
| 1034 | */Radmin.exe* | .{0,1000}\/Radmin\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10142 |
| 1035 | */Radmin_Server_*.msi* | .{0,1000}\/Radmin_Server_.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10143 |
| 1036 | */Radmin_Viewer_*.msi* | .{0,1000}\/Radmin_Viewer_.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10144 |
| 1037 | */Radmin_VPN_1.*.exe* | .{0,1000}\/Radmin_VPN_1\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10145 |
| 1038 | */rathole.exe | .{0,1000}\/rathole\.exe | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10168 |
| 1039 | */rathole.git* | .{0,1000}\/rathole\.git.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10169 |
| 1040 | */rathole/src/* | .{0,1000}\/rathole\/src\/.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10170 |
| 1041 | */rathole-aarch64-* | .{0,1000}\/rathole\-aarch64\-.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10171 |
| 1042 | */rathole-arm* | .{0,1000}\/rathole\-arm.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10172 |
| 1043 | */rathole-main/* | .{0,1000}\/rathole\-main\/.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10173 |
| 1044 | */rathole-mipsel-* | .{0,1000}\/rathole\-mipsel\-.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10174 |
| 1045 | */rathole-x86_64* | .{0,1000}\/rathole\-x86_64.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10175 |
| 1046 | */raw/main/speedtest.exe* | .{0,1000}\/raw\/main\/speedtest\.exe.{0,1000} | greyware_tool_keyword | speedtest | legitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration efforts | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | Dispossessor - Dagon Locker | Data Exfiltration | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 10185 | |
| 1047 | */raw/master/speedtest.exe* | .{0,1000}\/raw\/master\/speedtest\.exe.{0,1000} | greyware_tool_keyword | speedtest | legitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration efforts | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | Dispossessor - Dagon Locker | Data Exfiltration | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 10188 | |
| 1048 | */rclone.conf* | .{0,1000}\/rclone\.conf.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10198 |
| 1049 | */rclone.exe* | .{0,1000}\/rclone\.exe.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | N/A | interactive mode | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10199 |
| 1050 | */rclone.git* | .{0,1000}\/rclone\.git.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10200 |
| 1051 | */rclone.rar* | .{0,1000}\/rclone\.rar.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10201 |
| 1052 | */rclone.zip* | .{0,1000}\/rclone\.zip.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10202 |
| 1053 | */rclone/releases/download/* | .{0,1000}\/rclone\/releases\/download\/.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10203 |
| 1054 | */rdpscan --* | .{0,1000}\/rdpscan\s\-\-.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 0 | #linux | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10222 |
| 1055 | */rdpscan.git* | .{0,1000}\/rdpscan\.git.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10223 |
| 1056 | */rdpscan-macos.zip* | .{0,1000}\/rdpscan\-macos\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10224 |
| 1057 | */rdpscan-windows.zip* | .{0,1000}\/rdpscan\-windows\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10225 |
| 1058 | */RDPWInst.exe* | .{0,1000}\/RDPWInst\.exe.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10235 |
| 1059 | */RDPWInst-v*.msi* | .{0,1000}\/RDPWInst\-v.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10236 |
| 1060 | */rdpwrap.dll* | .{0,1000}\/rdpwrap\.dll.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10237 |
| 1061 | */rdpwrap.git* | .{0,1000}\/rdpwrap\.git.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10238 |
| 1062 | */RDPWrap-v*.zip* | .{0,1000}\/RDPWrap\-v.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10239 |
| 1063 | */RealTimeSync.exe* | .{0,1000}\/RealTimeSync\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 10246 |
| 1064 | */RedTeaming-Tactics-and-Techniques.git* | .{0,1000}\/RedTeaming\-Tactics\-and\-Techniques\.git.{0,1000} | greyware_tool_keyword | ired.team | Red Teaming Tactics and Techniques | T1593.003 | TA0043 | N/A | N/A | Reconnaissance | https://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques | 1 | 1 | N/A | N/A | 7 | 10 | 4234 | 1071 | 2024-08-22T07:17:31Z | 2019-03-02T13:33:33Z | 10302 |
| 1065 | */release/gt-win-x86_64.exe* | .{0,1000}\/release\/gt\-win\-x86_64\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 10336 |
| 1066 | */release/sshx-server* | .{0,1000}\/release\/sshx\-server.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 10337 |
| 1067 | */releases/download/Ahk2Exe* | .{0,1000}\/releases\/download\/Ahk2Exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 10339 |
| 1068 | */RemCom.exe* | .{0,1000}\/RemCom\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10352 |
| 1069 | */RemCom.git* | .{0,1000}\/RemCom\.git.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10353 |
| 1070 | */RemComSvc.exe* | .{0,1000}\/RemComSvc\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10354 |
| 1071 | */Remote.It-Installer-* | .{0,1000}\/Remote\.It\-Installer\-.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10356 |
| 1072 | */RemoteControlSetup.exe* | .{0,1000}\/RemoteControlSetup\.exe.{0,1000} | greyware_tool_keyword | ComodoRMM (Itarian RMM) | Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://one.comodo.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10369 |
| 1073 | */RemoteDesktop.exe* | .{0,1000}\/RemoteDesktop\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10370 |
| 1074 | */remoteit.exe* | .{0,1000}\/remoteit\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10373 |
| 1075 | */remoteit.x86-win.exe* | .{0,1000}\/remoteit\.x86\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10374 |
| 1076 | */remoteit/connectd/releases* | .{0,1000}\/remoteit\/connectd\/releases.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 10375 |
| 1077 | */remoteit/desktop* | .{0,1000}\/remoteit\/desktop.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10376 |
| 1078 | */remoteit-desktop.exe* | .{0,1000}\/remoteit\-desktop\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10377 |
| 1079 | */remotemoe.git* | .{0,1000}\/remotemoe\.git.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 10382 |
| 1080 | */remotepc.deb* | .{0,1000}\/remotepc\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10384 |
| 1081 | */remotepc.deb* | .{0,1000}\/remotepc\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10385 |
| 1082 | */RemotePC.exe* | .{0,1000}\/RemotePC\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10386 |
| 1083 | */RemotePC.exe* | .{0,1000}\/RemotePC\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10387 |
| 1084 | */RemotePC.lnk* | .{0,1000}\/RemotePC\.lnk.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10388 |
| 1085 | */RemotePC.tmp* | .{0,1000}\/RemotePC\.tmp.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10389 |
| 1086 | */remotepc-attended.deb* | .{0,1000}\/remotepc\-attended\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10390 |
| 1087 | */RemotePCAttended.dmg* | .{0,1000}\/RemotePCAttended\.dmg.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | #macos | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10391 |
| 1088 | */remotepclauncher.exe* | .{0,1000}\/remotepclauncher\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10392 |
| 1089 | */RemotePCSuite.dmg* | .{0,1000}\/RemotePCSuite\.dmg.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | #macos | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10393 |
| 1090 | */remotepcuiu.exe* | .{0,1000}\/remotepcuiu\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10394 |
| 1091 | */RemotePCViewer.msi* | .{0,1000}\/RemotePCViewer\.msi.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10395 |
| 1092 | */res/rdpwrap.ini* | .{0,1000}\/res\/rdpwrap\.ini.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 0 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10405 |
| 1093 | */rest_client_zrok/* | .{0,1000}\/rest_client_zrok\/.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 0 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 10423 |
| 1094 | */restic-*.tar.gz* | .{0,1000}\/restic\-.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10424 |
| 1095 | */restic.exe* | .{0,1000}\/restic\.exe.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10425 |
| 1096 | */restic/releases/download/* | .{0,1000}\/restic\/releases\/download\/.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10426 |
| 1097 | */restic_*_windows_amd64.zip* | .{0,1000}\/restic_.{0,1000}_windows_amd64\.zip.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10427 |
| 1098 | */restic-master/* | .{0,1000}\/restic\-master\/.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10428 |
| 1099 | */reverse-tunnel.git* | .{0,1000}\/reverse\-tunnel\.git.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10451 |
| 1100 | */reverse-tunnel/agent/cmd* | .{0,1000}\/reverse\-tunnel\/agent\/cmd.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10452 |
| 1101 | */reverse-tunnel/server/service* | .{0,1000}\/reverse\-tunnel\/server\/service.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10453 |
| 1102 | */RevoUninProSetup.exe* | .{0,1000}\/RevoUninProSetup\.exe.{0,1000} | greyware_tool_keyword | RevoUninstaller | legitimate tool abused by the Dispossessor ransomware group | T1562.001 - T1112 - T1059 - T1036 | TA0005 - TA0040 | N/A | Dispossessor | Defense Evasion | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10457 |
| 1103 | */rfusclient.exe* | .{0,1000}\/rfusclient\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10472 |
| 1104 | */rmm/api/tacticalrmm/* | .{0,1000}\/rmm\/api\/tacticalrmm\/.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 10487 |
| 1105 | */rmm-installer.ps1* | .{0,1000}\/rmm\-installer\.ps1.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 10488 |
| 1106 | */root/jprq-server* | .{0,1000}\/root\/jprq\-server.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 0 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 10504 |
| 1107 | */root/tunnel* | .{0,1000}\/root\/tunnel.{0,1000} | greyware_tool_keyword | tunnel.pyjam.as | SSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10510 |
| 1108 | */RpcDND_Console.exe* | .{0,1000}\/RpcDND_Console\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10540 |
| 1109 | */rpcdownloader.exe* | .{0,1000}\/rpcdownloader\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10541 |
| 1110 | */RPCFireWallRule.exe* | .{0,1000}\/RPCFireWallRule\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10545 |
| 1111 | */rpcperfviewer.exe* | .{0,1000}\/rpcperfviewer\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10549 |
| 1112 | */RPCProxyLatency.exe* | .{0,1000}\/RPCProxyLatency\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10550 |
| 1113 | */rserver3.exe* | .{0,1000}\/rserver3\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10554 |
| 1114 | */rsocks.git* | .{0,1000}\/rsocks\.git.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10556 |
| 1115 | */rsocks.git* | .{0,1000}\/rsocks\.git.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | #linux | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 10557 |
| 1116 | */rsocks.toml* | .{0,1000}\/rsocks\.toml.{0,1000} | greyware_tool_keyword | rsocks | A SOCKS 4/5 reverse proxy server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/tonyseek/rsocks | 1 | 0 | #linux | N/A | 10 | 10 | 131 | 13 | 2022-09-20T07:11:29Z | 2015-03-08T22:31:31Z | 10558 |
| 1117 | */rsocks/releases/download/* | .{0,1000}\/rsocks\/releases\/download\/.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10559 |
| 1118 | */rsocks_linux_amd64* | .{0,1000}\/rsocks_linux_amd64.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | #linux | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10560 |
| 1119 | */rsocks_windows_386.exe* | .{0,1000}\/rsocks_windows_386\.exe.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10561 |
| 1120 | */rtun-freebsd-amd64* | .{0,1000}\/rtun\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10580 |
| 1121 | */rtun-linux-amd64* | .{0,1000}\/rtun\-linux\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10581 |
| 1122 | */rtun-linux-arm64* | .{0,1000}\/rtun\-linux\-arm64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10582 |
| 1123 | */rtun-mac-amd64* | .{0,1000}\/rtun\-mac\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10583 |
| 1124 | */rtun-server-freebsd-amd64* | .{0,1000}\/rtun\-server\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10584 |
| 1125 | */rtun-server-linux-amd64* | .{0,1000}\/rtun\-server\-linux\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10585 |
| 1126 | */rtun-server-linux-arm64* | .{0,1000}\/rtun\-server\-linux\-arm64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10586 |
| 1127 | */rtun-server-mac-amd64* | .{0,1000}\/rtun\-server\-mac\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10587 |
| 1128 | */rtun-server-windows-amd64.exe* | .{0,1000}\/rtun\-server\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10588 |
| 1129 | */rtun-windows-amd64.exe* | .{0,1000}\/rtun\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10589 |
| 1130 | */RustDesk.exe* | .{0,1000}\/RustDesk\.exe.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10639 |
| 1131 | */rustdesk.git* | .{0,1000}\/rustdesk\.git.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10640 |
| 1132 | */rustdesk/rustdesk/releases/* | .{0,1000}\/rustdesk\/rustdesk\/releases\/.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10641 |
| 1133 | */rutserv.exe* | .{0,1000}\/rutserv\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10649 |
| 1134 | */rutview.exe* | .{0,1000}\/rutview\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10650 |
| 1135 | */rvim -c ':py3 import os*os.execl(\"/bin/sh\* | .{0,1000}\/rvim\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10651 |
| 1136 | */s4n7h0/NSE* | .{0,1000}\/s4n7h0\/NSE.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 0 | #linux | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 10658 |
| 1137 | */sbin/dropbear* | .{0,1000}\/sbin\/dropbear.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 0 | #linux | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 10696 |
| 1138 | */sdelete.exe* | .{0,1000}\/sdelete\.exe.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10747 |
| 1139 | */SDelete.zip* | .{0,1000}\/SDelete\.zip.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10748 |
| 1140 | */sdelete64.exe* | .{0,1000}\/sdelete64\.exe.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10749 |
| 1141 | */sdelete64a.exe* | .{0,1000}\/sdelete64a\.exe.{0,1000} | greyware_tool_keyword | sdelete | delete one or more files and/or directories, or to cleanse the free space on a logical disk - abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10750 |
| 1142 | */send.exploit.in/* | .{0,1000}\/send\.exploit\.in\/.{0,1000} | greyware_tool_keyword | send.exploit.in | file-sharing platform used by ransomware groups | T1567 | TA0010 | N/A | Black Basta | Data Exfiltration | https://www.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10784 |
| 1143 | */SetACL.exe* | .{0,1000}\/SetACL\.exe.{0,1000} | greyware_tool_keyword | SetACL | Manage Windows permissions from the command line | T1069 - T1222 | TA0002 - TA0004 - TA0005 | N/A | N/A | Defense Evasion | https://helgeklein.com/download/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10810 |
| 1144 | */SetACL64..exe* | .{0,1000}\/SetACL64\.\.exe.{0,1000} | greyware_tool_keyword | SetACL | Manage Windows permissions from the command line | T1069 - T1222 | TA0002 - TA0004 - TA0005 | N/A | N/A | Defense Evasion | https://helgeklein.com/download/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10811 |
| 1145 | */set-proxy.ps1* | .{0,1000}\/set\-proxy\.ps1.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 10814 |
| 1146 | */sftp *@*:* | .{0,1000}/sftp\s.{0,1000}\@.{0,1000}\:.{0,1000} | greyware_tool_keyword | sftp | Detects the use of tools that copy files from or to remote systems | T1041 - T1105 - T1106 | TA0002 - TA0008 - TA0010 | N/A | Black Basta | Data Exfiltration | https://attack.mitre.org/techniques/T1105/ | 1 | 0 | #linux | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 10819 |
| 1147 | */sftp *get*.wallet* | .{0,1000}sftp.*get.*(\.pem|\.key|\.wallet)\b.{0,1000} | greyware_tool_keyword | sftp | sftp transfers of sensitive files | T1041 - T1105 - T1106 | TA0002 - TA0008 - TA0010 | N/A | N/A | Data Exfiltration | https://attack.mitre.org/techniques/T1105/ | 1 | 0 | #linux | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 10820 |
| 1148 | */sftp *put*.tar.gz* | .{0,1000}sftp\s.*put.*(\.tar\.gz|\.zip|\.rar|\.7z)\b.{0,1000} | greyware_tool_keyword | sftp | sftp archive transfers | T1041 - T1105 - T1106 | TA0002 - TA0008 - TA0010 | N/A | N/A | Data Exfiltration | https://attack.mitre.org/techniques/T1105/ | 1 | 0 | #linux | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 10821 |
| 1149 | */Shadowsocks-*.zip* | .{0,1000}\/Shadowsocks\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10839 |
| 1150 | */Shadowsocks.zip* | .{0,1000}\/Shadowsocks\.zip.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10840 |
| 1151 | */shadowsocks_service.* | .{0,1000}\/shadowsocks_service\..{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | #linux | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10841 |
| 1152 | */shadowsocks-manager.sock* | .{0,1000}\/shadowsocks\-manager\.sock.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 0 | #linux | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10842 |
| 1153 | */shadowsocks-rust.default* | .{0,1000}\/shadowsocks\-rust\.default.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10843 |
| 1154 | */shadowsocks-rust.git* | .{0,1000}\/shadowsocks\-rust\.git.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10844 |
| 1155 | */shadowsocks-rust.init* | .{0,1000}\/shadowsocks\-rust\.init.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10845 |
| 1156 | */shadowsocks-rust.service* | .{0,1000}\/shadowsocks\-rust\.service.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10846 |
| 1157 | */shadowsocks-service* | .{0,1000}\/shadowsocks\-service.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10847 |
| 1158 | */shadowsocks-windows.git* | .{0,1000}\/shadowsocks\-windows\.git.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10848 |
| 1159 | */simplehelper64.exe* | .{0,1000}\/simplehelper64\.exe.{0,1000} | greyware_tool_keyword | SimpleHelp | SimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackCat | RMM | simple-help.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11275 |
| 1160 | */SirTunnel.git* | .{0,1000}\/SirTunnel\.git.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 11296 |
| 1161 | */sirtunnel.py* | .{0,1000}\/sirtunnel\.py.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 11297 |
| 1162 | */sish.git* | .{0,1000}\/sish\.git.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 1 | N/A | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 11299 |
| 1163 | */sish.log* | .{0,1000}\/sish\.log.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 0 | #linux | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 11300 |
| 1164 | */sish/cmd/* | .{0,1000}\/sish\/cmd\/.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 0 | #linux | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 11301 |
| 1165 | */SoftEtherVPN-*.tar.xz* | .{0,1000}\/SoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11494 |
| 1166 | */SoftEtherVPN.git* | .{0,1000}\/SoftEtherVPN\.git.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | abused https://asec.ahnlab.com/en/66843/ | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11495 |
| 1167 | */SoftEtherVPN/releases/tag/* | .{0,1000}\/SoftEtherVPN\/releases\/tag\/.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11496 |
| 1168 | */softether-vpnclient-*.exe* | .{0,1000}\/softether\-vpnclient\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11497 |
| 1169 | */softether-vpnserver-*.deb* | .{0,1000}\/softether\-vpnserver\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11498 |
| 1170 | */softether-vpnserver.service* | .{0,1000}\/softether\-vpnserver\.service.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 0 | #VPN #linux | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11499 |
| 1171 | */softether-vpnserver_*.exe* | .{0,1000}\/softether\-vpnserver_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11500 |
| 1172 | */SolarWinds-Dameware-DRS-St.exe* | .{0,1000}\/SolarWinds\-Dameware\-DRS\-St\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | Dameware Remote Support | 10 | 10 | N/A | N/A | N/A | N/A | 11502 |
| 1173 | */sources.list.d/tailscale.list* | .{0,1000}\/sources\.list\.d\/tailscale\.list.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11506 |
| 1174 | */spacerunner.exe* | .{0,1000}\/spacerunner\.exe.{0,1000} | greyware_tool_keyword | SpaceRunner | enables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace. | T1059.001 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/Mr-B0b/SpaceRunner | 1 | 0 | N/A | N/A | 7 | 2 | 195 | 38 | 2020-07-26T10:39:53Z | 2020-07-26T09:31:09Z | 11507 |
| 1175 | */SplashtopStreamer/SPLog.txt* | .{0,1000}\/SplashtopStreamer\/SPLog\.txt.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://ruler-project.github.io/ruler-project/RULER/remote/Splashtop/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11528 |
| 1176 | */src/expose serve * | .{0,1000}\/src\/expose\sserve\s.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 0 | #linux | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 11586 |
| 1177 | */sshpass /bin/sh -p* | .{0,1000}\/sshpass\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 11611 |
| 1178 | */sshtunnel -* | .{0,1000}\/sshtunnel\s\-.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 0 | #linux | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11616 |
| 1179 | */sshtunnel.git* | .{0,1000}\/sshtunnel\.git.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11617 |
| 1180 | */sshtunnel.py* | .{0,1000}\/sshtunnel\.py.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11618 |
| 1181 | */sshtunnel/tarball/* | .{0,1000}\/sshtunnel\/tarball\/.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11619 |
| 1182 | */sshtunnel/zipball/* | .{0,1000}\/sshtunnel\/zipball\/.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11620 |
| 1183 | */sshuttle.git* | .{0,1000}\/sshuttle\.git.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11621 |
| 1184 | */sshuttle.py* | .{0,1000}\/sshuttle\.py.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11622 |
| 1185 | */sshuttle/tarball* | .{0,1000}\/sshuttle\/tarball.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11623 |
| 1186 | */sshuttle/zipball* | .{0,1000}\/sshuttle\/zipball.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11624 |
| 1187 | */sshx-server/* | .{0,1000}\/sshx\-server\/.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 11626 |
| 1188 | */stdbuf -i0 /bin/sh -p* | .{0,1000}\/stdbuf\s\-i0\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 11666 |
| 1189 | */stunnel-*.tar.gz* | .{0,1000}\/stunnel\-.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 0 | #linux | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11691 |
| 1190 | */stunnel-latest.tar.gz* | .{0,1000}\/stunnel\-latest\.tar\.gz.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11692 |
| 1191 | */stunnel-latest-android.zip* | .{0,1000}\/stunnel\-latest\-android\.zip.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11693 |
| 1192 | */stunnel-latest-win64-installer.exe* | .{0,1000}\/stunnel\-latest\-win64\-installer\.exe.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11694 |
| 1193 | */suo5.git* | .{0,1000}\/suo5\.git.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11718 |
| The file is too large to be shown. View Raw |