Files
mthcht-ThreatHunting-Keywords/greyware_tool_keyword_endpoint_detection.csv
2025-08-04 02:33:52 +02:00

6.5 MiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* $domain sirtunnel $domain $serverPort*.{0,1000}\s\$domain\ssirtunnel\s\$domain\s\$serverPort.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel10N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z16
3* ,exec(__import__('base64').b64decode("*.{0,1000}\s,exec\(__import__\(\'base64\'\)\.b64decode\(\".{0,1000}greyware_tool_keywordpythonsuspicious way of exeuting codeT1059TA0005pytoileurN/ADefense Evasionhttps://x.com/Ax_Sharma/status/1795813203500322953/photo/410N/ACool package campaign810N/AN/AN/AN/A22
4* ./level-darwin-bundle-amd64.pkg*.{0,1000}\s\.\/level\-darwin\-bundle\-amd64\.pkg.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10#linuxN/A1010N/AN/AN/AN/A23
5* ./level-linux-amd64 *.{0,1000}\s\.\/level\-linux\-amd64\s.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10#linuxN/A1010N/AN/AN/AN/A24
6* ./level-linux-arm64 *.{0,1000}\s\.\/level\-linux\-arm64\s.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10#linuxN/A1010N/AN/AN/AN/A25
7* /bin/nc * -e /bin/bash* > cron && crontab cron*.{0,1000}\s\/bin\/nc\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\s\>\scron\s\&\&\scrontab\scron.{0,1000}greyware_tool_keywordncLinux Persistence Shell cronT1053 - T1037TA0003N/ACalypso - GALLIUMPersistencehttps://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md10#linuxN/A101015941982025-04-16T21:16:51Z2021-08-16T17:34:25Z38
8* /bin/nc * -e /bin/bash*> * crontab cron*.{0,1000}\s\/bin\/nc\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\>\s.{0,1000}\scrontab\scron.{0,1000}greyware_tool_keywordnclinux commands abused by attackersT1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002N/ACalypso - GALLIUMExploitation toolN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A39
9* /c echo mar3pora *.{0,1000}\s\/c\secho\smar3pora\s.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A41
10* /c echo Pa$$w0rd | C:\ProgramData\anydesk.exe*.{0,1000}\s\/c\secho\sPa\$\$w0rd\s\|\sC\:\\ProgramData\\anydesk\.exe.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A42
11* /c sc query WinDefend*.{0,1000}\s\/c\ssc\squery\sWinDefend.{0,1000}greyware_tool_keywordscGet information about Windows Defender serviceT1518.001 - T1049TA0007 - TA0009N/ASnatchDiscoveryhttps://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/10N/AN/A810N/AN/AN/AN/A44
12* /c start /min powershell -noprofile -w H -c *irw*.{0,1000}\s\/c\sstart\s\/min\spowershell\s\-noprofile\s\-w\sH\s\-c\s.{0,1000}irw.{0,1000}greyware_tool_keywordpowershellSuspicious PowerShell execution behavior often observed in FakeCaptcha phishing attemptsT1059.001 - T1027 - T1564.003TA0005 - TA0002 - TA0009N/AN/ACollectionhttps://x.com/malware_traffic/status/1884476331821326816/photo/210N/AN/A76N/AN/AN/AN/A45
13* /config:netscan.xml *.{0,1000}\s\/config\:netscan\.xml\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A51
14* /Create /RU SYSTEM /TN MicrosoftEdgeUpdateTaskMachine /TR *.{0,1000}\s\/Create\s\/RU\sSYSTEM\s\/TN\sMicrosoftEdgeUpdateTaskMachine\s\/TR\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A52
15* /create /tn "SysChecks" /tr c:\temp\sch.bat *.{0,1000}\s\/create\s\/tn\s\"SysChecks\"\s\/tr\sc\:\\temp\\sch\.bat\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A54
16* /Create /TN sch.bat /TR "c:\temp\script.vbs" *.{0,1000}\s\/Create\s\/TN\ssch\.bat\s\/TR\s\"c\:\\temp\\script\.vbs\"\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A56
17* /EV"NetSupport School"*.{0,1000}\s\/EV\"NetSupport\sSchool\".{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/10N/AN/A1010N/AN/AN/AN/A66
18* /f /im RemotePCS*.{0,1000}\s\/f\s\/im\sRemotePCS.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A67
19* /F /TN "Level\Level Watchdog"*.{0,1000}\s\/F\s\/TN\s\"Level\\Level\sWatchdog\".{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10N/AN/A1010N/AN/AN/AN/A68
20* /monitor /from_service /cpu_memory_refresh * /disk_space_refresh * /proc_list_refresh * /semkey *.{0,1000}\s\/monitor\s\/from_service\s\/cpu_memory_refresh\s.{0,1000}\s\/disk_space_refresh\s.{0,1000}\s\/proc_list_refresh\s.{0,1000}\s\/semkey\s.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/AN/A1010N/AN/AN/AN/A81
21* /r /proxy /proxyport /proxyusername /proxypasswd *.{0,1000}\s\/r\s\/proxy\s\s\/proxyport\s\s\/proxyusername\s\s\/proxypasswd\s.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10#linuxN/A1010N/AN/AN/AN/A93
22* /register /proxy /proxyport /proxyusername /proxypasswd*.{0,1000}\s\/register\s\s\/proxy\s\s\/proxyport\s\s\/proxyusername\s\s\/proxypasswd.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10#linuxN/A1010N/AN/AN/AN/A95
23* /usr/local/bin/expose*.{0,1000}\s\/usr\/local\/bin\/expose.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose10#linuxN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z114
24* /v "DisableAntiSpyware" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableAntiSpyware\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A115
25* /v "DisableAntiVirus" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableAntiVirus\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A116
26* /v "DisableIOAVProtection" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableIOAVProtection\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A117
27* /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableOnAccessProtection\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A118
28* /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableRealtimeMonitoring\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A119
29* /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f*.{0,1000}\s\/v\s\"DisableScanOnRealtimeEnable\"\s\/t\sREG_DWORD\s\/d\s\"1\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A120
30* /v "MpEnablePus" /t REG_DWORD /d "0" /f*.{0,1000}\s\/v\s\"MpEnablePus\"\s\/t\sREG_DWORD\s\/d\s\"0\"\s\/f.{0,1000}greyware_tool_keywordregdisable protection features of Windows DefenderT1562.001 - T1112 TA0005N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaDefense Evasionhttps://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/#c0110#registryN/A1010N/AN/AN/AN/A121
31* /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f*.{0,1000}\s\/v\sDisableRealtimeMonitoring\s\/t\sREG_DWORD\s\/d\s1\s\/f.{0,1000}greyware_tool_keywordregreg command used to disabled real time monitoring defender - often abused by attackersT1562.001 - T1112 - T1059 - T1036TA0005 - TA0040N/ADispossessorDefense Evasionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10#registryN/A1010N/AN/AN/AN/A126
32* /var/log -type f -exec */tr* -s 0 {} \*.{0,1000}\/\?\?\?\/\?\?\?\/f\?n\?\s\/var\/log\s\-type\sf\s\-exec\s\/\?\?\?\/\?\?\?\/tr\?\?\?\?\?e\s\-s\s0\s\{\}\s\\.{0,1000}greyware_tool_keywordfindtruncate every file under /var/log to size 0 - no log content = no forensic.T1486 - T1553 - T1592.002 - T1081TA0005 - TA0007 - TA0009N/AN/ADefense EvasionN/A10#linuxN/A1010N/AN/AN/AN/A128
33* \\\\localhost /user:Username /pwd:Password \"C:\\InstallMe.bat*.{0,1000}\s\\\\\\\\localhost\s\/user\:Username\s\/pwd\:Password\s\s\\\"C\:\\\\InstallMe\.bat.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom10N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z131
34* | clbin*.{0,1000}\s\|\sclbin.{0,1000}greyware_tool_keywordclbin.comclbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands.T1567.002TA0010 - TA0009N/AN/AData Exfiltrationhttps://clbin.com/10#PastebinLikeN/A88N/AN/AN/AN/A134
35* <Data>Received Request Run command *</Data>*.{0,1000}\s\<Data\>Received\sRequest\sRun\scommand\s.{0,1000}\<\/Data\>.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A138
36* > /var/log/syslog*.{0,1000}\s\>\s\/var\/log\/syslog.{0,1000}greyware_tool_keywordbashIndicator Removal on Host - clearing logsT1070.002TA0005N/AN/ADefense Evasionhttps://github.com/mthcht/atomic-red-team/blob/master/atomics/T1070.002/T1070.002.md10#linuxN/A101002025-03-01T22:20:20Z2025-03-01T21:01:46Z143
37* >/var/log/syslog*.{0,1000}\s\>\/var\/log\/syslog.{0,1000}greyware_tool_keywordbashIndicator Removal on Host - clearing logsT1070.002TA0005N/AN/ADefense Evasionhttps://github.com/mthcht/atomic-red-team/blob/master/atomics/T1070.002/T1070.002.md10#linuxN/A101002025-03-01T22:20:20Z2025-03-01T21:01:46Z150
38* -a tcrmtshellagentmodule_*.{0,1000}\s\-a\stcrmtshellagentmodule_.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/ADameware Remote Support1010N/AN/AN/AN/A174
39* a.pinggy.io*.{0,1000}\sa\.pinggy\.io.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/10N/AN/A1010N/AN/AN/AN/A175
40* -accepteula -nobanner -d cmd.exe /c *.{0,1000}\s\-accepteula\s\-nobanner\s\-d\scmd\.exe\s\/c\s.{0,1000}greyware_tool_keywordpsexecAdversaries may place the PsExec executable in the temp directory and execute it from there as part of their offensive activities. By doing so. they can leverage PsExec to execute commands or launch processes on remote systems. enabling Lateral Movement. privilege escalation. or the execution of malicious payloads.T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0008 - TA0009 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorLateral Movementhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A178
41* adaudit.ps1*.{0,1000}\sadaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z201
42* admin create frontend sqJRAINSiB public *.{0,1000}\sadmin\screate\sfrontend\ssqJRAINSiB\spublic\s.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z231
43* ADRecon.ps1*.{0,1000}\sADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z239
44* advfirewall firewall add rule * dir=in protocol=tcp localport=3389 action=allow*.{0,1000}\sadvfirewall\sfirewall\sadd\srule\s.{0,1000}\sdir\=in\sprotocol\=tcp\slocalport\=3389\saction\=allow.{0,1000}greyware_tool_keywordnetshOpens port 3389 for RDP inbound access through the firewallT1021.001 - T1562.004 TA0008 - TA0005N/AN/ALateral MovementN/A10N/AN/A88N/AN/AN/AN/A240
45* aeroadmin.exe*.{0,1000}\saeroadmin\.exe.{0,1000}greyware_tool_keywordaeroadminRMM software - full remote control / file transferT1021.001 - T1048.003TA0008 - TA0011 - TA0009 - TA0010N/AN/ARMMhttps://ulm.aeroadmin.com/AeroAdmin.exe10N/AN/A1010N/AN/AN/AN/A241
46* Ahk2Exe.exe*.{0,1000}\sAhk2Exe\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe10N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z250
47* -altgw *.zohoassist.com *.{0,1000}\s\-altgw\s.{0,1000}\.zohoassist\.com\s.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A260
48* --bin sshx-server*.{0,1000}\s\-\-bin\ssshx\-server.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx10N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z390
49* boringproxy-client.service*.{0,1000}\sboringproxy\-client\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z425
50* boringproxy-server.service*.{0,1000}\sboringproxy\-server\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z426
51* -c 'import pty;pty.spawn("/bin/bash*.{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\"\/bin\/bash.{0,1000}greyware_tool_keywordpythoninteractive shellT1059TA0002 - TA0011N/AN/AC2N/A10#linuxgreyware_tools high risks of false positives610N/AN/AN/AN/A505
52* -c 'import pty;pty.spawn("/bin/sh*.{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\"\/bin\/sh.{0,1000}greyware_tool_keywordpythoninteractive shellT1059TA0002 - TA0011N/AN/AC2N/A10#linuxgreyware_tools high risks of false positives610N/AN/AN/AN/A507
53* -c 'import pty;pty.spawn(\"/bin/sh*.{0,1000}\s\-c\s\'import\spty\;pty\.spawn\(\\\"\/bin\/sh.{0,1000}greyware_tool_keywordpythoninteractive shellT1059TA0002 - TA0011N/AN/AC2N/A10#linuxgreyware_tools high risks of false positives64N/AN/AN/AN/A508
54* -c rest_client_zrok -t*.{0,1000}\s\-c\srest_client_zrok\s\-t.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z512
55* -c1 * --data-string * --icmp *.{0,1000}\s\-c1\s.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-\-icmp\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A524
56* -c1 * --icmp * --data-string *.{0,1000}\s\-c1\s.{0,1000}\s\-\-icmp\s.{0,1000}\s\-\-data\-string\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A525
57* c3pool_miner*.{0,1000}\sc3pool_miner.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/10N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z531
58* chrome-remote-desktop@*.{0,1000}\schrome\-remote\-desktop\@.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com10N/AN/A1010N/AN/AN/AN/A578
59* CN=Quasar Server CA*.{0,1000}\sCN\=Quasar\sServer\sCA.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar10#contentN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z621
60* --coin *--nicehash *.{0,1000}\s\-\-coin\s.{0,1000}\-\-nicehash\s.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/10N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z633
61* --coin=monero*.{0,1000}\s\-\-coin\=monero.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/10N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z634
62* --config=*c3pool*config_background.json*.{0,1000}\s\-\-config\=.{0,1000}c3pool.{0,1000}config_background\.json.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/10N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z675
63* Connection #*. Connection to "*" established. Mode: <Remote control>.*.{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\sestablished\.\sMode\:\s\<Remote\scontrol\>\..{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/10#contentN/A1010N/AN/AN/AN/A686
64* Connection #*. Connection to "*". Security check - OK. Mode: <Inventory manager>*.{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\.\sSecurity\scheck\s\-\sOK\.\sMode\:\s\s\<Inventory\smanager\>.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/10#contentN/A1010N/AN/AN/AN/A687
65* Connection #*. Connection to "*". Security check - OK. Mode: <Command (command: *)>.{0,1000}\sConnection\s\#.{0,1000}\.\sConnection\sto\s\".{0,1000}\"\.\sSecurity\scheck\s\-\sOK\.\sMode\:\s\<Command\s\(command\:\s.{0,1000}\)\>greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/10#contentN/A1010N/AN/AN/AN/A688
66* Connection #*. Direct connection to * (*:5650).*.{0,1000}\sConnection\s\#.{0,1000}\.\sDirect\sconnection\sto\s.{0,1000}\s\(.{0,1000}\:5650\)\..{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/10#contentN/A1010N/AN/AN/AN/A689
67* create RPCService start=*.{0,1000}\screate\sRPCService\sstart\=.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A725
68* create ViewerService start=auto*.{0,1000}\screate\sViewerService\sstart\=auto.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A726
69* croc-entrypoint.sh*.{0,1000}\scroc\-entrypoint\.sh.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc10#linuxN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z739
70* -csrc C:\\Windows\\notepad.exe -c cmd.exe*.{0,1000}\s\-csrc\sC\:\\\\Windows\\\\notepad\.exe\s\-c\scmd\.exe.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec10N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z746
71* Dameware Mini Remote Control x64 -- Installation completed successfully*.{0,1000}\sDameware\sMini\sRemote\sControl\sx64\s\-\-\sInstallation\scompleted\ssuccessfully.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/ADameware Remote Support1010N/AN/AN/AN/A776
72* --data-string * -c1 * --icmp *.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-c1\s.{0,1000}\s\-\-icmp\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A781
73* --data-string * --icmp * -c1 *.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-\-icmp\s.{0,1000}\s\-c1\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A782
74* dclist *.{0,1000}\sdclist\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/10N/AN/A1010N/AN/AN/AN/A796
75* del C:\Windows\temp\1 /F /Q*.{0,1000}\sdel\sC\:\\Windows\\temp\\1\s\/F\s\/Q.{0,1000}greyware_tool_keyworddelsuspicious deletion made by the Russian Foreign Intelligence ServiceT1059.003TA0005N/AN/ADefense Evasionhttps://github.com/mthcht/ThreatIntel-Reports10N/AN/A8210992025-04-22T03:37:27Z2024-10-23T11:27:13Z814
76* denied AXFR from *.{0,1000}\sdenied\sAXFR\sfrom\s.{0,1000}greyware_tool_keyworddnsDetects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attemptsT1071.004 - T1078.004TA0011 - TA0006N/AN/AExploitation toolhttps://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml10N/Agreyware tool - risks of False positive !N/A10469210512025-01-22T01:58:36Z2013-09-17T17:07:58Z824
77* dir /s */ Microsoft.ActiveDirectory.Management.dll*.{0,1000}\sdir\s\/s\s.{0,1000}\/\sMicrosoft\.ActiveDirectory\.Management\.dll.{0,1000}greyware_tool_keyworddirthreat actors searched for Active Directory related DLLs in directoriesT1059 - T1083 - T1018TA0002 - TA0009 - TA0040N/AN/ADiscoveryhttps://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/10N/AN/AN/AN/AN/AN/AN/AN/A844
78* --donate-level=*.{0,1000}\s\-\-donate\-level\=.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/10N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z922
79* --doNotTestSMBv1*.{0,1000}\s\-\-doNotTestSMBv1.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z924
80* downloads.level.io*.{0,1000}\sdownloads\.level\.io.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10N/AN/A1010N/AN/AN/AN/A945
81* DownloadServer=https://www.gotomypc.com *.{0,1000}\sDownloadServer\=https\:\/\/www\.gotomypc\.com\s.{0,1000}greyware_tool_keywordGoToMyPCGoToMyPC is remote desktop software that allows users to access computers remotely using a web browserT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AN/ARMMhttps://www.gotomypc.com/10N/AN/A1010N/AN/AN/AN/A946
82* dropping source port zero packet from *.{0,1000}\sdropping\ssource\sport\szero\spacket\sfrom\s.{0,1000}greyware_tool_keyworddnsDetects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attemptsT1071.004 - T1078.004TA0011 - TA0006N/AN/AExploitation toolhttps://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml10N/Agreyware tool - risks of False positive !N/A10469210512025-01-22T01:58:36Z2013-09-17T17:07:58Z967
83* DumpS1.ps1*.{0,1000}\sDumpS1\.ps1.{0,1000}greyware_tool_keywordSentinelAgentdump a process with SentinelAgent.exeT1003 - T1055TA0006 - TA0005N/AN/ACredential Accesshttps://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e10N/AN/A87N/AN/AN/AN/A1004
84* ecivreS-potS*.{0,1000}\secivreS\-potS.{0,1000}greyware_tool_keyword_reversed string for obfuscationT1027TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A1019
85* -ep Bypass -nop function *[System.Security.Cryptography.Aes]::Create()*.CreateDecryptor()*.TransformFinalBlock*[System.Text.Encoding]::Utf8.GetString*.{0,1000}\s\-ep\sBypass\-nop\sfunction\s.{0,1000}\[System\.Security\.Cryptography\.Aes\]\:\:Create\(\).{0,1000}\.CreateDecryptor\(\).{0,1000}\.TransformFinalBlock.{0,1000}\[System\.Text\.Encoding\]\:\:Utf8\.GetString.{0,1000}greyware_tool_keywordpowershellobfuscation techniques with powershellT1059.001 - T1027TA0002 - TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A1067
86* -ep Unrestricted -nop function *[System.Security.Cryptography.Aes]::Create()*.CreateDecryptor()*.TransformFinalBlock*[System.Text.Encoding]::Utf8.GetString*.{0,1000}\s\-ep\sUnrestricted\s\-nop\sfunction\s.{0,1000}\[System\.Security\.Cryptography\.Aes\]\:\:Create\(\).{0,1000}\.CreateDecryptor\(\).{0,1000}\.TransformFinalBlock.{0,1000}\[System\.Text\.Encoding\]\:\:Utf8\.GetString.{0,1000}greyware_tool_keywordpowershellobfuscation techniques with powershellT1059.001 - T1027TA0002 - TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A1068
87* erase /quiet /method=* data dir=*.{0,1000}\serase\s\/quiet\s\/method\=.{0,1000}\sdata\sdir\=.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser10N/AN/A710N/AN/AN/AN/A1071
88* erase /quiet /methodName=* data dir=*.{0,1000}\serase\s\/quiet\s\/methodName\=.{0,1000}\sdata\sdir\=.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser10N/AN/A710N/AN/AN/AN/A1072
89* -exec bypass -nop -c whoami*.{0,1000}\s\-exec\sbypass\s\-nop\s\-c\swhoami.{0,1000}greyware_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0007N/ABlack BastaDiscoveryN/A10N/AN/A910N/AN/AN/AN/A1101
90* exiting (due to fatal error)*.{0,1000}\sexiting\s\(due\sto\sfatal\serror\).{0,1000}greyware_tool_keyworddnsDetects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attemptsT1071.004 - T1078.004TA0011 - TA0006N/AN/AExploitation toolhttps://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml10N/Agreyware tool - risks of False positive !N/A10469210512025-01-22T01:58:36Z2013-09-17T17:07:58Z1131
91* -f "(objectcategory=computer)" -s subtree dn operatingSystem*.{0,1000}\s\-f\s\"\(objectcategory\=computer\)\"\s\-s\ssubtree\sdn\soperatingSystem.{0,1000}greyware_tool_keywordadfindEnumerate All Computers in the DomainT1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1143
92* -f "(objectcategory=person)" -s subtree samaccountname userPrincipalName*.{0,1000}\s\-f\s\"\(objectcategory\=person\)\"\s\-s\ssubtree\ssamaccountname\suserPrincipalName.{0,1000}greyware_tool_keywordadfindEnumerate All Users in the DomainT1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1144
93* -f "(objectcategory=trustedDomain)" -s subtree name trustAttributes trustDirection trustType*.{0,1000}\s\-f\s\"\(objectcategory\=trustedDomain\)\"\s\-s\ssubtree\sname\strustAttributes\strustDirection\strustType.{0,1000}greyware_tool_keywordadfindDump All Domain TrustsT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1145
94* -f *.dmp windows.cmdline*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.cmdline.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1148
95* -f *.dmp windows.dlllist --pid *.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.dlllist\s\-\-pid\s.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1149
96* -f *.dmp windows.filescan*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.filescan.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1150
97* -f *.dmp windows.handles --pid *.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.handles\s\-\-pid\s.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1151
98* -f *.dmp windows.info*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.info.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1152
99* -f *.dmp windows.malfind*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.malfind.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1153
100* -f *.dmp windows.netscan*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.netscan.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1154
101* -f *.dmp windows.netstat*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.netstat.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1155
102* -f *.dmp windows.pslist*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.pslist.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1156
103* -f *.dmp windows.psscan*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.psscan.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1157
104* -f *.dmp windows.pstree*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.pstree.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1158
105* -f *.dmp windows.registry.hivelist*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.hivelist.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1159
106* -f *.dmp windows.registry.hivescan*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.hivescan.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1160
107* -f *.dmp windows.registry.printkey*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.printkey.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1161
108* -f *.dmp windows.registry.printkey*Software\Microsoft\Windows\CurrentVersion*.{0,1000}\s\-f\s.{0,1000}\.dmp\swindows\.registry\.printkey.{0,1000}Software\\Microsoft\\Windows\\CurrentVersion.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10#registryN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1162
109* Get-AVStatus.ps1*.{0,1000}\sGet\-AVStatus\.ps1.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill10N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z1315
110* gifnoc cs*.{0,1000}\sgifnoc\scs.{0,1000}greyware_tool_keyword_reversed string for obfuscationT1027TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A1340
111* gost.tar.gz*.{0,1000}\sgost\.tar\.gz.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost10N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z1363
112* gost/cmd/gost*.{0,1000}\sgost\/cmd\/gost.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost10N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z1364
113* gotoopener://launch.getgo.com/*.{0,1000}\sgotoopener\:\/\/launch\.getgo\.com\/.{0,1000}greyware_tool_keywordGoToMyPCGoToMyPC is remote desktop software that allows users to access computers remotely using a web browserT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AN/ARMMhttps://www.gotomypc.com/10N/AN/A1010N/AN/AN/AN/A1366
114* gt-win-x86_64.exe*.{0,1000}\sgt\-win\-x86_64\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt10N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z1396
115* host -p * --allow-anonymous --protocol https*.{0,1000}\shost\s\-p\s.{0,1000}\s\-\-allow\-anonymous\s\-\-protocol\shttps.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview10N/AN/A810N/AN/AN/AN/A1432
116* host -p 443 -allow-anonymous*.{0,1000}\shost\s\-p\s443\s\-allow\-anonymous.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview10N/AN/A810N/AN/AN/AN/A1433
117* hostPath="c:\" writable="true" autoMount="true"*.{0,1000}\shostPath\=\"c\:\\\"\swritable\=\"true\"\sautoMount\=\"true\".{0,1000}greyware_tool_keywordVirtualBoxadding the entire C drive as a shared folder for a VMT1021.001 - T1137 - T1072TA0006 - TA0008 - TA0005N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A1010N/AN/AN/AN/A1440
118* http-put-server.py*.{0,1000}\shttp\-put\-server\.py.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10N/AN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z1525
119* -i remotepc.deb*.{0,1000}\s\-i\sremotepc\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A1599
120* --icmp * -c1 * --data-string *.{0,1000}\s\-\-icmp\s.{0,1000}\s\-c1\s.{0,1000}\s\-\-data\-string\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A1608
121* --icmp * --data-string * -c1 *.{0,1000}\s\-\-icmp\s.{0,1000}\s\-\-data\-string\s.{0,1000}\s\-c1\s.{0,1000}greyware_tool_keywordnpingicmp exfiltration with nping (comes with nmap)T1041 - T1095TA0010 - TA0011N/AN/AData Exfiltrationhttp://nmap.org/nping/10N/AN/A79N/AN/AN/AN/A1609
122* install bore-cli*.{0,1000}\sinstall\sbore\-cli.{0,1000}greyware_tool_keywordborebore is a simple CLI tool for making tunnels to localhostT1090 - T1090.003 - T1572 - T1572.001TA0042 - TA0011N/AN/AData Exfiltrationhttps://github.com/ekzhang/bore10N/AN/A101096344102025-04-14T21:52:18Z2022-04-04T02:47:54Z1678
123* install -c conda-forge sshtunnel*.{0,1000}\sinstall\s\-c\sconda\-forge\ssshtunnel.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel10N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z1679
124* install c3pool_miner *.{0,1000}\sinstall\sc3pool_miner\s.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/10N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z1680
125* install localtunnel*.{0,1000}\sinstall\slocaltunnel.{0,1000}greyware_tool_keywordlocaltunnelsclient for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/localtunnel10N/AN/A8102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z1694
126* install meshcentral*.{0,1000}\sinstall\smeshcentral.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z1695
127* install pgrok*.{0,1000}\sinstall\spgrok.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok10N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z1698
128* install requests_ntlm*.{0,1000}\sinstall\srequests_ntlm.{0,1000}greyware_tool_keywordrequests-ntlmHTTP NTLM Authentication for Requests LibraryT1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://pypi.org/project/requests-ntlm/10N/AN/A89N/AN/AN/AN/A1699
129* install shadowsocks-rust*.{0,1000}\sinstall\sshadowsocks\-rust.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z1701
130* install softether5*.{0,1000}\sinstall\ssoftether5.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN10#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z1702
131* install sshuttle*.{0,1000}\sinstall\ssshuttle.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle10#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z1704
132* install tailscale*.{0,1000}\sinstall\stailscale.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale10N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z1705
133* install tmate*.{0,1000}\sinstall\stmate.{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate-ssh-server10#linuxN/A10106421482024-06-21T11:52:24Z2013-06-09T23:58:55Z1706
134* install tunnelto*.{0,1000}\sinstall\stunnelto.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto10N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z1709
135* install wireguard*.{0,1000}\sinstall\swireguard.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap10N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z1712
136* install wireguard-tools*.{0,1000}\sinstall\swireguard\-tools.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap10N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z1713
137* install xvnc4viewer netcat-traditional socat*.{0,1000}\sinstall\sxvnc4viewer\snetcat\-traditional\ssocat.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z1715
138* install-fleetctl.sh*.{0,1000}\sinstall\-fleetctl\.sh.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet10N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z1716
139* Invoke-WebRequest -Uri http://download.anydesk.com/AnyDesk.exe*.{0,1000}\sInvoke\-WebRequest\s\-Uri\shttp\:\/\/download\.anydesk\.com\/AnyDesk\.exe.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the Dispossessor ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A1753
140* IObitUnlocker.exe*.{0,1000}\sIObitUnlocker\.exe.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#10N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A1756
141* -jar ipscan.exe*.{0,1000}\s\-jar\sipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/Anetwork exploitation tool71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z1798
142* jprq-windows-386.exe*.{0,1000}\sjprq\-windows\-386\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z1826
143* jprq-windows-amd64.exe*.{0,1000}\sjprq\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z1827
144* list-recycle-bin.ps1*.{0,1000}\slist\-recycle\-bin\.ps1.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill10N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z1963
145* localgroup Administrators localadm /ADD *.{0,1000}\slocalgroup\sAdministrators\slocaladm\s\/ADD\s.{0,1000}greyware_tool_keywordnetcommand used in the Dispossessor ransomware group notesT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A2021
146* localtunnel-server*.{0,1000}\slocaltunnel\-server.{0,1000}greyware_tool_keywordlocaltunnelsserver for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/server10N/AN/A810316310332024-03-20T09:14:46Z2013-06-16T22:30:48Z2033
147* LoggingServer=logging.getgo.com ProxyHost=*.{0,1000}\sLoggingServer\=logging\.getgo\.com\sProxyHost\=.{0,1000}greyware_tool_keywordGoToMyPCGoToMyPC is remote desktop software that allows users to access computers remotely using a web browserT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AN/ARMMhttps://www.gotomypc.com/10N/AN/A1010N/AN/AN/AN/A2036
148* -log-level trace -dre -log-path *.{0,1000}\s\-log\-level\strace\s\-dre\s\-log\-path\s.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/ADameware Remote Support1010N/AN/AN/AN/A2038
149* -m boringproxy*.{0,1000}\s\-m\sboringproxy.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z2058
150* -m SimpleHTTPServer *.{0,1000}\s\-m\sSimpleHTTPServer\s.{0,1000}greyware_tool_keywordsimplehttpserverquick web server in pythonT1021.002 - T1059.006TA0002 - TA0005N/AN/AData Exfiltrationhttps://docs.python.org/2/library/simplehttpserver.html10N/AN/A610N/AN/AN/AN/A2093
151* -m sshtunnel *.{0,1000}\s\-m\ssshtunnel\s.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel10N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z2098
152* -ma lssas.exe*.{0,1000}\s\-ma\slssas\.exe.{0,1000}greyware_tool_keywordProcdumpdump lsass process with procdumpT1003.001TA0006N/ALockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - DispossessorCredential Accesshttps://learn.microsoft.com/en-us/sysinternals/downloads/procdump10N/AN/A1010N/AN/AN/AN/A2109
153* MEGAcmd.sh*.{0,1000}\sMEGAcmd\.sh.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z2126
154* megasync.exe*.{0,1000}\smegasync\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop10N/AN/A1010N/AN/AN/AN/A2127
155* MEGAsyncSetup32.exe*.{0,1000}\sMEGAsyncSetup32\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop10N/AN/A1010N/AN/AN/AN/A2128
156* MEGAsyncSetup64.exe*.{0,1000}\sMEGAsyncSetup64\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop10N/AN/A1010N/AN/AN/AN/A2129
157* meshcentral.service*.{0,1000}\smeshcentral\.service.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z2141
158* -ms assist.zoho.com -p 443*.{0,1000}\s\-ms\sassist\.zoho\.com\s\-p\s443.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A2189
159* -Name DisableAntiSpyware -Value 1 -PropertyType DWORD -Force*.{0,1000}\s\-Name\sDisableAntiSpyware\s\-Value\s1\s\-PropertyType\sDWORD\s\-Force.{0,1000}greyware_tool_keywordpowershellDefense evasion technique In order to avoid detection at any point of the kill chain. attackers use several ways to disable anti-virus. disable Microsoft firewall and clear logs.T1562.001 - T1562.002 - T1070.004TA0007 - TA0040 - TA0005N/ADispossessorDefense EvasionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A2245
160* --name localtunnel *.{0,1000}\s\-\-name\slocaltunnel\s.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/NoahShen/gotunnelme10N/AN/A1010171452018-01-06T04:41:15Z2013-10-18T02:46:51Z2247
161* -name:* -password:* -remoteexecute -filename*.{0,1000}\s\-name\:.{0,1000}\s\-password\:.{0,1000}\s\-remoteexecute\s\-filename.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/10N/AN/A1010N/AN/AN/AN/A2250
162* nc termbin.com *.{0,1000}\snc\stermbin\.com\s.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A2267
163* ncat * -e /bin/bash*|crontab*.{0,1000}\sncat\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\|crontab.{0,1000}greyware_tool_keywordncatreverse shell persistenceT1059.004 - T1053.005 - T1059.005TA0002 - TA0005N/ACalypso - GALLIUMPersistenceN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A2269
164* neoreg.py *.{0,1000}\sneoreg\.py\s.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg10N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z2284
165* netcat termbin.com *.{0,1000}\snetcat\stermbin\.com\s.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A2292
166* netscan.exe *.{0,1000}\snetscan\.exe\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A2301
167* netscan64.exe *.{0,1000}\snetscan64\.exe\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A2302
168* net-vpn/tailscale*.{0,1000}\snet\-vpn\/tailscale.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale10N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z2303
169* --nicehash *--coin *.{0,1000}\s\-\-nicehash\s.{0,1000}\-\-coin\s.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/10N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z2311
170* NimScan.exe*.{0,1000}\sNimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z2317
171* NimScan.nim*.{0,1000}\sNimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z2318
172* nircmd.exe*.{0,1000}\snircmd\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html10N/AN/A1010N/AN/AN/AN/A2334
173* nircmdc.exe*.{0,1000}\snircmdc\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html10N/AN/A1010N/AN/AN/AN/A2335
174* -NoExit -Command [Console]::OutputEncoding=[Text.UTF8Encoding]::UTF8*.{0,1000}\s\-NoExit\s\-Command\s\[Console\]\:\:OutputEncoding\=\[Text\.UTF8Encoding\]\:\:UTF8.{0,1000}greyware_tool_keywordpowershellpowershell command pattern used by sliver - an open source cross-platform adversary emulation/red team frameworkT1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043N/AAvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEARC2https://github.com/BishopFox/sliver10N/AN/A1010921812492025-04-21T17:52:43Z2019-01-17T22:07:38Z2346
175* noitcetorPAUP*.{0,1000}\snoitcetorPAUP.{0,1000}greyware_tool_keyword_reversed string for obfuscationT1027TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A2349
176* -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient*.{0,1000}\s\-NoP\s\-NonI\s\-W\sHidden\s\-Exec\sBypass\s\-Command\sNew\-Object\sSystem\.Net\.Sockets\.TCPClient.{0,1000}greyware_tool_keywordpowershellreverse shell powershellT1059.001 - T1203 - T1105 - T1562.001TA0002 - TA0011N/ABlack BastaC2https://github.com/mthbernardes/rsg10N/AN/A10105611262024-05-03T16:33:20Z2017-12-12T02:57:07Z2352
177* -NOP -WIND HIDDeN -eXeC BYPASS -NONI *.{0,1000}\s\-NOP\s\-WIND\sHIDDeN\s\-eXeC\sBYPASS\s\-NONI\s.{0,1000}greyware_tool_keywordpowershellsuspicious powershell arguments order used by many exploitation toolsT1059.001 - T1059.003 - T1027.009TA0002 - TA0005N/AN/AExploitation toolN/A10N/AN/A1010N/AN/AN/AN/A2356
178* OfflineSamTool.h*.{0,1000}\sOfflineSamTool\.h.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140610N/AN/A1010N/AN/AN/AN/A2436
179* -omeshcmd.exe -imodule1.js*.{0,1000}\s\-omeshcmd\.exe\s\-imodule1\.js.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshAgent10N/AN/A103264962025-03-19T18:43:56Z2017-10-12T21:26:52Z2439
180* on http://localhost:7777*.{0,1000}\son\shttp\:\/\/localhost\:7777.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr10N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z2444
181* oshi.at *.{0,1000}\soshi\.at\s.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload10#filehostingserviceN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z2462
182* pacman -S wireguard-tools*.{0,1000}\spacman\s\-S\swireguard\-tools.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap10N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z2502
183* PAExec service*.{0,1000}\sPAExec\sservice.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec10N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z2504
184* pagekite.logging*.{0,1000}\spagekite\.logging.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z2505
185* pagekite.py*.{0,1000}\spagekite\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z2506
186* pagekite-gtk.py*.{0,1000}\spagekite\-gtk\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z2507
187* PCMonitorManager.exe*.{0,1000}\sPCMonitorManager\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A2573
188* PCMonitorSrv.exe*.{0,1000}\sPCMonitorSrv\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A2574
189* pcmontask.exe*.{0,1000}\spcmontask\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/10N/AN/A1010N/AN/AN/AN/A2575
190* -perm -4000 -o -perm -2000*.{0,1000}\s\-perm\s\-4000\s\-o\s\-perm\s\-2000.{0,1000}greyware_tool_keywordfindLook for files with the SGID (Set Group ID) bit setT1083 - T1069 - T1202TA0004 - TA0007N/AN/ADiscoveryN/A10#linuxN/A710N/AN/AN/AN/A2584
191* pgrok.exe*.{0,1000}\spgrok\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok10N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z2599
192* pgrokd.exe*.{0,1000}\spgrokd\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok10N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z2600
193* Portr inspector running on *.{0,1000}\sPortr\sinspector\srunning\son\s.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr10N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z2637
194* portr.exe*.{0,1000}\sportr\.exe.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr10N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z2638
195* privoxy.exe*.{0,1000}\sprivoxy\.exe.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows10N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z2675
196* process call create *cmd.exe /c powershell.exe -nop -w hidden -c *IEX ((new-object net.webclient).downloadstring('https://*.{0,1000}\sprocess\scall\screate\s.{0,1000}cmd\.exe\s\/c\spowershell\.exe\s\-nop\s\-w\shidden\s\-c\s.{0,1000}IEX\s\(\(new\-object\snet\.webclient\)\.downloadstring\(\'https\:\/\/.{0,1000}greyware_tool_keywordwmicThreat Actors ran the following command to download and execute a PowerShell payloadT1059.001 - T1059.003 - T1569.002 - T1021.006TA0002 - TA0005N/AMAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - DispossessorCollectionhttps://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF10N/AN/A1010N/AN/AN/AN/A2676
197* ps2exe.ps1*.{0,1000}\sps2exe\.ps1.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill10N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z2688
198* pulseway_x64.deb*.{0,1000}\spulseway_x64\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A2702
199* Pulseway_x64.msi*.{0,1000}\sPulseway_x64\.msi.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A2703
200* pulseway_x86.deb*.{0,1000}\spulseway_x86\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10N/AN/A1010N/AN/AN/AN/A2704
201* pwn_tclsh.me*.{0,1000}\spwn_tclsh\.me.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z2732
202* py2exe*.{0,1000}\spy2exe.{0,1000}greyware_tool_keywordpy2exepy2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attackerT1027.002 - T1045 - T1059.001 - T1587.001TA0005 - TA0042Operation WocaoN/AResource Developmenthttps://github.com/py2exe/py2exe10N/Agreyware_tools high risks of false positivesN/A109271022024-11-12T19:44:34Z2019-03-11T13:16:35Z2734
203* py39-sshuttle*.{0,1000}\spy39\-sshuttle.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle10#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z2735
204* -r rclone:* init*.{0,1000}\s\-r\srclone\:.{0,1000}\sinit.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic10N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z2757
205* rathole.exe.{0,1000}\srathole\.exegreyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole10N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z2772
206* RDPWInst.exe*.{0,1000}\sRDPWInst\.exe.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap10N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z2794
207* rdpwrap.dll*.{0,1000}\srdpwrap\.dll.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap10N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z2795
208* RemCom.exe*.{0,1000}\sRemCom\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom10N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z2825
209* RemComSvc.exe*.{0,1000}\sRemComSvc\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom10N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z2826
210* RemComSvc.h*.{0,1000}\sRemComSvc\.h.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom10N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z2827
211* RemoteDesktop.exe*.{0,1000}\sRemoteDesktop\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/10N/AN/A1010N/AN/AN/AN/A2833
212* remoteit.exe*.{0,1000}\sremoteit\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z2838
213* remoteit.x86-win.exe*.{0,1000}\sremoteit\.x86\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z2839
214* remoteit-desktop.exe*.{0,1000}\sremoteit\-desktop\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z2840
215* RemotePC.exe*.{0,1000}\sRemotePC\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2844
216* RemotePCAttendedService *.{0,1000}\sRemotePCAttendedService\s.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/10N/AN/A1010N/AN/AN/AN/A2845
217* remotepclauncher.exe*.{0,1000}\sremotepclauncher\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2846
218* remotepcuiu.exe*.{0,1000}\sremotepcuiu\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2847
219* RemotePCViewer.msi*.{0,1000}\sRemotePCViewer\.msi.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/10N/AN/A1010N/AN/AN/AN/A2848
220* restic.exe*.{0,1000}\srestic\.exe.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic10N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z2870
221* restic/restic *.{0,1000}\srestic\/restic\s.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic10N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z2871
222* rmm-installer.ps1*.{0,1000}\srmm\-installer\.ps1.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm10N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z2911
223* rpcdownloader.exe*.{0,1000}\srpcdownloader\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2923
224* rpcperfviewer.exe*.{0,1000}\srpcperfviewer\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2927
225* RPCWinXP.exe*.{0,1000}\sRPCWinXP\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/10N/AN/A1010N/AN/AN/AN/A2928
226* -rr_flag * -group * -fileTransferGateways *.zohoassist.com -ADMINAGENT*.{0,1000}\s\-rr_flag\s.{0,1000}\s\-group\s.{0,1000}\s\-fileTransferGateways\s.{0,1000}\.zohoassist\.com\s\-ADMINAGENT.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A2929
227* rsocks.pool*.{0,1000}\srsocks\.pool.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10N/AN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z2931
228* rsocks.server*.{0,1000}\srsocks\.server.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10N/AN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z2932
229* rsync.stunnel.org::stunnel *.{0,1000}\srsync\.stunnel\.org\:\:stunnel\s.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html10N/AN/A78N/AN/AN/AN/A2933
230* rtun-server-windows-amd64.exe*.{0,1000}\srtun\-server\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel10N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z2939
231* rtun-windows-amd64.exe*.{0,1000}\srtun\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel10N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z2940
232* RustDesk.exe*.{0,1000}\sRustDesk\.exe.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk10N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z2953
233* -s rest_server_zrok -t*.{0,1000}\s\-s\srest_server_zrok\s\-t.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z2966
234* s3://sshx/*.{0,1000}\ss3\:\/\/sshx\/.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx10N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z2968
235* -sc getacls -sddlfilter *.{0,1000}\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryN/A10N/AN/A1010N/AN/AN/AN/A2984
236* -sc trustdump*.{0,1000}\s\-sc\strustdump.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/10N/AN/A1010N/AN/AN/AN/A2987
237* --scanner aclcheck*.{0,1000}\s\-\-scanner\saclcheck.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z2993
238* --scanner laps_bitlocker*.{0,1000}\s\-\-scanner\slaps_bitlocker.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z2994
239* --scanner nullsession-trust*.{0,1000}\s\-\-scanner\snullsession\-trust.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z2995
240* --scanner smb3querynetwork*.{0,1000}\s\-\-scanner\ssmb3querynetwork.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z2996
241* --scanner zerologon*.{0,1000}\s\-\-scanner\szerologon.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle10N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z2997
242* --script smb-vuln-ms08-067,smb-vuln-ms17-010*.{0,1000}\s\-\-script\ssmb\-vuln\-ms08\-067,smb\-vuln\-ms17\-010.{0,1000}greyware_tool_keywordnmapnmap vuln scan of most used vulnerabilitiesT1046 - T1203 - T1210TA0007N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A3011
243* SELECT ProcessId FROM Win32_Process * Name='ZAAudioClient.exe'*.{0,1000}\sSELECT\sProcessId\sFROM\sWin32_Process\s.{0,1000}\sName\=\'ZAAudioClient\.exe\'.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A3035
244* -service TightVNC Server*.{0,1000}\s\-service\sTightVNC\sServer.{0,1000}greyware_tool_keywordtightvncTightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.tightvnc.com10N/AN/A1010N/AN/AN/AN/A3049
245* -ServiceName "AADInternals"*.{0,1000}\s\-ServiceName\s\"AADInternals\".{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals10#servicenameN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z3050
246* set xmrig Type SERVICE_WIN32_OWN_PROCESS*.{0,1000}\sset\sxmrig\sType\sSERVICE_WIN32_OWN_PROCESS.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-170810N/AN/A910N/AN/AN/AN/A3057
247* set-proxy.ps1*.{0,1000}\sset\-proxy\.ps1.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals10N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z3064
248* shadowsocks-divert*.{0,1000}\sshadowsocks\-divert.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z3073
249* shadowsocks-rust.sslocal-daemon*.{0,1000}\sshadowsocks\-rust\.sslocal\-daemon.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z3074
250* shadowsocks-tproxy-mark*.{0,1000}\sshadowsocks\-tproxy\-mark.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z3075
251* sharedfolder add * -hostpath c:\ -automount*.{0,1000}\ssharedfolder\sadd\s.{0,1000}\s\-hostpath\sc\:\\\s\-automount.{0,1000}greyware_tool_keywordVirtualBoxadding the entire C drive as a shared folder for a VMT1021.001 - T1137 - T1072TA0006 - TA0008 - TA0005N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A1010N/AN/AN/AN/A3076
252* sirtunnel.py*.{0,1000}\ssirtunnel\.py.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel10N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z3151
253* sish -c date*.{0,1000}\ssish\s\-c\sdate.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish10N/AN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z3152
254* --socks5-hostname 127.0.0.1:9050*.{0,1000}\s\-\-socks5\-hostname\s127\.0\.0\.1\:9050.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload10#filehostingserviceN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z3292
255* SoftEtherVPN-*.tar.xz*.{0,1000}\sSoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN10#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z3297
256* ssh -R* remote.moe*.{0,1000}\sssh\s\-R.{0,1000}\sremote\.moe.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe10N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z3354
257* sshtunnel.py*.{0,1000}\ssshtunnel\.py.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel10N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z3362
258* SSHTunnelForwarder(*.{0,1000}\sSSHTunnelForwarder\(.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel10N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z3363
259* sshuttle:sshuttle *.{0,1000}\ssshuttle\:sshuttle\s.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle10#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z3364
260* start rustdesk://*.{0,1000}\sstart\srustdesk\:\/\/.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk10N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z3390
261* start SupremoService*.{0,1000}\sstart\sSupremoService.{0,1000}greyware_tool_keywordSupremoSupremo - Remote access softwareT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ABlack BastaRMMhttps://www.supremocontrol.com10N/AN/A1010N/AN/AN/AN/A3391
262* start uvnc_service*.{0,1000}\sstart\suvnc_service.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html10N/AN/A1010N/AN/AN/AN/A3392
263* Starting tunneling server*.{0,1000}\sStarting\stunneling\sserver.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel10N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z3399
264* stop ProxifierDrv*.{0,1000}\sstop\sProxifierDrv.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/10N/AN/A89N/AN/AN/AN/A3413
265* stop uvnc_service*.{0,1000}\sstop\suvnc_service.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html10N/AN/A1010N/AN/AN/AN/A3414
266* Supremo.exe*.{0,1000}\sSupremo\.exe.{0,1000}greyware_tool_keywordSupremoSupremo - Remote access softwareT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ABlack BastaRMMhttps://www.supremocontrol.com10N/AN/A1010N/AN/AN/AN/A3432
267* tacticalrmm.exe*.{0,1000}\stacticalrmm\.exe.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm10N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z3459
268* tailscale.exe*.{0,1000}\stailscale\.exe.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale10N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z3460
269* tailscale-archive-keyring*.{0,1000}\stailscale\-archive\-keyring.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale10N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z3461
270* termbin.com 9999*.{0,1000}\stermbin\.com\s9999.{0,1000}greyware_tool_keywordtermbin.comsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationtermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A3501
271* the servers Wireguard interface.*.{0,1000}\sthe\sservers\sWireguard\sinterface\..{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel10N/AN/A1010N/AN/AN/AN/A3512
272* tkc_agent_dre.deb*.{0,1000}\stkc_agent_dre\.deb.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/AN/A1010N/AN/AN/AN/A3523
273* --to bore.pub*.{0,1000}\s\-\-to\sbore\.pub.{0,1000}greyware_tool_keywordborebore is a simple CLI tool for making tunnels to localhostT1090 - T1090.003 - T1572 - T1572.001TA0042 - TA0011N/AN/AData Exfiltrationhttps://github.com/ekzhang/bore10N/AN/A101096344102025-04-14T21:52:18Z2022-04-04T02:47:54Z3529
274* tunneld.service*.{0,1000}\stunneld\.service.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel10N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z3570
275* tunnelmole.bundle.js*.{0,1000}\stunnelmole\.bundle\.js.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/10N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z3571
276* tunwg.exe*.{0,1000}\stunwg\.exe.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg10N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z3574
277* ultravnc.ini *.{0,1000}\sultravnc\.ini\s.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html10N/AN/A1010N/AN/AN/AN/A3610
278* upload*.systemmonitor.eu.com*/command/agentprocessor*.{0,1000}\supload.{0,1000}\.systemmonitor\.eu\.com.{0,1000}\/command\/agentprocessor.{0,1000}greyware_tool_keywordNsight RMMNsight RMM usageT1021 - T1219 - T1563 - T1608TA0002 - TA0008 - TA0011 - TA0040N/AScattered Spider*RMMhttps://www.n-able.com/products/n-sight-rmm10N/AN/A1010N/AN/AN/AN/A3626
279* vnc.ini *.{0,1000}\svnc\.ini\s.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html10N/AN/A1010N/AN/AN/AN/A3673
280* VSAX_x64.msi*.{0,1000}\sVSAX_x64\.msi.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/10N/AN/A1010N/AN/AN/AN/A3679
281* -W Hidden -command *https://*Invoke-WebRequest*; iex $*.{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}https\:\/\/.{0,1000}Invoke\-WebRequest.{0,1000}\;\siex\s\$.{0,1000}greyware_tool_keywordpowershellA PowerShell process downloaded and launched a remote fileT1059.001 - T1105 - T1203TA0001 - TA0002Lumma StealerN/ACollectionN/A10N/AN/A88N/AN/AN/AN/A3685
282* -W Hidden -command *Invoke-WebRequest*https://*; iex $*.{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}Invoke\-WebRequest.{0,1000}https\:\/\/.{0,1000}\;\siex\s\$.{0,1000}greyware_tool_keywordpowershellA PowerShell process downloaded and launched a remote fileT1059.001 - T1105 - T1203TA0001 - TA0002Lumma StealerN/ACollectionN/A10N/AN/A88N/AN/AN/AN/A3686
283* -w hidden -ep bypass -nop -Command "iex ((New-Object System.Net.WebClient).DownloadString(*.{0,1000}\s\-w\shidden\s\-ep\sbypass\s\-nop\s\-Command\s\"iex\s\(\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(.{0,1000}greyware_tool_keywordpowershellsuspicious powershell command often used in recaptcha phishing campaign (run dialog)T1086 - T1105 - T1218.003 - T1569.002TA0002 - TA0009Lumma StealerN/ACollectionN/A10N/AN/A1010N/AN/AN/AN/A3687
284* We have found at least * potential SUID exploitable file(s)*.{0,1000}\sWe\shave\sfound\sat\sleast\s.{0,1000}\spotential\sSUID\sexploitable\sfile\(s\).{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z3696
285* --webview-exe-name=QuickAssist.exe*.{0,1000}\s\-\-webview\-exe\-name\=QuickAssist\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx510N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A3700
286* where /r C:\Windows\WinSxS\ *Microsoft.ActiveDirectory.Management.dll*.{0,1000}\swhere\s\/r\sC\:\\Windows\\WinSxS\\\s.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}greyware_tool_keywordwherethreat actors searched for Active Directory related DLLs in directoriesT1059 - T1083 - T1018TA0002 - TA0009 - TA0040N/AN/ADiscoveryhttps://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/10N/AN/AN/AN/AN/AN/AN/AN/A3704
287* wireguard-installer.exe*.{0,1000}\swireguard\-installer\.exe.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap10N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z3736
288* wireproxy.service*.{0,1000}\swireproxy\.service.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy10#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z3737
289* wiretap.exe*.{0,1000}\swiretap\.exe.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap10N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z3738
290* xmrig.exe*.{0,1000}\s\sxmrig\.exe.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/10N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z3781
291* ZA_Connect.exe*.{0,1000}\sZA_Connect\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A3788
292* ZAAudioClient.exe*.{0,1000}\sZAAudioClient\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A3789
293* ZAFileTransfer.exe*.{0,1000}\sZAFileTransfer\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A3790
294* ZAService.exe*.{0,1000}\sZAService\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/10N/AN/A1010N/AN/AN/AN/A3791
295* zrok.listener*.{0,1000}\szrok\.listener.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z3792
296*"%~dp0RDPWInst" -i -o*.{0,1000}\"\%\~dp0RDPWInst\"\s\-i\s\-o.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap10N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z3813
297*"[IO.File]::WriteAllBytes($*,[Convert]::FromBase64String("*.{0,1000}\"\[IO\.File\]\:\:WriteAllBytes\(\$.{0,1000},\[Convert\]\:\:FromBase64String\(\".{0,1000}greyware_tool_keywordpowershellsuspicious behavior powershell scriptT1059.001 - T1105 - T1204.002TA0002 - TA0005N/AN/ADefense Evasionhttps[://]87[.]120[.]120[.]56/crypt/xx.ps110N/AN/A910N/AN/AN/AN/A3814
298*"appName":"eHorus Agent"*.{0,1000}\"appName\"\:\"eHorus\sAgent\".{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/10#registryN/A1010N/AN/AN/AN/A3820
299*"-----BEGIN OpenVPN Static key*.{0,1000}\"\-\-\-\-\-BEGIN\sOpenVPN\sStatic\skey.{0,1000}greyware_tool_keywordOPENVPNOpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate dataT1071 - T1573 - T1133TA0003 - TA0008 - TA0011N/AN/ADefense Evasionhttps://openvpn.net/10#content #VPNN/A68N/AN/AN/AN/A3822
300*"C:\Windows\system32\ARP.EXE" /a*.{0,1000}\"C\:\\Windows\\system32\\ARP\.EXE\"\s\/a.{0,1000}greyware_tool_keywordarpArp displays and modifies information about a system's Address Resolution Protocol (ARP) cacheT1018TA0007N/ATurla - APT32 - OrangewormDiscoveryN/A10N/AN/A57N/AN/AN/AN/A3825
301*"gost installation completed!"*.{0,1000}\"gost\sinstallation\scompleted!\".{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost10N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z3840
302*"http://mitm"*.{0,1000}\"http\:\/\/mitm\".{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals10N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z3845
303*"message":"ably connection state: CONNECTED"}*.{0,1000}\"message\"\:\"ably\sconnection\sstate\:\sCONNECTED\"\}.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10N/AN/A1010N/AN/AN/AN/A3853
304*"PageKite system service"*.{0,1000}\"PageKite\ssystem\sservice\".{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z3858
305*"publisher":"uvnc bvba*.{0,1000}\"publisher\"\:\"uvnc\sbvba.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html10#registryregistry value1010N/AN/AN/AN/A3860
306*"RemotePCAttendedService"*.{0,1000}\"RemotePCAttendedService\".{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/10N/AN/A1010N/AN/AN/AN/A3863
307*"SimpleHelp Remote Printer"*.{0,1000}\"SimpleHelp\sRemote\sPrinter\".{0,1000}greyware_tool_keywordSimpleHelpSimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackCatRMMsimple-help.com10N/AN/A1010N/AN/AN/AN/A3870
308*"User-Agent", "tunnelto-client"*.{0,1000}\"User\-Agent\",\s\"tunnelto\-client\".{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto10N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z3880
309*# adiskreader *.{0,1000}\#\sadiskreader\s.{0,1000}greyware_tool_keywordadiskreaderAsync Python library to parse local and remote disk imagesT1020 - T1048 - T1074 - T1560.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://github.com/skelsec/adiskreader10N/AN/A417672025-03-15T19:48:39Z2023-12-18T11:54:31Z3885
310*$(mega-whoami)*.{0,1000}\$\(mega\-whoami\).{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z3935
311*$base64adrecon*.{0,1000}\$base64adrecon.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10#contentAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z3945
312*$EHORUS_HOME/.vnc/passwd*.{0,1000}\$EHORUS_HOME\/\.vnc\/passwd.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/10#linuxN/A1010N/AN/AN/AN/A3959
313*$env:LEVEL_API_KEY = "*";*.{0,1000}\$env\:LEVEL_API_KEY\s\=\s\".{0,1000}\"\;.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10N/AN/A1010N/AN/AN/AN/A3963
314*$HOME/.zrok*.{0,1000}\$HOME\/\.zrok.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z3985
315*$MEGACMDSHELL*.{0,1000}\$MEGACMDSHELL.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z3998
316*$outputPath = "C:\AnyDesk.exe"*.{0,1000}\$outputPath\s\=\s\"C\:\\AnyDesk\.exe\".{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps110N/Asimple backdoor with anydesk101102025-04-17T19:04:37Z2023-12-05T22:08:51Z4004
317*$tempFile = Join-Path ([System.IO.Path]::GetTempPath()) "install_windows.exe";*.{0,1000}\$tempFile\s\=\sJoin\-Path\s\(\[System\.IO\.Path\]\:\:GetTempPath\(\)\)\s\"install_windows\.exe\"\;.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10N/AN/A1010N/AN/AN/AN/A4021
318*%~dp0RDPWInst.exe*.{0,1000}\%\~dp0RDPWInst\.exe.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap10N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z4028
319*%COMSPEC%*echo*\pipe\*.{0,1000}\%COMSPEC\%.{0,1000}echo.{0,1000}\\pipe\\.{0,1000}greyware_tool_keywordechoDetects the use of getsystem Meterpreter/Cobalt Strike command. Getsystem is used to elevate privilege to SYSTEM account.T1068.003 - T1078.002TA0004 - TA0008N/AN/AExploitation toolhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_meterpreter_or_cobaltstrike_getsystem_service_start.yml10N/Agreyware tool - risks of False positive !N/A10911523162025-04-17T19:43:35Z2016-12-24T09:48:49Z4036
320*%LOCALAPPDATA%\MEGAcmd*.{0,1000}\%LOCALAPPDATA\%\\MEGAcmd.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z4038
321*%SystemRoot%\\MEMORY.DMP*.{0,1000}\%SystemRoot\%\\\\MEMORY\.DMP.{0,1000}greyware_tool_keywordCIMplantC# port of WMImplant which uses either CIM or WMI to query remote systemsT1047 - T1059.001 - T1021.006TA0002 - TA0007 - TA0008N/AScattered Spider*Lateral Movementhttps://github.com/RedSiege/CIMplant10N/AN/A102199292021-07-14T18:18:42Z2021-01-29T21:41:58Z4041
322*%SYSTEMROOT%\PAExec-*.{0,1000}\%SYSTEMROOT\%\\PAExec\-.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec10N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z4042
323*%tooRmetsyS%*.{0,1000}\%tooRmetsyS\%.{0,1000}greyware_tool_keyword_reversed string for obfuscationT1027TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A4044
324*%USERPROFILE%\\nssm.zip*.{0,1000}\%USERPROFILE\%\\\\nssm\.zip.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/10N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z4046
325*&& telnet * 2>&1 </dev/console*.{0,1000}\&\&\stelnet\s.{0,1000}\s2\>\&1\s\<\/dev\/console.{0,1000}greyware_tool_keywordtelnetsuspicious shell commands used in various Equation Group scripts and toolsT1105 - T1021.001 - T1021.002TA0002 - TA0008N/AN/AC2https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_apt_equationgroup_lnx.yml10N/Agreyware tool - risks of False positive !N/A10911523162025-04-17T19:43:35Z2016-12-24T09:48:49Z4048
326*&browser=tor&api=false*.{0,1000}\&browser\=tor\&api\=false.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A4049
327*(&(&(objectCategory=person)(objectClass=user))(|(description=*pass*)(comment=*pass*)))*.{0,1000}\(\&\(\&\(objectCategory\=person\)\(objectClass\=user\)\)\(\|\(description\=.{0,1000}pass.{0,1000}\)\(comment\=.{0,1000}pass.{0,1000}\)\)\).{0,1000}greyware_tool_keywordldap queriesmetasploit enum_ad_user_commentsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/82472610N/AN/A84N/AN/AN/AN/A4053
328*(&(objectCategory=computer)(msDS-isRODC=TRUE))*.{0,1000}\(\&\(objectCategory\=computer\)\(msDS\-isRODC\=TRUE\)\).{0,1000}greyware_tool_keywordldap queriesEnumerate Read-Only Domain Controllers (RODC)T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4057
329*(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=" + target + "))*.{0,1000}\(\&\(objectCategory\=computer\)\(ms\-MCS\-AdmPwd\=.{0,1000}\)\(sAMAccountName\=\"\s\+\starget\s\+\s\"\)\).{0,1000}greyware_tool_keywordldap queriesLAPS passwords (from SharpLAPS)T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4058
330*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)(memberOf=CN=Administrators*.{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\)\(memberOf\=CN\=Administrators.{0,1000}greyware_tool_keywordldap queriesEnumerate Accounts with Non-Expiring Passwords and Administrative PrivilegesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4059
331*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)*.{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\).{0,1000}greyware_tool_keywordldap queriesEnumerate all users with the account configuration 'Password never expires'T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4060
332*(&(objectClass=group)(managedBy=*)(groupType:1.2.840.113556.1.4.803:=2147483648))*.{0,1000}\(\&\(objectClass\=group\)\(managedBy\=.{0,1000}\)\(groupType\:1\.2\.840\.113556\.1\.4\.803\:\=2147483648\)\).{0,1000}greyware_tool_keywordldap queriesmetasploit enum_ad_managedby_groups.rbT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/rapid7/metasploit-framework/blob/d37a82500d1d08f9d8ab3da9b194653835748fae/modules/post/windows/gather/enum_ad_managedby_groups.rb#L5910N/AN/A81035400142722025-04-22T20:14:59Z2011-08-30T06:13:20Z4061
333*(&(objectclass=group)(samaccountname=*domain admins*))*.{0,1000}\(\&\(objectclass\=group\)\(samaccountname\=.{0,1000}domain\sadmins.{0,1000}\)\).{0,1000}greyware_tool_keywordldap queriesEnumerate Domain Administrators GroupT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4062
334*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4063
335*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4064
336*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4065
337*([adsisearcher]'(&(objectCategory=computer)(!(primaryGroupID=516)(userAccountControl:1.2.840.113556.1.4.803:=524288)))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(!\(primaryGroupID\=516\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\)\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all servers configured for Unconstrained DelegationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A910N/AN/AN/AN/A4067
338*([adsisearcher]'(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all Domain ControllersT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/10N/AN/A910N/AN/AN/AN/A4068
339*([adsisearcher]'(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=user\)\(!\(samAccountName\=krbtgt\)\(servicePrincipalName\=.{0,1000}\)\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesSearch for user accounts with SPN but not TGT accountsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4069
340*([adsisearcher]'(adminCount=1)').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(adminCount\=1\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesSearch for all objects with AdminSHHolderT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4070
341*([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Domains*.{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Domains.{0,1000}greyware_tool_keywordldap queriesQueries for domain level and mode informationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4071
342*([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Sites | *.{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Sites\s\|\s.{0,1000}greyware_tool_keywordldap queriesenumeration of AD Forest SitesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4072
343*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).FindAllDomainControllers() | Select-Object -Property *.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.FindAllDomainControllers\(\)\s\|\sSelect\-Object\s\-Property\s.{0,1000}greyware_tool_keywordldap queriesquerying all domain controllers with detailed propertiesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4073
344*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()*.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000}greyware_tool_keywordldap queriesget all trust relationships in the current domainT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4074
345*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()*.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000}greyware_tool_keywordpowershellPowershell enumerate domains and forestsT1482 - T1069.002TA0007 - TA0008N/ABlack BastaDiscoveryhttps://medium.com/@simone.kraus/black-basta-playbook-chat-leak-d5036936166d10N/AN/A1010N/AN/AN/AN/A4075
346*(Get-ADForest).Domains | %{ Get-ADDomainController -Filter * -Server $_ }*.{0,1000}\(Get\-ADForest\)\.Domains\s\|\s\%\{\sGet\-ADDomainController\s\-Filter\s.{0,1000}\s\-Server\s\$_\s\}.{0,1000}greyware_tool_keywordldap queriesEnumerate all of the domain controllers for all domains in a forestT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A66N/AN/AN/AN/A4077
347*(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))*.{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000}greyware_tool_keywordldap queriesused by Rubeus and S4UTomato toolsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A1010N/AN/AN/AN/A4081
348*(objectCategory=person)(objectClass=user)(serviceAccount=TRUE)*.{0,1000}\(objectCategory\=person\)\(objectClass\=user\)\(serviceAccount\=TRUE\).{0,1000}greyware_tool_keywordldap queriesQuery to find service accounts which are typically high-privileged and targeted for privilege escalationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4085
349*(objectclass=group)(samaccountname=domain admins)*.{0,1000}\(objectclass\=group\)\(samaccountname\=domain\sadmins\).{0,1000}greyware_tool_keywordldap queriesEnumerate Domain AdminsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4086
350*(userAccountControl:1.2.840.113556.1.4.803:=524288)*.{0,1000}\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\).{0,1000}greyware_tool_keywordldap queriesAccounts Trusted for DelegationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4091
351*...::$index_allocation*.{0,1000}\.\.\.\:\:\$index_allocation.{0,1000}greyware_tool_keyword$index_allocationcreation of hidden folders (and file) via ...$.......::$index_allocationT1027.001 - T1564.001TA0005 N/AN/ADefense Evasionhttps://soroush.me/blog/2010/12/a-dotty-salty-directory-a-secret-place-in-ntfs-for-secret-files/10N/AN/A810N/AN/AN/AN/A4096
352*../tunnelto_lib*.{0,1000}\.\.\/tunnelto_lib.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto10#linuxN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z4099
353*..\..\..\..\..\..\Windows\System32\cmd.exe*.{0,1000}\.\.\\\.\.\\\.\.\\\.\.\\\.\.\\\.\.\\Windows\\System32\\cmd\.exe.{0,1000}greyware_tool_keyword_attempt to bypass security controls or execute commands from an unexpected locationT1036 - T1059TA0002 - TA0005N/AN/ADefense Evasionhttps://twitter.com/malwrhunterteam/status/1737220172220620854/photo/110N/AN/A79N/AN/AN/AN/A4101
354*./boringproxy server*.{0,1000}\.\/boringproxy\sserver.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10#linuxN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z4109
355*./capsh --gid=0 --uid=0 --*.{0,1000}\.\/capsh\s\-\-gid\=0\s\-\-uid\=0\s\-\-.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4112
356*./chisel client *.{0,1000}\.\/chisel\sclient\s.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap10#linuxchisel1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z4114
357*./chroot / /bin/sh -p*.{0,1000}\.\/chroot\s\/\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4115
358*./dropbear *.{0,1000}\.\/dropbear\s.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z4128
359*./env /bin/sh -p*.{0,1000}\.\/env\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4131
360*./expect -c 'spawn /bin/sh -p;interact'*.{0,1000}\.\/expect\s\-c\s\'spawn\s\/bin\/sh\s\-p\;interact\'.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4134
361*./flock -u / /bin/sh -p*.{0,1000}\.\/flock\s\-u\s\/\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4139
362*./nice /bin/sh -p*.{0,1000}\.\/nice\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4171
363*./nmap*.{0,1000}\.\/nmap.{0,1000}greyware_tool_keywordnmapA very common tool. Network host vuln and port detector.T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap11#linuxgreyware tool - risks of False positive !8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z4173
364*./rview -c ':py3 import os*os.execl(\"/bin/sh\*.{0,1000}\.\/rview\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4195
365*./staqlab-tunnel *.{0,1000}\.\/staqlab\-tunnel\s.{0,1000}greyware_tool_keywordstaqlab-tunnelExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/cocoflan/Staqlab-tunnel10#linuxN/A1010102020-05-19T06:43:14Z2020-05-19T06:19:31Z4211
366*./test/nmap*/*.nse*.{0,1000}\.\/test\/nmap.{0,1000}\/.{0,1000}\.nse.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install10#linuxN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z4216
367*./tunwg --*.{0,1000}\.\/tunwg\s\-\-.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg10#linuxN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z4217
368*./wiretap remove*.{0,1000}\.\/wiretap\sremove.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap10#linuxN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z4221
369*.\RemComSvc\*.{0,1000}\.\\RemComSvc\\.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom10N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z4229
370*.\TightVNC1*.{0,1000}\.\\TightVNC1.{0,1000}greyware_tool_keywordtightvncTightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.tightvnc.com10#registryregistry1010N/AN/AN/AN/A4231
371*.\TightVNC2*.{0,1000}\.\\TightVNC2.{0,1000}greyware_tool_keywordtightvncTightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.tightvnc.com10#registryregistry1010N/AN/AN/AN/A4232
372*.\TightVNC3*.{0,1000}\.\\TightVNC3.{0,1000}greyware_tool_keywordtightvncTightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.tightvnc.com10#registryregistry1010N/AN/AN/AN/A4233
373*._tcp.argotunnel.com*.{0,1000}\._tcp\.argotunnel\.com.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z4234
374*.a.pinggy.online*.{0,1000}\.a\.pinggy\.online.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A4237
375*.api.mega.co.nz*.{0,1000}\.api\.mega\.co\.nz.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4242
376*.api.splashtop.com*.{0,1000}\.api\.splashtop\.com.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c7211N/AN/A1010N/AN/AN/AN/A4243
377*.apitest.barracudamsp.com*.{0,1000}\.apitest\.barracudamsp\.com.{0,1000}greyware_tool_keywordBarracudaRMMDeliver remote support services - formely AVGT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.barracudamsp.com/products/rmm/barracuda-rmm11N/AN/A1010N/AN/AN/AN/A4244
378*.asse.devtunnels.ms*.{0,1000}\.asse\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A4249
379*.aweray.net*.{0,1000}\.aweray\.net.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A4252
380*.bash_history >/dev/null 2>&1*.{0,1000}\.bash_history\s\>\/dev\/null\s2\>\&1.{0,1000}greyware_tool_keywordbashIndicator Removal on HostT1070.002 - T1562.004 - T1059.004TA0005N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A4255
381*.beyondtrustcloud.com/session_complete*.{0,1000}\.beyondtrustcloud\.com\/session_complete.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A4258
382*.bin/tmole*.{0,1000}\.bin\/tmole.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/10N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z4265
383*.bin/tunnelmole*.{0,1000}\.bin\/tunnelmole.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/10N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z4266
384*.chrome-remote-desktop-session*.{0,1000}\.chrome\-remote\-desktop\-session.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com10N/AN/A1010N/AN/AN/AN/A4269
385*.comodo.com/static/frontend/static-pages/enroll-wizard/token*.{0,1000}\.comodo\.com\/static\/frontend\/static\-pages\/enroll\-wizard\/token.{0,1000}greyware_tool_keywordComodoRMM (Itarian RMM)Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://one.comodo.com/11N/AN/A1010N/AN/AN/AN/A4275
386*.config/systemd/user/remotemoe.service*.{0,1000}\.config\/systemd\/user\/remotemoe\.service.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe10N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z4276
387*.config/telebit/telebitd.yml*.{0,1000}\.config\/telebit\/telebitd\.yml.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/10N/AN/A1010N/AN/AN/AN/A4277
388*.configrclonerclone.conf*.{0,1000}\.configrclonerclone\.conf.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone10N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z4278
389*.console.gotoassist.com*.{0,1000}\.console\.gotoassist\.com.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A4279
390*.d.requestbin.net*.{0,1000}\.d\.requestbin\.net.{0,1000}greyware_tool_keywordrequestbin.netallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://requestbin.net11N/AOut of band interaction domains1010N/AN/AN/AN/A4282
391*.dev1.fleetdeck.io*.{0,1000}\.dev1\.fleetdeck\.io.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z4285
392*.dnslog.cn:*.{0,1000}\.dnslog\.cn\:.{0,1000}greyware_tool_keyworddnslog.cnallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://dnslog.cn11N/AOut of band interaction domains1010N/AN/AN/AN/A4289
393*.exe * /hide * /range:* /auto:*.*.{0,1000}\.exe\s.{0,1000}\s\/hide\s.{0,1000}\s\/range\:.{0,1000}\s\/auto\:.{0,1000}\..{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4325
394*.exe /hide /range:all*.{0,1000}\.exe\s\/hide\s\/range\:all.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4334
395*.exe /i /s cmd *.{0,1000}\.exe\s\/i\s\/s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4336
396*.exe /i /s cmd.exe*.{0,1000}\.exe\s\/i\s\/s\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4337
397*.exe /i /s powershell*.{0,1000}\.exe\s\/i\s\/s\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4338
398*.exe /i /s pwsh*.{0,1000}\.exe\s\/i\s\/s\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4339
399*.exe /s /i cmd.exe*.{0,1000}\.exe\s\/s\s\/i\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4344
400*.exe /s /i powershell*.{0,1000}\.exe\s\/s\s\/i\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4345
401*.exe /s /i pwsh*.{0,1000}\.exe\s\/s\s\/i\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4346
402*.exe /s:ip_ranges.txt /f:scan_results.txt*.{0,1000}\.exe\s\/s\:ip_ranges\.txt\s\/f\:scan_results\.txt.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A4347
403*.exe /wakeall*.{0,1000}\.exe\s\/wakeall.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4348
404*.exe delete shadows*.{0,1000}\.exe\sdelete\sshadows.{0,1000}greyware_tool_keywordvssadmininhibiting recovery by deleting backup and recovery data to prevent system recovery after an attackT1490TA0040N/AN/ADefense EvasionN/A10N/AN/A1010N/AN/AN/AN/A4424
405*.exe -gcb -sc trustdmp > *.{0,1000}\.exe\s\-gcb\s\-sc\strustdmp\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4443
406*.exe host -p * - allow-anonymous*.{0,1000}\.exe\shost\s\-p\s.{0,1000}\s\-\sallow\-anonymous.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview10N/AN/A810N/AN/AN/AN/A4468
407*.exe -i -s cmd *.{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4471
408*.exe -i -s cmd *.{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4472
409*.exe -i -s cmd.exe*.{0,1000}\.exe\s\-i\s\-s\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4473
410*.exe -i -s powershell*.{0,1000}\.exe\s\-i\s\-s\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4474
411*.exe -i -s pwsh*.{0,1000}\.exe\s\-i\s\-s\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4475
412*.exe --IPCport 5939 --Module 1*.{0,1000}\.exe\s\-\-IPCport\s5939\s\-\-Module\s1.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/10N/Ahttps://github.com/SigmaHQ/sigma/pull/47591010N/AN/AN/AN/A4487
413*.exe --pn dre_video_uploader --logpath logs*.{0,1000}\.exe\s\-\-pn\sdre_video_uploader\s\-\-logpath\slogs.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software10N/AN/A1010N/AN/AN/AN/A4570
414*.exe port create -p *.{0,1000}\.exe\sport\screate\s\-p\s.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview10N/AN/A810N/AN/AN/AN/A4571
415*.exe -s -i cmd.exe*.{0,1000}\.exe\s\-s\s\-i\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4591
416*.exe -s -i powershell*.{0,1000}\.exe\s\-s\s\-i\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4592
417*.exe -s -i pwsh*.{0,1000}\.exe\s\-s\s\-i\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4593
418*.exe -sc adinfo > *.{0,1000}\.exe\s\-sc\sadinfo\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4598
419*.exe -sc dclist > *.{0,1000}\.exe\s\-sc\sdclist\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4599
420*.exe -sc getacls -sddlfilter *.{0,1000}\.exe\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A4600
421*.exe -sc trustdmp > *.{0,1000}\.exe\s\-sc\strustdmp\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4601
422*.exe shadowcopy delete*.{0,1000}\.exe\sshadowcopy\sdelete.{0,1000}greyware_tool_keywordwmicVSS is a feature in Windows that allows for the creation of snapshots of a volume capturing its state at a specific point in time. Adversaries may abuse the wmic shadowcopy command to interact with these shadow copies for defense evasion purposes.T1490 - T1562.002TA0040 - TA0007N/AMAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - DispossessorDefense EvasionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4608
423*.exe -subnets -f (objectCategory=subnet) > *.{0,1000}\.exe\s\-subnets\s\-f\s\(objectCategory\=subnet\)\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4623
424*.exec*.interact.sh*.{0,1000}\.exec.{0,1000}\.interact\.sh.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z4660
425*.free.pinggy.online*.{0,1000}\.free\.pinggy\.online.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A4665
426*.gofile.io/uploadFile*.{0,1000}\.gofile\.io\/uploadFile.{0,1000}greyware_tool_keywordgofile.iolegitimate service abused by lots of stealer to exfiltrate dataT1567.002TA0010N/AHive - Royal - LockBit - Vice Society - BlackSuit - ContiData Exfiltrationhttps://gofile.io11#filehostingserviceN/A810N/AN/AN/AN/A4670
427*.in.zrok.io*.{0,1000}\.in\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4677
428*.interactsh.com.{0,1000}\.interactsh\.comgreyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C7T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh10N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z4678
429*.l.tunwg.com*.{0,1000}\.l\.tunwg\.com.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z4686
430*.localltunnel.me*.{0,1000}\.localltunnel\.me.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z4696
431*.loclx.io:*.{0,1000}\.loclx\.io\:.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A4697
432*.meshagent.pid*.{0,1000}\.meshagent\.pid.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshAgent10N/AN/A103264962025-03-19T18:43:56Z2017-10-12T21:26:52Z4701
433*.mspa.n-able.com*.{0,1000}\.mspa\.n\-able\.com.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A4703
434*.myftp.biz*.{0,1000}\.myftp\.biz.{0,1000}greyware_tool_keywordmyftp.bizdyndns - lots of subdomains associated with malwares - could be used in various ways for both legitimate and malicious activities (malicious mostly)T1071 - T1021 - T1095 - T1059TA0010 - TA0008 - TA0009 - TA0011N/AN/AData Exfiltrationhttps://github.com/hagezi/dns-blocklists/blob/9d6562bddc175b59241d5935531f648cd6b6d9c8/rpz/dyndns.txt#L10311#filehostingservice #P2PN/A1010107253402025-04-22T19:18:32Z2022-04-25T07:13:09Z4704
435*.myftp.org*.{0,1000}\.myftp\.org.{0,1000}greyware_tool_keywordmyftp.orgdyndns - lots of subdomains associated with malwares - myftp.org could be used in various ways for both legitimate and malicious activities (malicious mostly)T1071 - T1021 - T1095 - T1059TA0010 - TA0008 - TA0009 - TA0011N/AN/AData Exfiltrationhttps://github.com/pan-unit42/iocs/blob/master/rat_nest/iocs.csv11#filehostingservice #P2PN/A1087111522025-04-05T02:03:37Z2015-06-04T13:37:09Z4705
436*.ngrok.me*.{0,1000}\.ngrok\.me.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z4709
437*.ps1 -sysinfo Enum*.{0,1000}\.ps1\s\-sysinfo\sEnum.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill10N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z4766
438*.py *--proxy socks5://*.{0,1000}\.py\s.{0,1000}\-\-proxy\ssocks5\:\/\/.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg10N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z4811
439*.rclone.exe config*.{0,1000}\.rclone\.exe\sconfig.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone10N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z4860
440*.realtime.services.box.net*.{0,1000}\.realtime\.services\.box\.net.{0,1000}greyware_tool_keywordBoxAttackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackersT1567.002 - T1071.001 - T1036 - T1048.002TA0005 - TA0010 - TA0009N/AN/AData Exfiltrationhttps://app.box.com/11#dnsqueryN/A67N/AN/AN/AN/A4861
441*.relay.splashtop.com*.{0,1000}\.relay\.splashtop\.com.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c7211N/AN/A1010N/AN/AN/AN/A4863
442*.remotepc.com*.{0,1000}\.remotepc\.com.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A4864
443*.remotepc.com*.{0,1000}\.remotepc\.com.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/Anetwork1010N/AN/AN/AN/A4865
444*.remoteutilities.com*.{0,1000}\.remoteutilities\.com.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A4866
445*.remoteview.logmein.com*.{0,1000}\.remoteview\.logmein\.com.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A4867
446*.router.teamviewer.com*.{0,1000}\.router\.teamviewer\.com.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/11N/AFP risk - teamviewer usage1010N/AN/AN/AN/A4871
447*.rsocks.plist*.{0,1000}\.rsocks\.plist.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10N/AN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z4872
448*.server_DoElevationRequest((Get-NtProcess -ProcessId $pid)*"cmd.exe"*C:\"*.{0,1000}\.server_DoElevationRequest\(\(Get\-NtProcess\s\-ProcessId\s\$pid\).{0,1000}\"cmd\.exe\".{0,1000}C\:\\\".{0,1000}greyware_tool_keywordsudosudo on windows allowing privilege escalationT1068 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html10#linuxN/A78N/AN/AN/AN/A4884
449*.servicedesk.atera.com/GetAgent*.{0,1000}\.servicedesk\.atera\.com\/GetAgent.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A4885
450*.share.zrok.io*.{0,1000}\.share\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4904
451*.srv.browser.lol*.{0,1000}\.srv\.browser\.lol.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A4910
452*.static.mega.co.nz*.{0,1000}\.static\.mega\.co\.nz.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4915
453*.tailscale-keyring.list*.{0,1000}\.tailscale\-keyring\.list.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale10N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z4920
454*.trycloudfare.com*DavWWWRoot*.{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A4923
455*.tunnel.pyjam.as*.{0,1000}\.tunnel\.pyjam\.as.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel11N/AN/A1010N/AN/AN/AN/A4924
456*.tunnelto.dev*.{0,1000}\.tunnelto\.dev.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z4929
457*.userstorage.mega.co.nz/ul/*.{0,1000}\.userstorage\.mega\.co\.nz\/ul\/.{0,1000}greyware_tool_keywordmega.co.nzuploading data to mega cloudT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR - DispossessorData Exfiltrationhttps://mega.io/11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4944
458*.v2.argotunnel.com*.{0,1000}\.v2\.argotunnel\.com.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z4945
459*.vm.sshx.internal:8051*.{0,1000}\.vm\.sshx\.internal\:8051.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx10N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z4948
460*.vsax.net*.{0,1000}\.vsax\.net.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/10N/AN/A1010N/AN/AN/AN/A4950
461*.xeox.com*.{0,1000}\.xeox\.com.{0,1000}greyware_tool_keywordxeoxEasily access and manage Windows devices remotely within XEOX - RMM abused by threat actorsT1021 - T1078 - T1219 - T1105 - T1046TA0011 - TA0010 - TA0003 - TA0005N/ADispossessorRMMhttps://xeox.com/remote-access/11N/AN/A1010N/AN/AN/AN/A4956
462*.zohoassist.com.cn*.{0,1000}\.zohoassist\.com\.cn.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A4979
463*.zohoassist.jp*.{0,1000}\.zohoassist\.jp.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A4980
464*.zrok.quigley.com*.{0,1000}\.zrok\.quigley\.com.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4981
465*/*.loclx.io*.{0,1000}\/.{0,1000}\.loclx\.io.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A4983
466*/.anydesk/.anydesk.trace*.{0,1000}\/\.anydesk\/\.anydesk\.trace.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A5004
467*/.anydesk/service.conf*.{0,1000}\/\.anydesk\/service\.conf.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A5005
468*/.anydesk/system.conf*.{0,1000}\/\.anydesk\/system\.conf.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A5006
469*/.anydesk/user.conf*.{0,1000}\/\.anydesk\/user\.conf.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A5007
470*/.btunnel.*.{0,1000}\/\.btunnel\..{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in10#linuxN/A98N/AN/AN/AN/A5008
471*/.fleetctl/fleetctl*.{0,1000}\/\.fleetctl\/fleetctl.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet10#linuxN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z5015
472*/.ltproxy.yml*.{0,1000}\/\.ltproxy\.yml.{0,1000}greyware_tool_keywordLTProxyLinux Transparent Proxy (Similar to Proxifiter)T1090 - T1573.001 - T1571 - T1071.001TA0010 - TA0005N/AN/AData Exfiltrationhttps://github.com/L-codes/LTProxy10#linuxN/A1013152024-11-27T05:09:47Z2021-11-11T15:17:54Z5022
473*/.ssh/dropbear*.{0,1000}\/\.ssh\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z5038
474*/.tmate.conf*.{0,1000}\/\.tmate\.conf.{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate-ssh-server10#linuxN/A10106421482024-06-21T11:52:24Z2013-06-09T23:58:55Z5040
475*/.tunneld/*.key*.{0,1000}\/\.tunneld\/.{0,1000}\.key.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel10#linuxN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z5041
476*/.zrok/*.json*.{0,1000}\/\.zrok\/.{0,1000}\.json.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z5043
477*/.zrok:/.zrok*.{0,1000}\/\.zrok\:\/\.zrok.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z5044
478*// NewHTTPClient creates a new zrok HTTP client.*.{0,1000}\/\/\sNewHTTPClient\screates\sa\snew\szrok\sHTTP\sclient\..{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#content #linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z5049
479*// Package tunnel is a server/client package that enables to proxy public*.{0,1000}\/\/\sPackage\stunnel\sis\sa\sserver\/client\spackage\sthat\senables\sto\sproxy\spublic.{0,1000}greyware_tool_keywordtunnelTunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outsideT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/koding/tunnel10#linux #contentN/A1010328722023-10-20T13:43:58Z2015-05-28T07:26:42Z5050
480*/_sish/console*.{0,1000}\/_sish\/console.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish10#linuxN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z5065
481*/3proxy-*.deb*.{0,1000}\/3proxy\-.{0,1000}\.deb.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5088
482*/3proxy-*.rpm*.{0,1000}\/3proxy\-.{0,1000}\.rpm.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5089
483*/3proxy-*.zip*.{0,1000}\/3proxy\-.{0,1000}\.zip.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5090
484*/3proxy.exe*.{0,1000}\/3proxy\.exe.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5091
485*/3proxy.git*.{0,1000}\/3proxy\.git.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5092
486*/3proxy.log*.{0,1000}\/3proxy\.log.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11#logfile #linuxN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5093
487*/a.pinggy.io*.{0,1000}\/a\.pinggy\.io.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A5100
488*/AADInternals.git*.{0,1000}\/AADInternals\.git.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z5102
489*/action1_agent(My_Organization).msi*.{0,1000}\/action1_agent\(My_Organization\)\.msi.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/Aproduct name1010N/AN/AN/AN/A5123
490*/AD_Miner.git*.{0,1000}\/AD_Miner\.git.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5127
491*/AD_Miner/releases/*.{0,1000}\/AD_Miner\/releases\/.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5128
492*/adaudit.git*.{0,1000}\/adaudit\.git.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5138
493*/adaudit.ps1*.{0,1000}\/adaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5140
494*/AD-common-queries.git*.{0,1000}\/AD\-common\-queries\.git.{0,1000}greyware_tool_keywordAD-common-queriesCollection of common ADSI queries for Domain Account enumerationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries11N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z5147
495*/AdFind.zip*.{0,1000}\/AdFind\.zip.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior11N/AN/A1010N/AN/AN/AN/A5186
496*/ADGet.exe*.{0,1000}\\ADGet\.exe.{0,1000}greyware_tool_keywordadgetgather valuable informations about the AD environmentT1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482TA0001 - TA0002 - TA0003 - TA0007 - TA0011N/AN/ADiscoveryhttps://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/11N/AN/A1010N/AN/AN/AN/A5198
497*/ADRecon*.{0,1000}\/ADRecon.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commandsT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/sense-of-security/ADRecon11N/AN/A101017862922020-06-15T05:23:14Z2017-11-29T23:01:53Z5212
498*/ADRecon.git*.{0,1000}\/ADRecon\.git.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z5213
499*/ADRecon.ps1*.{0,1000}\/ADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z5214
500*/Advanced_Port_Scanner_*.exe*.{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A5218
501*/aeroadmin.exe*.{0,1000}\/aeroadmin\.exe.{0,1000}greyware_tool_keywordaeroadminRMM software - full remote control / file transferT1021.001 - T1048.003TA0008 - TA0011 - TA0009 - TA0010N/AN/ARMMhttps://ulm.aeroadmin.com/AeroAdmin.exe10N/AN/A1010N/AN/AN/AN/A5219
502*/Agent/AcknowledgeCommands/*.{0,1000}\/Agent\/AcknowledgeCommands\/.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/10N/AN/A1010N/AN/AN/AN/A5229
503*/Agent/GetCommandsFallback/*.{0,1000}\/Agent\/GetCommandsFallback\/.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/10N/AN/A1010N/AN/AN/AN/A5231
504*/Agent/GetEnvironmentStatus/*.{0,1000}\/Agent\/GetEnvironmentStatus\/.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/10N/AN/A1010N/AN/AN/AN/A5232
505*/Agent/GetRecurringPackages/*.{0,1000}\/Agent\/GetRecurringPackages\/.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/10N/AN/A1010N/AN/AN/AN/A5233
506*/Ahk2Exe.exe*.{0,1000}\/Ahk2Exe\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5255
507*/Ahk2Exe.git*.{0,1000}\/Ahk2Exe\.git.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5256
508*/Ahk2Exe.zip*.{0,1000}\/Ahk2Exe\.zip.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5257
509*/Ahk2Exe1.*.zip*.{0,1000}\/Ahk2Exe1\..{0,1000}\.zip.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5258
510*/ahk-install.exe*.{0,1000}\/ahk\-install\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5259
511*/ahk-v2.exe*.{0,1000}\/ahk\-v2\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5260
512*/Alpemix.zip*.{0,1000}\/Alpemix\.zip.{0,1000}greyware_tool_keywordAlpemixconnect to your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.alpemix.com/11N/AN/A1010N/AN/AN/AN/A5281
513*/amalshaji/portr-admin/*.{0,1000}\/amalshaji\/portr\-admin\/.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z5282
514*/amidaware/rmmagent/releases/download/*.{0,1000}\/amidaware\/rmmagent\/releases\/download\/.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z5288
515*/Amperage.exe*.{0,1000}\/Amperage\.exe.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5291
516*/AmperageKit.git*.{0,1000}\/AmperageKit\.git.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5292
517*/AmperageKit/releases/*.{0,1000}\/AmperageKit\/releases\/.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5293
518*/Anydesk.exe.{0,1000}\/Anydesk\.exegreyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://anydesk.com/11N/Arisk of false positives - compliance detection1010N/AN/AN/AN/A5333
519*/anyplace-control/data2/*.exe*.{0,1000}\/anyplace\-control\/data2\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordAnyplaceControlaccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyplace-control[.]com11N/AN/A1010N/AN/AN/AN/A5334
520*/anyproxy.log*.{0,1000}\/anyproxy\.log.{0,1000}greyware_tool_keywordCursedChromeChrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies allowing you to browse sites as your victimsT1176 - T1219 - T1090TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/mandatoryprogrammer/CursedChrome10#linuxanyproxy101015332262024-10-26T19:06:54Z2020-04-26T20:55:05Z5335
521*/AnyViewerSetup.exe*.{0,1000}\/AnyViewerSetup\.exe.{0,1000}greyware_tool_keywordanyvieweraccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyviewer.com11N/AN/A1010N/AN/AN/AN/A5336
522*/apache-megacmd.conf*.{0,1000}\/apache\-megacmd\.conf.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10#linuxN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z5338
523*/Apemix.exe*.{0,1000}\/Apemix\.exe.{0,1000}greyware_tool_keywordAlpemixconnect to your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.alpemix.com/11N/AN/A1010N/AN/AN/AN/A5342
524*/api/latest/fleet/mdm/bootstrap?token=*.{0,1000}\/api\/latest\/fleet\/mdm\/bootstrap\?token\=.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z5350
525*/api/v1/fleet/mdm/sso/callback*.{0,1000}\/api\/v1\/fleet\/mdm\/sso\/callback.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z5365
526*/app/pgrokd/*.{0,1000}\/app\/pgrokd\/.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok10#linuxN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z5381
527*/AppFiles/ipscan.exe*.{0,1000}\/AppFiles\/ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z5382
528*/Applications/Anydesk.app/*.{0,1000}\/Applications\/Anydesk\.app\/.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#macosrisk of false positives - compliance detection1010N/AN/AN/AN/A5383
529*/Applications/Managed Workplace/Onsite Manager/logs/*.{0,1000}\/Applications\/Managed\sWorkplace\/Onsite\sManager\/logs\/.{0,1000}greyware_tool_keywordBarracudaRMMDeliver remote support services - formely AVGT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.barracudamsp.com/products/rmm/barracuda-rmm10#linuxN/A1010N/AN/AN/AN/A5384
530*/Applications/MEGAcmd.app*.{0,1000}\/Applications\/MEGAcmd\.app.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10#macosN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z5385
531*/Applications/remoteit.app/*.{0,1000}\/Applications\/remoteit\.app\/.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10#macosN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z5386
532*/Assistance rapide Installer.exe*.{0,1000}\/Assistance\srapide\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A5428
533*/Assistenza rapida Installer.exe*.{0,1000}\/Assistenza\srapida\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A5429
534*/atnow.exe*.{0,1000}\/atnow\.exe.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5454
535*/atnow.zip*.{0,1000}\/atnow\.zip.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5455
536*/AttendedUDP.zip*.{0,1000}\/AttendedUDP\.zip.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A5466
537*/AutoHotkey.exe*.{0,1000}\/AutoHotkey\.exe.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5478
538*/AutoHotkey.git*.{0,1000}\/AutoHotkey\.git.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5479
539*/AutoHotkey/releases/download/*.{0,1000}\/AutoHotkey\/releases\/download\/.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5480
540*/AutoHotkey_*.zip*.{0,1000}\/AutoHotkey_.{0,1000}\.zip.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5481
541*/AutoHotkey_1*_setup.exe*.{0,1000}\/AutoHotkey_1.{0,1000}_setup\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5482
542*/AutoHotkey_2*_setup.exe*.{0,1000}\/AutoHotkey_2.{0,1000}_setup\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5483
543*/AutoHotkey64.exe*.{0,1000}\/AutoHotkey64\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5484
544*/AutoHotkey64.exe*.{0,1000}\/AutoHotkey64\.exe.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5485
545*/Aweray_Remote_*.exe*.{0,1000}\/Aweray_Remote_.{0,1000}\.exe.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A5505
546*/Aweray_Remote_*.zip*.{0,1000}\/Aweray_Remote_.{0,1000}\.zip.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A5506
547*/bin/bash -c 'wg addconf *.{0,1000}\/bin\/bash\s\-c\s\'wg\saddconf\s.{0,1000}greyware_tool_keywordtunnel.pyjam.asSSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://gitlab.com/pyjam.as/tunnel10#linuxN/A1010N/AN/AN/AN/A5623
548*/bin/boringproxy*.{0,1000}\/bin\/boringproxy.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10#linuxN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5624
549*/bin/dataplicity*.{0,1000}\/bin\/dataplicity.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z5625
550*/bin/dropbear*.{0,1000}\/bin\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z5626
551*/bin/meshagent*.{0,1000}\/bin\/meshagent.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10#linuxN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z5635
552*/bin/MeshCommander*.{0,1000}\/bin\/MeshCommander.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10#linuxN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z5636
553*/bin/portr*.{0,1000}\/bin\/portr.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr10#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z5638
554*/bin/rsocks*.{0,1000}\/bin\/rsocks.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10#linuxN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z5651
555*/bin/sh | nc*.{0,1000}\/bin\/sh\s\|\snc.{0,1000}greyware_tool_keywordshellReverse Shell Command LineT1105 - T1021.001 - T1021.002TA0002 - TA0008N/AN/AC2https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_shell_susp_rev_shells.yml10#linuxgreyware tool - risks of False positive !N/A10911523162025-04-17T19:43:35Z2016-12-24T09:48:49Z5652
556*/bin/sh -i <&3 >&3 2>&3*.{0,1000}\/bin\/sh\s\-i\s\<\&3\s\>\&3\s2\>\&3.{0,1000}greyware_tool_keywordshellReverse Shell Command LineT1105 - T1021.001 - T1021.002TA0002 - TA0008N/AN/AC2https://github.com/SigmaHQ/sigma/blob/master/rules/linux/lnx_shell_susp_rev_shells.yml10#linuxgreyware tool - risks of False positive !N/A10911523162025-04-17T19:43:35Z2016-12-24T09:48:49Z5654
557*/bin/staqlab-tunnel*.{0,1000}\/bin\/staqlab\-tunnel.{0,1000}greyware_tool_keywordstaqlab-tunnelExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/cocoflan/Staqlab-tunnel10#linuxN/A1010102020-05-19T06:43:14Z2020-05-19T06:19:31Z5656
558*/bin/syncthing*.{0,1000}\/bin\/syncthing.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing10#linuxhttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z5657
559*/bin/tunnelmole.js*.{0,1000}\/bin\/tunnelmole\.js.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/10#linuxN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z5661
560*/bin/tunwg*.{0,1000}\/bin\/tunwg.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg10#linuxN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z5662
561*/bin/wireproxy*.{0,1000}\/bin\/wireproxy.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy10#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z5665
562*/bin/x64/connectd.exe*.{0,1000}\/bin\/x64\/connectd\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11#linuxN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z5666
563*/bomgar-rep.exe*.{0,1000}\/bomgar\-rep\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5761
564*/bomgar-rep-installer.exe*.{0,1000}\/bomgar\-rep\-installer\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/10N/AN/A1010N/AN/AN/AN/A5762
565*/bomgar-scc-*.exe*.{0,1000}\/bomgar\-scc\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5763
566*/bomgar-scc.exe*.{0,1000}\/bomgar\-scc\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5764
567*/boringproxy.git*.{0,1000}\/boringproxy\.git.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5767
568*/boringproxy-client.service*.{0,1000}\/boringproxy\-client\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5768
569*/boringproxy-server.service*.{0,1000}\/boringproxy\-server\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5769
570*/BoxDrive.msi*.{0,1000}\/BoxDrive\.msi.{0,1000}greyware_tool_keywordBoxAttackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackersT1567.002 - T1071.001 - T1036 - T1048.002TA0005 - TA0010 - TA0009N/AN/AData Exfiltrationhttps://app.box.com/11N/AN/A67N/AN/AN/AN/A5770
571*/btunnel.exe*.{0,1000}\/btunnel\.exe.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A5847
572*/btunnel.log*.{0,1000}\/btunnel\.log.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in10#linuxN/A98N/AN/AN/AN/A5848
573*/cloud.telebit.remote.plist*.{0,1000}\/cloud\.telebit\.remote\.plist.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/10#linuxN/A1010N/AN/AN/AN/A6086
574*/cloudflared.git*.{0,1000}\/cloudflared\.git.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6091
575*/cloudflared/tunnel/*.{0,1000}\/cloudflared\/tunnel\/.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared10#linuxN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6092
576*/cloudflared-linux-*.deb*.{0,1000}\/cloudflared\-linux\-.{0,1000}\.deb.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11#linuxN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6093
577*/cloudflared-linux-*.rpm*.{0,1000}\/cloudflared\-linux\-.{0,1000}\.rpm.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11#linuxN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6094
578*/cmd/tailscaled*.{0,1000}\/cmd\/tailscaled.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z6105
579*/com.tonyseek.rsocks.plist*.{0,1000}\/com\.tonyseek\.rsocks\.plist.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10#linuxN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z6153
580*/config/apps/http/servers/sirtunnel/routes*.{0,1000}\/config\/apps\/http\/servers\/sirtunnel\/routes.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z6181
581*/connectd.aarch64-win.exe*.{0,1000}\/connectd\.aarch64\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z6189
582*/connectd.x86_64-win.exe*.{0,1000}\/connectd\.x86_64\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z6190
583*/Create /TN TVInstallRestore /TR *.{0,1000}\/Create\s\/TN\sTVInstallRestore\s\/TR\s.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/10N/AFP risk - teamviewer usage1010N/AN/AN/AN/A6229
584*/croc.exe*.{0,1000}\/croc\.exe.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6271
585*/croc.service*.{0,1000}\/croc\.service.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc10#linuxN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6272
586*/croc/releases/download/v10*.{0,1000}\/croc\/releases\/download\/v10.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6273
587*/croc/releases/latest*.{0,1000}\/croc\/releases\/latest.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6274
588*/croc-entrypoint.sh*.{0,1000}\/croc\-entrypoint\.sh.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc10#linuxN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6275
589*/crowbar.git*.{0,1000}\/crowbar\.git.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6285
590*/crowbar_1.0.0_darwin_386.zip*.{0,1000}\/crowbar_1\.0\.0_darwin_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6286
591*/crowbar_1.0.0_darwin_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_darwin_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6287
592*/crowbar_1.0.0_freebsd_386.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6288
593*/crowbar_1.0.0_freebsd_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6289
594*/crowbar_1.0.0_freebsd_arm.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_arm\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6290
595*/crowbar_1.0.0_linux_386.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_386\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6291
596*/crowbar_1.0.0_linux_amd64.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_amd64\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6292
597*/crowbar_1.0.0_linux_arm.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_arm\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6293
598*/crowbar_1.0.0_openbsd_386.zip*.{0,1000}\/crowbar_1\.0\.0_openbsd_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6294
599*/crowbar_1.0.0_openbsd_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_openbsd_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6295
600*/crowbar_1.0.0_windows_386.zip*.{0,1000}\/crowbar_1\.0\.0_windows_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6296
601*/crowbar_1.0.0_windows_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_windows_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6297
602*/damewareagent.exe*.{0,1000}\/damewareagent\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A6397
603*/dataplicity.app*.{0,1000}\/dataplicity\.app.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6436
604*/dataplicity.conf*.{0,1000}\/dataplicity\.conf.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6437
605*/dataplicity.log*.{0,1000}\/dataplicity\.log.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6438
606*/dataplicity-agent.git*.{0,1000}\/dataplicity\-agent\.git.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6439
607*/dataplicity-agent/releases/download*.{0,1000}\/dataplicity\-agent\/releases\/download.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6440
608*/docker/compose/zrok-instance/*.{0,1000}\/docker\/compose\/zrok\-instance\/.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z6707
609*/download*mediafire.com/.{0,1000}\/download.{0,1000}mediafire\.com\/greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1083 - T1560TA0009 N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A6750
610*/download/fiddler/fiddler-everywhere-windows*.{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A6751
611*/download/pcunlocker*.{0,1000}\/download\/pcunlocker.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A6754
612*/downloads/ultravnc.html*.{0,1000}\/downloads\/ultravnc\.html.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html11N/AN/A1010N/AN/AN/AN/A6771
613*/dropbear.git*.{0,1000}\/dropbear\.git.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6792
614*/dropbear.init*.{0,1000}\/dropbear\.init.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6793
615*/dropbear.log*.{0,1000}\/dropbear\.log.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6794
616*/dropbear/releases/*.{0,1000}\/dropbear\/releases\/.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6795
617*/dropbear_dss_host_key*.{0,1000}\/dropbear_dss_host_key.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6796
618*/dropbear_rsa_host_key*.{0,1000}\/dropbear_rsa_host_key.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6797
619*/dropbear-sshj.git*.{0,1000}\/dropbear\-sshj\.git.{0,1000}greyware_tool_keywordSSH-J.comThis is Dropbear SSH server modified to be used as a public SSH jump & port forwarding serviceT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://bitbucket.org/ValdikSS/dropbear-sshj/src/master/11N/AN/A1010N/AN/AN/AN/A6798
620*/DuckDNS.7z*.{0,1000}\/DuckDNS\.7z.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6809
621*/DuckDNS.git*.{0,1000}\/DuckDNS\.git.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6810
622*/DuckDNS.zip"*.{0,1000}\/DuckDNS\.zip\".{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6811
623*/duckdns/duck.log*.{0,1000}\/duckdns\/duck\.log.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11#logfile #linuxN/A510N/AN/AN/AN/A6812
624*/duckdns/duck.sh*.{0,1000}\/duckdns\/duck\.sh.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6813
625*/duckdns-powershell.git*.{0,1000}\/duckdns\-powershell\.git.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6814
626*/DumpS1.ps1*.{0,1000}\/DumpS1\.ps1.{0,1000}greyware_tool_keywordSentinelAgentdump a process with SentinelAgent.exeT1003 - T1055TA0006 - TA0005N/AN/ACredential Accesshttps://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e10N/AN/A87N/AN/AN/AN/A6841
627*/dwagent.desktop*.{0,1000}\/dwagent\.desktop.{0,1000}greyware_tool_keyworddwagentThe DWService to remotly control your machine - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://github.com/dwservice/agent10#linuxN/A105471832023-03-22T08:45:16Z2019-01-23T10:40:24Z6857
628*/dwagent.service*.{0,1000}\/dwagent\.service.{0,1000}greyware_tool_keyworddwagentThe DWService to remotly control your machine - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://github.com/dwservice/agent10#linuxN/A105471832023-03-22T08:45:16Z2019-01-23T10:40:24Z6858
629*/dwagsystray*.{0,1000}\/dwagsystray.{0,1000}greyware_tool_keyworddwagentThe DWService to remotly control your machine - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://github.com/dwservice/agent10#linuxN/A105471832023-03-22T08:45:16Z2019-01-23T10:40:24Z6859
630*/DWMRC_St_64.msi*.{0,1000}\/DWMRC_St_64\.msi.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6860
631*/DWRCC.exe*.{0,1000}\/DWRCC\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6861
632*/DWRCCMD.exe*.{0,1000}\/DWRCCMD\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6862
633*/DWRCS.exe*.{0,1000}\/DWRCS\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6863
634*/ehorus_agent_installer-*.{0,1000}\/ehorus_agent_installer\-.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/11N/AN/A1010N/AN/AN/AN/A6906
635*/Eraser 5.8.8.exe*.{0,1000}\/Eraser\s5\.8\.8\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser10N/AN/A710N/AN/AN/AN/A6979
636*/Eraser 6.0.10.2620.exe*.{0,1000}\/Eraser\s6\.0\.10\.2620\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6980
637*/Eraser 6.0.8.2273.exe*.{0,1000}\/Eraser\s6\.0\.8\.2273\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6981
638*/Eraser 6.0.9.2343.exe*.{0,1000}\/Eraser\s6\.0\.9\.2343\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6982
639*/Eraser 6.2.0.2994.exe*.{0,1000}\/Eraser\s6\.2\.0\.2994\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6983
640*/EraserSetup.exe*.{0,1000}\/EraserSetup\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6984
641*/etc/3proxy/conf*.{0,1000}\/etc\/3proxy\/conf.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy10#linuxN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z6989
642*/etc/capabilities/shadowsocks.json*.{0,1000}\/etc\/capabilities\/shadowsocks\.json.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10#linuxN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z6990
643*/etc/crowbar/*.{0,1000}\/etc\/crowbar\/.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar10#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6993
644*/etc/crowbard.conf*.{0,1000}\/etc\/crowbard\.conf.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar10#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6994
645*/etc/dataplicity*.{0,1000}\/etc\/dataplicity.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6995
646*/etc/default/dropbear*.{0,1000}\/etc\/default\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6996
647*/etc/dropbear/*.{0,1000}\/etc\/dropbear\/.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6998
648*/etc/ehorus/ehorus_agent*.{0,1000}\/etc\/ehorus\/ehorus_agent.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/10#linuxN/A1010N/AN/AN/AN/A6999
649*/etc/fleet/fleet.env*.{0,1000}\/etc\/fleet\/fleet\.env.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet10#linuxN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7000
650*/etc/init.d/ehorus_agent_daemon*.{0,1000}\/etc\/init\.d\/ehorus_agent_daemon.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/10#linuxN/A1010N/AN/AN/AN/A7002
651*/etc/letsencrypt/live/jprq.site/*.{0,1000}\/etc\/letsencrypt\/live\/jprq\.site\/.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z7010
652*/etc/level/config.yaml*.{0,1000}\/etc\/level\/config\.yaml.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/10#linuxN/A1010N/AN/AN/AN/A7011
653*/etc/ltproxy.yml*.{0,1000}\/etc\/ltproxy\.yml.{0,1000}greyware_tool_keywordLTProxyLinux Transparent Proxy (Similar to Proxifiter)T1090 - T1573.001 - T1571 - T1071.001TA0010 - TA0005N/AN/AData Exfiltrationhttps://github.com/L-codes/LTProxy10#linuxN/A1013152024-11-27T05:09:47Z2021-11-11T15:17:54Z7012
654*/etc/pagekite.d*.{0,1000}\/etc\/pagekite\.d.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10#linuxN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z7014
655*/etc/pulseway/config.xml*.{0,1000}\/etc\/pulseway\/config\.xml.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/10#linuxN/A1010N/AN/AN/AN/A7017
656*/etc/remoteit/*.{0,1000}\/etc\/remoteit\/.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10#linuxN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z7018
657*/etc/shadowsocks-rust*.{0,1000}\/etc\/shadowsocks\-rust.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10#linuxN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z7021
658*/etc/sshuttle*.{0,1000}\/etc\/sshuttle.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle10#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z7022
659*/etc/systemd/system/anydesk.service*.{0,1000}\/etc\/systemd\/system\/anydesk\.service.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A7026
660*/etc/systemd/system/localtunnel.service*.{0,1000}\/etc\/systemd\/system\/localtunnel\.service.{0,1000}greyware_tool_keywordRust LocaltunnelsLocaltunnel implementation in Rust - exposes your localhost endpoint to the worldT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/kaichaosun/rlt10#linuxN/A72119132024-12-16T09:09:34Z2022-06-27T05:57:34Z7028
661*/etc/wireguard/*.conf*.{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000}greyware_tool_keywordtunnelTunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outsideT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/koding/tunnel10#linuxN/A1010328722023-10-20T13:43:58Z2015-05-28T07:26:42Z7031
662*/etc/wireguard/*.conf*.{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel10#linuxN/A1010N/AN/AN/AN/A7032
663*/etc/wireguard/*.conf*.{0,1000}\/etc\/wireguard\/.{0,1000}\.conf.{0,1000}greyware_tool_keywordtunnel.pyjam.asSSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://gitlab.com/pyjam.as/tunnel10#linuxN/A1010N/AN/AN/AN/A7033
664*/etc/zrok.env*.{0,1000}\/etc\/zrok\.env.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z7035
665*/etc/zrok/*.{0,1000}\/etc\/zrok\/.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z7036
666*/expose/database/expose.db*.{0,1000}\/expose\/database\/expose\.db.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z7151
667*/expose/raw/master/builds/expose*.{0,1000}\/expose\/raw\/master\/builds\/expose.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z7152
668*/Fiddler Everywhere *.*.*.exe*.{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A7190
669*/FileZilla_*_sponsored-setup.exe*.{0,1000}\/FileZilla_.{0,1000}_sponsored\-setup\.exe.{0,1000}greyware_tool_keywordFileZillaFileZilla admintool used by threat actors for persistence and data exfiltrationT1505 - T1041TA0003 - TA0009 -TA0010N/ADispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155Data Exfiltrationhttps://filezilla-project.org/11N/APUA risk of legitimate usage57N/AN/AN/AN/A7199
670*/FileZilla_Server_*.deb*.{0,1000}\/FileZilla_Server_.{0,1000}\.deb.{0,1000}greyware_tool_keywordFileZillaFileZilla admintool used by threat actors for persistence and data exfiltrationT1505 - T1041TA0003 - TA0009 -TA0010N/ADispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155Data Exfiltrationhttps://filezilla-project.org/11N/APUA risk of legitimate usage57N/AN/AN/AN/A7200
671*/fleet_v*_linux.tar.gz*.{0,1000}\/fleet_v.{0,1000}_linux\.tar\.gz.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11#linuxN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7216
672*/fleetd.crx*.{0,1000}\/fleetd\.crx.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7217
673*/fleetdm/fleet/releases/download/*.{0,1000}\/fleetdm\/fleet\/releases\/download\/.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7218
674*/fleetdm/fleet/releases/latest*.{0,1000}\/fleetdm\/fleet\/releases\/latest.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7219
675*/FreeFileSync.exe*.{0,1000}\/FreeFileSync\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7247
676*/FreeFileSync.tar.gz*.{0,1000}\/FreeFileSync\.tar\.gz.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7248
677*/FreeFileSync_*.tar.gz*.{0,1000}\/FreeFileSync_.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7249
678*/FreeFileSync_*_Windows_Setup.exe*.{0,1000}\/FreeFileSync_.{0,1000}_Windows_Setup\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7250
679*/FreeFileSync_x64.exe*.{0,1000}\/FreeFileSync_x64\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7251
680*/FreeFileSyncPortable_*.exe*.{0,1000}\/FreeFileSyncPortable_.{0,1000}\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7252
681*/frp.git*.{0,1000}\/frp\.git.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7258
682*/frp_0.*.*_darwin_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7259
683*/frp_0.*.*_darwin_arm64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_arm64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7260
684*/frp_0.*.*_freebsd_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_freebsd_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7261
685*/frp_0.*.*_linux_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7262
686*/frp_0.*.*_linux_arm.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7263
687*/frp_0.*.*_linux_arm64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7264
688*/frp_0.*.*_linux_mips.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7265
689*/frp_0.*.*_linux_mips64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7266
690*/frp_0.*.*_linux_mips64le.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64le\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7267
691*/frp_0.*.*_linux_mipsle.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mipsle\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7268
692*/frpc.exe*.{0,1000}\/frpc\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7270
693*/frpc-mem.log*.{0,1000}\/frpc\-mem\.log.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole10#linuxN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z7271
694*/frps-mem.log*.{0,1000}\/frps\-mem\.log.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole10#linuxN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z7272
695*/genacl_proxy_gfw_bypass_china_ip.py.{0,1000}\/genacl_proxy_gfw_bypass_china_ip\.pygreyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10#linuxN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z7347
696*/github.com*.exe?raw=true*.{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7414
697*/github.com/*/archive/refs/tags/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7415
698*/github.com/*/raw/main/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7416
699*/github.com/*/raw/main/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7417
700*/github.com/*/raw/main/*.app*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7418
701*/github.com/*/raw/main/*.as*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7419
702*/github.com/*/raw/main/*.asc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7420
703*/github.com/*/raw/main/*.asp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7421
704*/github.com/*/raw/main/*.bash*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11#linuxgreyware tool - risks of False positive !910N/AN/AN/AN/A7422
705*/github.com/*/raw/main/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7423
706*/github.com/*/raw/main/*.beacon*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7424
707*/github.com/*/raw/main/*.bin*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7425
708*/github.com/*/raw/main/*.bpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7426
709*/github.com/*/raw/main/*.c*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7427
710*/github.com/*/raw/main/*.cer*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7428
711*/github.com/*/raw/main/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7429
712*/github.com/*/raw/main/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7430
713*/github.com/*/raw/main/*.cpp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7431
714*/github.com/*/raw/main/*.crt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7432
715*/github.com/*/raw/main/*.cs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7433
716*/github.com/*/raw/main/*.csh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7434
717*/github.com/*/raw/main/*.dat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7435
718*/github.com/*/raw/main/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7436
719*/github.com/*/raw/main/*.docm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7437
720*/github.com/*/raw/main/*.dos*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7438
721*/github.com/*/raw/main/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7439
722*/github.com/*/raw/main/*.go*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7440
723*/github.com/*/raw/main/*.gz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7441
724*/github.com/*/raw/main/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7442
725*/github.com/*/raw/main/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7443
726*/github.com/*/raw/main/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7444
727*/github.com/*/raw/main/*.js*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7445
728*/github.com/*/raw/main/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7446
729*/github.com/*/raw/main/*.log*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7447
730*/github.com/*/raw/main/*.mac*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7448
731*/github.com/*/raw/main/*.mam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7449
732*/github.com/*/raw/main/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7450
733*/github.com/*/raw/main/*.msp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7451
734*/github.com/*/raw/main/*.nexe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7452
735*/github.com/*/raw/main/*.nim*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7453
736*/github.com/*/raw/main/*.otm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7454
737*/github.com/*/raw/main/*.out*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7455
738*/github.com/*/raw/main/*.ova*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7456
739*/github.com/*/raw/main/*.pem*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7457
740*/github.com/*/raw/main/*.pfx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7458
741*/github.com/*/raw/main/*.pl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7459
742*/github.com/*/raw/main/*.plx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7460
743*/github.com/*/raw/main/*.pm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7461
744*/github.com/*/raw/main/*.ppk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7462
745*/github.com/*/raw/main/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7463
746*/github.com/*/raw/main/*.psm1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7464
747*/github.com/*/raw/main/*.pub*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7465
748*/github.com/*/raw/main/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7466
749*/github.com/*/raw/main/*.pyc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7467
750*/github.com/*/raw/main/*.pyo*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7468
751*/github.com/*/raw/main/*.rar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7469
752*/github.com/*/raw/main/*.raw*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7470
753*/github.com/*/raw/main/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7471
754*/github.com/*/raw/main/*.rgs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7472
755*/github.com/*/raw/main/*.RGS*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7473
756*/github.com/*/raw/main/*.run*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7474
757*/github.com/*/raw/main/*.scpt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7475
758*/github.com/*/raw/main/*.script*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7476
759*/github.com/*/raw/main/*.sct*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7477
760*/github.com/*/raw/main/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7478
761*/github.com/*/raw/main/*.ssh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7479
762*/github.com/*/raw/main/*.sys*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7480
763*/github.com/*/raw/main/*.teamserver*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7481
764*/github.com/*/raw/main/*.temp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7482
765*/github.com/*/raw/main/*.tgz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7483
766*/github.com/*/raw/main/*.tmp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7484
767*/github.com/*/raw/main/*.vb*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7485
768*/github.com/*/raw/main/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7486
769*/github.com/*/raw/main/*.vbscript*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7487
770*/github.com/*/raw/main/*.ws*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7488
771*/github.com/*/raw/main/*.wsf*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7489
772*/github.com/*/raw/main/*.wsh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7490
773*/github.com/*/raw/main/*.X86*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7491
774*/github.com/*/raw/main/*.X86_64*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7492
775*/github.com/*/raw/main/*.xlam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7493
776*/github.com/*/raw/main/*.xlm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7494
777*/github.com/*/raw/main/*.xlsm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7495
778*/github.com/*/raw/main/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7496
779*/github.com/*/raw/refs/heads/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7497
780*/github.com/*/raw/refs/heads/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7498
781*/github.com/*/raw/refs/heads/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7499
782*/github.com/*/raw/refs/heads/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7500
783*/github.com/*/raw/refs/heads/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7501
784*/github.com/*/raw/refs/heads/*.cpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7502
785*/github.com/*/raw/refs/heads/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7503
786*/github.com/*/raw/refs/heads/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7504
787*/github.com/*/raw/refs/heads/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7505
788*/github.com/*/raw/refs/heads/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7506
789*/github.com/*/raw/refs/heads/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7507
790*/github.com/*/raw/refs/heads/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7508
791*/github.com/*/raw/refs/heads/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7509
792*/github.com/*/raw/refs/heads/*.pif*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7510
793*/github.com/*/raw/refs/heads/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7511
794*/github.com/*/raw/refs/heads/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7512
795*/github.com/*/raw/refs/heads/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7513
796*/github.com/*/raw/refs/heads/*.scr*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7514
797*/github.com/*/raw/refs/heads/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7515
798*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7516
799*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7517
800*/github.com/*/raw/refs/heads/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7518
801*/go-gost/core/*.{0,1000}\/go\-gost\/core\/.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7563
802*/go-http-tunnel.git.git*.{0,1000}\/go\-http\-tunnel\.git\.git.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel11N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z7564
803*/go-http-tunnel/cmd/*.{0,1000}\/go\-http\-tunnel\/cmd\/.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel11N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z7565
804*/go-localtunnel.git*.{0,1000}\/go\-localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/NoahShen/gotunnelme11N/AN/A1010171452018-01-06T04:41:15Z2013-10-18T02:46:51Z7570
805*/GoodSync-vsub-Setup.exe*.{0,1000}\/GoodSync\-vsub\-Setup\.exe.{0,1000}greyware_tool_keywordGoodsyncGoodSync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/AN/AData Exfiltrationhttps://www.goodsync.com/11N/AN/A910N/AN/AN/AN/A7579
806*/gost.tar.gz*.{0,1000}\/gost\.tar\.gz.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7597
807*/gost/raw/master/install.sh*.{0,1000}\/gost\/raw\/master\/install\.sh.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7598
808*/gost/releases/download/*.tar.gz*.{0,1000}\/gost\/releases\/download\/.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7599
809*/gotunnelme.git*.{0,1000}\/gotunnelme\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/NoahShen/gotunnelme11N/AN/A1010171452018-01-06T04:41:15Z2013-10-18T02:46:51Z7603
810*/gt server -c ./config.yml*.{0,1000}\/gt\sserver\s\-c\s\.\/config\.yml.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt10#linuxN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z7671
811*/gt-win-x86_64.exe*.{0,1000}\/gt\-win\-x86_64\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z7682
812*/home/*/.anydesk/*.{0,1000}\/home\/.{0,1000}\/\.anydesk\/.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A7790
813*/home/boringproxy*.{0,1000}\/home\/boringproxy.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy10#linuxN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z7792
814*/home/sshuttle*.{0,1000}\/home\/sshuttle.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle10#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z7798
815*/home/user/rustdesk*.{0,1000}\/home\/user\/rustdesk.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk10#linuxN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z7801
816*/host-7.2.2.0.msi*.{0,1000}\/host\-7\.2\.2\.0\.msi.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A7810
817*/http-put-server.py*.{0,1000}\/http\-put\-server\.py.{0,1000}greyware_tool_keywordexegolFully featured and community-driven hacking environment with hundreds of offensive toolsT1218 - T1140 - T1543 - T1095 - T1571 - T1547 - T1078 - T1559TA0043 - TA0002 - TA0004 - TA0011 - TA0003N/ABlack BastaExploitation toolhttps://github.com/ThePorgs/Exegol10#linuxN/A101023542092025-04-09T16:56:24Z2020-03-09T19:12:11Z7914
818*/hypertunnel.git*.{0,1000}\/hypertunnel\.git.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7992
819*/hypertunnel-tcp-relay*.tar.gz*.{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7993
820*/hypertunnel-tcp-relay*.zip*.{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.zip.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7994
821*/install-fleetctl.sh*.{0,1000}\/install\-fleetctl\.sh.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z8101
822*/interactsh/*.{0,1000}\/interactsh\/.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C5T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8106
823*/interactsh-client*.{0,1000}\/interactsh\-client.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C6T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8107
824*/interactsh-collaborator*.{0,1000}\/interactsh\-collaborator.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C15T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8108
825*/interactsh-server*.{0,1000}\/interactsh\-server.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C8T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8109
826*/Invoke-Maldaptive.git*.{0,1000}\/Invoke\-Maldaptive\.git.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive11N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z8153
827*/IObitUnlocker.exe*.{0,1000}\/IObitUnlocker\.exe.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#11N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A8172
828*/ipscan.exe*.{0,1000}\/ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8199
829*/ipscan.git*.{0,1000}\/ipscan\.git.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8200
830*/ipscan_*_amd64.deb*.{0,1000}\/ipscan_.{0,1000}_amd64\.deb.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#linuxN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8201
831*/ipscan2-binary/*.exe*.{0,1000}\/ipscan2\-binary\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8202
832*/ipscan-any-*.jar*.{0,1000}\/ipscan\-any\-.{0,1000}\.jar.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#linuxN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8203
833*/jprq.git*.{0,1000}\/jprq\.git.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8251
834*/jprq.log*.{0,1000}\/jprq\.log.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8252
835*/jprq.service*.{0,1000}\/jprq\.service.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8253
836*/jprq/server/*.go*.{0,1000}\/jprq\/server\/.{0,1000}\.go.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8254
837*/jprq-darwin-arm64*.{0,1000}\/jprq\-darwin\-arm64.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8255
838*/jprq-linux-386*.{0,1000}\/jprq\-linux\-386.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8256
839*/jprq-linux-arm64*.{0,1000}\/jprq\-linux\-arm64.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8257
840*/jprq-windows-386.exe*.{0,1000}\/jprq\-windows\-386\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8258
841*/jprq-windows-amd64.exe*.{0,1000}\/jprq\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8259
842*/keygen.exe*.{0,1000}\/keygen\.exe.{0,1000}greyware_tool_keyword_generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwaresT1204 - T1027 - T1059 - T1055 - T1060 - T1195TA0005 - TA0002 - TA0011N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A8341
843*/killProcessPOC.git*.{0,1000}\/killProcessPOC\.git.{0,1000}greyware_tool_keywordkillProcessPOCuse Avast (aswArPot.sys) to kill process - exploited by MONTI ransomwareT1055 - T1106 - T1560.002 - T1569TA0005Monti ransomwareN/ADefense Evasionhttps://github.com/timwhitez/killProcessPOC10N/Ahttps://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf1016782022-08-26T03:20:09Z2022-04-27T08:25:50Z8368
844*/lansearch.exe*.{0,1000}\/lansearch\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A8435
845*/LansweeperSetup_*.exe*.{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/11N/AN/A67N/AN/AN/AN/A8436
846*/latest/download/tunwg*.{0,1000}\/latest\/download\/tunwg.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z8453
847*/ld.so /bin/sh -p*.{0,1000}\/ld\.so\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z8463
848*/level-windows-amd64.exe*.{0,1000}\/level\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A8492
849*/level-windows-arm64.exe*.{0,1000}\/level\-windows\-arm64\.exe.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A8493
850*/libexec/softether/vpnserver/vpnserver*.{0,1000}\/libexec\/softether\/vpnserver\/vpnserver.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN10#VPN #linuxN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z8502
851*/Library/Logs/SPLog.txt*.{0,1000}\/Library\/Logs\/SPLog\.txt.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://ruler-project.github.io/ruler-project/RULER/remote/Splashtop/10#linuxN/A1010N/AN/AN/AN/A8507
852*/linux_x64_admin*.{0,1000}\/linux_x64_admin.{0,1000}greyware_tool_keywordstowawayStowaway -- Multi-hop Proxy Tool for pentestersT1021 - T1090 - T1071 - T1573TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/ph4ntonn/Stowaway10#linuxN/A101029894222025-04-05T14:48:38Z2019-11-15T03:25:50Z8542
853*/linux_x64_agent*.{0,1000}\/linux_x64_agent.{0,1000}greyware_tool_keywordstowawayStowaway -- Multi-hop Proxy Tool for pentestersT1021 - T1090 - T1071 - T1573TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/ph4ntonn/Stowaway10#linuxN/A101029894222025-04-05T14:48:38Z2019-11-15T03:25:50Z8543
854*/linux_x86_admin*.{0,1000}\/linux_x86_admin.{0,1000}greyware_tool_keywordstowawayStowaway -- Multi-hop Proxy Tool for pentestersT1021 - T1090 - T1071 - T1573TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/ph4ntonn/Stowaway10#linuxN/A101029894222025-04-05T14:48:38Z2019-11-15T03:25:50Z8544
855*/linux_x86_agent*.{0,1000}\/linux_x86_agent.{0,1000}greyware_tool_keywordstowawayStowaway -- Multi-hop Proxy Tool for pentestersT1021 - T1090 - T1071 - T1573TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/ph4ntonn/Stowaway10#linuxN/A101029894222025-04-05T14:48:38Z2019-11-15T03:25:50Z8545
856*/LMI_Rescue.exe*.{0,1000}\/LMI_Rescue\.exe.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A8558
857*/LMIRTechConsole.exe*.{0,1000}\/LMIRTechConsole\.exe.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A8559
858*/localtunnel.git*.{0,1000}\/localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8596
859*/localtunnel.git*.{0,1000}\/localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnelsclient for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/localtunnel11N/AN/A8102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8597
860*/localtunnel.js*.{0,1000}\/localtunnel\.js.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8598
861*/localtunnel-linux-*.tar*.{0,1000}\/localtunnel\-linux\-.{0,1000}\.tar.{0,1000}greyware_tool_keywordRust LocaltunnelsLocaltunnel implementation in Rust - exposes your localhost endpoint to the worldT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/kaichaosun/rlt10#linuxN/A72119132024-12-16T09:09:34Z2022-06-27T05:57:34Z8599
862*/localtunnel-server.git*.{0,1000}\/localtunnel\-server\.git.{0,1000}greyware_tool_keywordlocaltunnelsserver for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/server11N/AN/A810316310332024-03-20T09:14:46Z2013-06-16T22:30:48Z8600
863*/loclx.exe*.{0,1000}\/loclx\.exe.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A8606
864*/loclx-windows-amd64.zip*.{0,1000}\/loclx\-windows\-amd64\.zip.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A8607
865*/log/anydesk.trace*.{0,1000}\/log\/anydesk\.trace.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-003/10#linuxrisk of false positives - compliance detection1010N/AN/AN/AN/A8608
866*/lsa-whisperer-*.zip*.{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8658
867*/lsa-whisperer.git*.{0,1000}\/lsa\-whisperer\.git.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8659
868*/LTProxy.git*.{0,1000}\/LTProxy\.git.{0,1000}greyware_tool_keywordLTProxyLinux Transparent Proxy (Similar to Proxifiter)T1090 - T1573.001 - T1571 - T1071.001TA0010 - TA0005N/AN/AData Exfiltrationhttps://github.com/L-codes/LTProxy11#linuxN/A1013152024-11-27T05:09:47Z2021-11-11T15:17:54Z8660
869*/MEGAclient.exe*.{0,1000}\/MEGAclient\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8734
870*/MEGAcmd.exe*.{0,1000}\/MEGAcmd\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8735
871*/MEGAcmd.sh*.{0,1000}\/MEGAcmd\.sh.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8736
872*/MEGAcmdServer.exe*.{0,1000}\/MEGAcmdServer\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8737
873*/MEGAcmdSetup.exe*.{0,1000}\/MEGAcmdSetup\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8738
874*/MEGAcmdSetup32.exe*.{0,1000}\/MEGAcmdSetup32\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8739
875*/MEGAcmdSetup64.exe*.{0,1000}\/MEGAcmdSetup64\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8740
876*/MEGAcmdSetup64.exe*.{0,1000}\/MEGAcmdSetup64\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8741
877*/MEGAcmdShell.exe*.{0,1000}\/MEGAcmdShell\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8742
878*/MEGAcmdUpdater.app*.{0,1000}\/MEGAcmdUpdater\.app.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd10#macosN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8743
879*/megasync.exe*.{0,1000}\/megasync\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8744
880*/MEGAsyncSetup32.exe*.{0,1000}\/MEGAsyncSetup32\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8745
881*/MEGAsyncSetup64.exe*.{0,1000}\/MEGAsyncSetup64\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8746
882*/megatools.exe*.{0,1000}\/megatools\.exe.{0,1000}greyware_tool_keywordmegatoolsMegatools is a collection of free and open source programs for accessing Mega service from a command line. Abused by attackers for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/megous/megatools10N/AN/A910N/AN/AN/AN/A8747
883*/MeshAgent --*.{0,1000}\/MeshAgent\s\-\-.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10#linuxN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8774
884*/MeshAgent.git*.{0,1000}\/MeshAgent\.git.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshAgent11N/AN/A103264962025-03-19T18:43:56Z2017-10-12T21:26:52Z8775
885*/MeshCentral.git*.{0,1000}\/MeshCentral\.git.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8776
886*/meshcentral.service*.{0,1000}\/meshcentral\.service.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral10#linuxN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8777
887*/meshinstall.sh*.{0,1000}\/meshinstall\.sh.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8778
888*/meshinstall-bsd-rcd.sh*.{0,1000}\/meshinstall\-bsd\-rcd\.sh.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8779
889*/Microsoft Azure Storage Explorer.app*.{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.app.{0,1000}greyware_tool_keywordAzure Storage Explorerlegitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data ExfiltrationT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ARhysidaData Exfiltrationhttps://azure.microsoft.com/en-us/products/storage/storage-explorer11N/AN/A810N/AN/AN/AN/A8812
890*/Microsoft Azure Storage Explorer.zip*.{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.zip.{0,1000}greyware_tool_keywordAzure Storage Explorerlegitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data ExfiltrationT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ARhysidaData Exfiltrationhttps://azure.microsoft.com/en-us/products/storage/storage-explorer11N/AN/A810N/AN/AN/AN/A8813
891*/MITMPluginLogViewer*.{0,1000}\/MITMPluginLogViewer.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z8865
892*/MITMServerHijacking*.{0,1000}\/MITMServerHijacking.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z8867
893*/mzcv.exe*.{0,1000}\/mzcv\.exe.{0,1000}greyware_tool_keywordMozillaCookiesViewnirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actorsT1070 - T1552.001 - T1125 - T1005TA0009 - TA0005N/AMuddyWaterCredential Accesshttps://www.nirsoft.net/utils/mzcv.html10N/AN/A710N/AN/AN/AN/A8993
894*/mzcv-x64.zip*.{0,1000}\/mzcv\-x64\.zip.{0,1000}greyware_tool_keywordMozillaCookiesViewnirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actorsT1070 - T1552.001 - T1125 - T1005TA0009 - TA0005N/AMuddyWaterCredential Accesshttps://www.nirsoft.net/utils/mzcv.html11N/AN/A710N/AN/AN/AN/A8994
895*/NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True*.{0,1000}\/NAMESPACE\:\\\\root\\Microsoft\\Windows\\Defender\sPATH\sMSFT_MpPreference\scall\sAdd\sExclusionExtension\=exe\sForce\=True.{0,1000}greyware_tool_keywordwmicWindows Defender Tampering Via WmicT1489TA0005N/AMAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEARDefense Evasionhttps://www.virustotal.com/gui/file/00820a1f0972678cfe7885bc989ab3e5602b0febc96baf9bf3741d56aa374f03/behavior10N/AN/A1010N/AN/AN/AN/A9007
896*/nats-rmm.conf*.{0,1000}\/nats\-rmm\.conf.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z9019
897*/nc64 -i *.{0,1000}\/nc64\s\-i\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9027
898*/nc64 -lvp *.{0,1000}\/nc64\s\-lvp\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9028
899*/nc64 -zv *.{0,1000}\/nc64\s\-zv\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9029
900*/neoreg.py*.{0,1000}\/neoreg\.py.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9047
901*/Neo-reGeorg.git*.{0,1000}\/Neo\-reGeorg\.git.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9048
902*/NeoreGeorg.java*.{0,1000}\/NeoreGeorg\.java.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9049
903*/Neo-reGeorg/tarball*.{0,1000}\/Neo\-reGeorg\/tarball.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9050
904*/Neo-reGeorg/zipball*.{0,1000}\/Neo\-reGeorg\/zipball.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9051
905*/netcat-win32-*.zip*.{0,1000}\/netcat\-win32\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordnetcatncat reverse shellT1105 - T1021.001 - T1021.002TA0002 - TA0008N/AAPT15 - Calypso - EMBER BEAR - Black BastaC2https://nmap.org/ncat/10#linuxgreyware tool - risks of False positive !1010N/AN/AN/AN/A9086
906*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/Anetwork exploitation tool610N/AN/AN/AN/A9108
907*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9109
908*/netscan_linux.tar.gz*.{0,1000}\/netscan_linux\.tar\.gz.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#linuxN/A810N/AN/AN/AN/A9110
909*/netscan_macos.dmg*.{0,1000}\/netscan_macos\.dmg.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#macosN/A810N/AN/AN/AN/A9111
910*/netscan_setup.exe*.{0,1000}\/netscan_setup\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9112
911*/netscan64.exe*.{0,1000}\/netscan64\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9113
912*/netshrun.c*.{0,1000}\/netshrun\.c.{0,1000}greyware_tool_keywordNetshRunNetsh.exe relies on extensions taken from Registry which means it may be used as a persistence and you go one step further extending netsh with a DLL allowing you to do whatever you wantT1546.008 - T1112 - T1037 - T1055 - T1218.001TA0003 - TA0002 - TA0008N/AN/AExploitation toolhttps://github.com/gtworek/PSBits/blob/master/NetShRun11N/AN/AN/A1033375422025-03-12T19:59:23Z2019-06-29T13:22:36Z9117
913*/ngrok.exe*.{0,1000}\/ngrok\.exe.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md10N/AN/A101015941982025-04-16T21:16:51Z2021-08-16T17:34:25Z9136
914*/ngrok.git*.{0,1000}\/ngrok\.git.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9137
915*/ngrok.go*.{0,1000}\/ngrok\.go.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9138
916*/ngrok.log*.{0,1000}\/ngrok\.log.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok10#linuxN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9139
917*/ngrokd.go*.{0,1000}\/ngrokd\.go.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9140
918*/ngrokroot.crt*.{0,1000}\/ngrokroot\.crt.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok10#linuxN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9143
919*/NimScan.exe*.{0,1000}\/NimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9175
920*/NimScan.git*.{0,1000}\/NimScan\.git.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9176
921*/NimScan.nim*.{0,1000}\/NimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9177
922*/nircmd.exe*.{0,1000}\/nircmd\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9184
923*/nircmd.zip*.{0,1000}\/nircmd\.zip.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9185
924*/nircmdc.exe*.{0,1000}\/nircmdc\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9186
925*/nircmd-x64.zip*.{0,1000}\/nircmd\-x64\.zip.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9187
926*/Nmap/folder/check15*.{0,1000}\/Nmap\/folder\/check15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9198
927*/Nmap/folder/check16*.{0,1000}\/Nmap\/folder\/check16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9199
928*/Nmap/folder/check17*.{0,1000}\/Nmap\/folder\/check17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9200
929*/nmaplowercheck15*.{0,1000}\/nmaplowercheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://nmap.org/book/nse-usage.html11N/Awill appear on your server access logs if you are scanned by nmap810N/AN/AN/AN/A9204
930*/nmaplowercheck16*.{0,1000}\/nmaplowercheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9205
931*/nmaplowercheck17*.{0,1000}\/nmaplowercheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9206
932*/nmap-nse-scripts*.{0,1000}\/nmap\-nse\-scripts.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install10#linuxN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9207
933*/nmap-scada*.{0,1000}\/nmap\-scada.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9208
934*/NmapUpperCheck15*.{0,1000}\/NmapUpperCheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9209
935*/NmapUpperCheck16*.{0,1000}\/NmapUpperCheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9210
936*/NmapUpperCheck17*.{0,1000}\/NmapUpperCheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9211
937*/nmap-vulners*.{0,1000}\/nmap\-vulners.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9212
938*/nse_install/*.{0,1000}\/nse_install\/.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install10#linuxN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9259
939*/nse-install.git*.{0,1000}\/nse\-install\.git.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9260
940*/nspowershell.exe*.{0,1000}\/nspowershell\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A9264
941*/nssadmui.exe*.{0,1000}\/nssadmui\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A9265
942*/OfflineSamTool.exe*.{0,1000}\/OfflineSamTool\.exe.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9370
943*/openvpn.exe*.{0,1000}\/openvpn\.exe.{0,1000}greyware_tool_keywordOPENVPNOpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate dataT1071 - T1573 - T1133TA0003 - TA0008 - TA0011N/AN/ADefense Evasionhttps://openvpn.net/11#VPNN/A68N/AN/AN/AN/A9396
944*/opt/config/aonetwork-client.yml*.{0,1000}\/opt\/config\/aonetwork\-client\.yml.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt10#linuxN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z9404
945*/opt/dataplicity/*.{0,1000}\/opt\/dataplicity\/.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent10#linuxN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z9406
946*/opt/duckdns/*.{0,1000}\/opt\/duckdns\/.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp10#linuxN/A510N/AN/AN/AN/A9408
947*/opt/entrypoint.sh*.{0,1000}\/opt\/entrypoint\.sh.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt10#linuxN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z9409
948*/opt/remoteit/remoteit*.{0,1000}\/opt\/remoteit\/remoteit.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop10#linuxN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z9428
949*/opt/rsocks/*.{0,1000}\/opt\/rsocks\/.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10#linuxN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z9429
950*/opt/telebit*.{0,1000}\/opt\/telebit.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/10#linuxN/A1010N/AN/AN/AN/A9433
951*/oset.exe*.{0,1000}\/oset\.exe.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9447
952*/oset.zip*.{0,1000}\/oset\.zip.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9448
953*/oshi_run.pl*.{0,1000}\/oshi_run\.pl.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload10#linux #filehostingserviceN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z9449
954*/OshiUpload.git*.{0,1000}\/OshiUpload\.git.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload11#filehostingservice #P2PN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z9450
955*/PAExec.cpp*.{0,1000}\/PAExec\.cpp.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9480
956*/paexec.exe.{0,1000}\/paexec\.exegreyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9481
957*/PAExec.git*.{0,1000}\/PAExec\.git.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9482
958*/paexec_eula.txt*.{0,1000}\/paexec_eula\.txt.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec10N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9483
959*/pagekite-*.log*.{0,1000}\/pagekite\-.{0,1000}\.log.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10#linuxN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9484
960*/pagekite.log*.{0,1000}\/pagekite\.log.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10#linuxN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9485
961*/pagekite.py*.{0,1000}\/pagekite\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9486
962*/pagekite-0.3.21.py*.{0,1000}\/pagekite\-0\.3\.21\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9487
963*/pagekite-0.4.6a.py*.{0,1000}\/pagekite\-0\.4\.6a\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9488
964*/pagekite-0.5.6d.py*.{0,1000}\/pagekite\-0\.5\.6d\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9489
965*/pagekite-0.5.8a.py*.{0,1000}\/pagekite\-0\.5\.8a\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9490
966*/pagekite-gtk.py*.{0,1000}\/pagekite\-gtk\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9491
967*/pagekite-tmp.py*.{0,1000}\/pagekite\-tmp\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite10#linuxN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9492
968*/PAYMENTS.exe*.{0,1000}\/PAYMENTS\.exe.{0,1000}greyware_tool_keyword_suspicious file name - has been used by threat actorsT1566TA0001N/AN/APhishingN/A10N/AN/A1010N/AN/AN/AN/A9567
969*/PCHunter.exe*.{0,1000}\/PCHunter\.exe.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A9569
970*/PCHunter_free.zip*.{0,1000}\/PCHunter_free\.zip.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A9570
971*/pcictlui.exe*.{0,1000}\/pcictlui\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/10N/AN/A1010N/AN/AN/AN/A9571
972*/PCIDEPLY.exe*.{0,1000}\/PCIDEPLY\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/10N/AN/A1010N/AN/AN/AN/A9572
973*/PCMonitorManager.exe*.{0,1000}\/PCMonitorManager\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9573
974*/PCMonitorSrv.exe*.{0,1000}\/PCMonitorSrv\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9574
975*/pcmontask.exe*.{0,1000}\/pcmontask\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A9575
976*/pcmrdp-client.dll*.{0,1000}\/pcmrdp\-client\.dll.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9576
977*/pcunlocker.iso*.{0,1000}\/pcunlocker\.iso.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A9577
978*/pcunlocker_trial.zip*.{0,1000}\/pcunlocker_trial\.zip.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A9578
979*/perf stat /bin/sh -p*.{0,1000}\/perf\sstat\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z9602
980*/perl -e 'exec \"/bin/sh\"*.{0,1000}\/perl\s\-e\s\'exec\s\\\"\/bin\/sh\\\".{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z9607
981*/pgrok.exe*.{0,1000}\/pgrok\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok11N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z9651
982*/pgrok.git*.{0,1000}\/pgrok\.git.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok11N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9652
983*/pgrok.yml*.{0,1000}\/pgrok\.yml.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok10#linuxN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9653
984*/pgrokd.exe*.{0,1000}\/pgrokd\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok11N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z9654
985*/pgrokd.yml.{0,1000}\/pgrokd\.ymlgreyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok10#linuxN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9655
986*/pgrokd_*.zip*.{0,1000}\/pgrokd_.{0,1000}\.zip.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok11N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9656
987*/pingcastle.git*.{0,1000}\/pingcastle\.git.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9695
988*/PingCastle.zip*.{0,1000}\/PingCastle\.zip.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9696
989*/pingcastle/releases/download/*.{0,1000}\/pingcastle\/releases\/download\/.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9697
990*/PortQry.exe*.{0,1000}\/PortQry\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9748
991*/PortQryV2.exe*.{0,1000}\/PortQryV2\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9749
992*/portr.exe*.{0,1000}\/portr\.exe.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9750
993*/portr.git*.{0,1000}\/portr\.git.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9751
994*/portr/releases*.{0,1000}\/portr\/releases.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9752
995*/portr_*_Darwin_arm64.zip*.{0,1000}\/portr_.{0,1000}_Darwin_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9753
996*/portr_*_Darwin_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Darwin_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9754
997*/portr_*_Linux_arm64.zip*.{0,1000}\/portr_.{0,1000}_Linux_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9755
998*/portr_*_Linux_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Linux_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9756
999*/portr_*_Windows_arm64.zip*.{0,1000}\/portr_.{0,1000}_Windows_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9757
1000*/portr_*_Windows_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Windows_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9758
1001*/portr_admin/*.py*.{0,1000}\/portr_admin\/.{0,1000}\.py.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9759
1002*/privoxy.exe*.{0,1000}\/privoxy\.exe.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z9904
1003*/Procdump.zip*.{0,1000}\/Procdump\.zip.{0,1000}greyware_tool_keywordProcdumpdump lsass process with procdumpT1003.001TA0006N/ALockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - DispossessorCredential Accesshttps://learn.microsoft.com/en-us/sysinternals/downloads/procdump11N/AN/A1010N/AN/AN/AN/A9907
1004*/processhacker-*-bin.zip*.{0,1000}\/processhacker\-.{0,1000}\-bin\.zip.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9910
1005*/processhacker/files/latest/download*.{0,1000}\/processhacker\/files\/latest\/download.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9911
1006*/ProduKey.exe*.{0,1000}\/ProduKey\.exe.{0,1000}greyware_tool_keywordprodukeyProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.T1003.001 - T1003.002 - T1012 - T1057 - T1518TA0006 - TA0007 - TA0009N/AEvilnumCredential Accesshttps://www.nirsoft.net/utils/product_cd_key_viewer.html11N/AN/A610N/AN/AN/AN/A9915
1007*/Proxifier.app/Contents/MacOS/Proxifier*.{0,1000}\/Proxifier\.app\/Contents\/MacOS\/Proxifier.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/10#macosN/A89N/AN/AN/AN/A9928
1008*/Proxifier.exe*.{0,1000}\/Proxifier\.exe.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9929
1009*/Proxifier/Proxifier.app/*.{0,1000}\/Proxifier\/Proxifier\.app\/.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/10#macosN/A89N/AN/AN/AN/A9930
1010*/ProxifierPE.zip*.{0,1000}\/ProxifierPE\.zip.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9931
1011*/ProxifierSetup.exe*.{0,1000}\/ProxifierSetup\.exe.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9932
1012*/ps2exe.ps1*.{0,1000}\/ps2exe\.ps1.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill11N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z9952
1013*/pslist.exe*.{0,1000}\/pslist\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9972
1014*/pslist64.exe*.{0,1000}\/pslist64\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9973
1015*/pulseway_x64.deb*.{0,1000}\/pulseway_x64\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10002
1016*/Pulseway_x64.msi*.{0,1000}\/Pulseway_x64\.msi.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10003
1017*/pulseway_x86.deb*.{0,1000}\/pulseway_x86\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10004
1018*/pwn_tclsh.me*.{0,1000}\/pwn_tclsh\.me.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10046
1019*/py2exe/*.{0,1000}\/py2exe\/.{0,1000}greyware_tool_keywordpy2exepy2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attackerT1027.002 - T1045 - T1059.001 - T1587.001TA0005 - TA0042Operation WocaoN/AResource Developmenthttps://github.com/py2exe/py2exe11N/Agreyware_tools high risks of false positivesN/A109271022024-11-12T19:44:34Z2019-03-11T13:16:35Z10061
1020*/pyinstaller/*.{0,1000}\/pyinstaller\/.{0,1000}greyware_tool_keywordpyinstallerPyInstaller bundles a Python application and all its dependencies into a single package executable.T1027.002 - T1045 - T1059.001 - T1587.001TA0005 - TA0042N/AN/AResource Developmenthttps://www.pyinstaller.org/10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A10069
1021*/pyjam.as/tunnel*.{0,1000}\/pyjam\.as\/tunnel.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel11N/AN/A1010N/AN/AN/AN/A10070
1022*/PyPagekite.git*.{0,1000}\/PyPagekite\.git.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10083
1023*/PyPagekite/tarball/*.{0,1000}\/PyPagekite\/tarball\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10084
1024*/PyPagekite/zipball/*.{0,1000}\/PyPagekite\/zipball\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10085
1025*/pyshark.git*.{0,1000}\/pyshark\.git.{0,1000}greyware_tool_keywordpysharkPython wrapper for tshark allowing python packet parsing using wireshark dissectorsT1040 - T1213 - T1105 - T1572TA0009 - TA0007N/AN/ADiscoveryhttps://github.com/KimiNewt/pyshark11N/AN/A61023554392024-12-04T15:41:20Z2013-12-28T14:38:22Z10096
1026*/QNAP_NAS/megacmdpkg*.{0,1000}\/QNAP_NAS\/megacmdpkg.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z10116
1027*/Quasar.git*.{0,1000}\/Quasar\.git.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10125
1028*/Quasar.v*.zip*.{0,1000}\/Quasar\.v.{0,1000}\.zip.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10126
1029*/Quasar/releases*.{0,1000}\/Quasar\/releases.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10127
1030*/Quick Assist Installer.exe*.{0,1000}\/Quick\sAssist\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A10129
1031*/Quick%20Assist%20Installer.exe*.{0,1000}\/Quick\%20Assist\%20Installer\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A10130
1032*/Radmin.exe*.{0,1000}\/Radmin\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10142
1033*/Radmin_Server_*.msi*.{0,1000}\/Radmin_Server_.{0,1000}\.msi.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10143
1034*/Radmin_Viewer_*.msi*.{0,1000}\/Radmin_Viewer_.{0,1000}\.msi.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10144
1035*/Radmin_VPN_1.*.exe*.{0,1000}\/Radmin_VPN_1\..{0,1000}\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10145
1036*/rathole.exe.{0,1000}\/rathole\.exegreyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10168
1037*/rathole.git*.{0,1000}\/rathole\.git.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10169
1038*/rathole/src/*.{0,1000}\/rathole\/src\/.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10170
1039*/rathole-aarch64-*.{0,1000}\/rathole\-aarch64\-.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10171
1040*/rathole-arm*.{0,1000}\/rathole\-arm.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10172
1041*/rathole-main/*.{0,1000}\/rathole\-main\/.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10173
1042*/rathole-mipsel-*.{0,1000}\/rathole\-mipsel\-.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10174
1043*/rathole-x86_64*.{0,1000}\/rathole\-x86_64.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10175
1044*/raw/main/speedtest.exe*.{0,1000}\/raw\/main\/speedtest\.exe.{0,1000}greyware_tool_keywordspeedtestlegitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration effortsT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 Dispossessor - Dagon LockerData Exfiltrationhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A67N/AN/AN/AN/A10185
1045*/raw/master/speedtest.exe*.{0,1000}\/raw\/master\/speedtest\.exe.{0,1000}greyware_tool_keywordspeedtestlegitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration effortsT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 Dispossessor - Dagon LockerData Exfiltrationhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A67N/AN/AN/AN/A10188
1046*/rclone.conf*.{0,1000}\/rclone\.conf.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone10N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10198
1047*/rclone.exe*.{0,1000}\/rclone\.exe.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone10N/Ainteractive mode8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10199
1048*/rclone.git*.{0,1000}\/rclone\.git.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10200
1049*/rclone.rar*.{0,1000}\/rclone\.rar.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10201
1050*/rclone.zip*.{0,1000}\/rclone\.zip.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10202
1051*/rclone/releases/download/*.{0,1000}\/rclone\/releases\/download\/.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10203
1052*/rdpscan --*.{0,1000}\/rdpscan\s\-\-.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan10#linuxN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10222
1053*/rdpscan.git*.{0,1000}\/rdpscan\.git.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10223
1054*/rdpscan-macos.zip*.{0,1000}\/rdpscan\-macos\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10224
1055*/rdpscan-windows.zip*.{0,1000}\/rdpscan\-windows\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10225
1056*/RDPWInst.exe*.{0,1000}\/RDPWInst\.exe.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10235
1057*/RDPWInst-v*.msi*.{0,1000}\/RDPWInst\-v.{0,1000}\.msi.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10236
1058*/rdpwrap.dll*.{0,1000}\/rdpwrap\.dll.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10237
1059*/rdpwrap.git*.{0,1000}\/rdpwrap\.git.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10238
1060*/RDPWrap-v*.zip*.{0,1000}\/RDPWrap\-v.{0,1000}\.zip.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10239
1061*/RealTimeSync.exe*.{0,1000}\/RealTimeSync\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A10246
1062*/RedTeaming-Tactics-and-Techniques.git*.{0,1000}\/RedTeaming\-Tactics\-and\-Techniques\.git.{0,1000}greyware_tool_keywordired.teamRed Teaming Tactics and TechniquesT1593.003TA0043N/AN/AReconnaissancehttps://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques11N/AN/A710423410712024-08-22T07:17:31Z2019-03-02T13:33:33Z10302
1063*/release/gt-win-x86_64.exe*.{0,1000}\/release\/gt\-win\-x86_64\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z10336
1064*/release/sshx-server*.{0,1000}\/release\/sshx\-server.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z10337
1065*/releases/download/Ahk2Exe*.{0,1000}\/releases\/download\/Ahk2Exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z10339
1066*/RemCom.exe*.{0,1000}\/RemCom\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10352
1067*/RemCom.git*.{0,1000}\/RemCom\.git.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10353
1068*/RemComSvc.exe*.{0,1000}\/RemComSvc\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10354
1069*/Remote.It-Installer-*.{0,1000}\/Remote\.It\-Installer\-.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10356
1070*/RemoteControlSetup.exe*.{0,1000}\/RemoteControlSetup\.exe.{0,1000}greyware_tool_keywordComodoRMM (Itarian RMM)Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://one.comodo.com/11N/AN/A1010N/AN/AN/AN/A10369
1071*/RemoteDesktop.exe*.{0,1000}\/RemoteDesktop\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A10370
1072*/remoteit.exe*.{0,1000}\/remoteit\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10373
1073*/remoteit.x86-win.exe*.{0,1000}\/remoteit\.x86\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10374
1074*/remoteit/connectd/releases*.{0,1000}\/remoteit\/connectd\/releases.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z10375
1075*/remoteit/desktop*.{0,1000}\/remoteit\/desktop.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10376
1076*/remoteit-desktop.exe*.{0,1000}\/remoteit\-desktop\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10377
1077*/remotemoe.git*.{0,1000}\/remotemoe\.git.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z10382
1078*/remotepc.deb*.{0,1000}\/remotepc\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10384
1079*/remotepc.deb*.{0,1000}\/remotepc\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10385
1080*/RemotePC.exe*.{0,1000}\/RemotePC\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10386
1081*/RemotePC.exe*.{0,1000}\/RemotePC\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10387
1082*/RemotePC.lnk*.{0,1000}\/RemotePC\.lnk.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10388
1083*/RemotePC.tmp*.{0,1000}\/RemotePC\.tmp.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10389
1084*/remotepc-attended.deb*.{0,1000}\/remotepc\-attended\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10390
1085*/RemotePCAttended.dmg*.{0,1000}\/RemotePCAttended\.dmg.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11#macosN/A1010N/AN/AN/AN/A10391
1086*/remotepclauncher.exe*.{0,1000}\/remotepclauncher\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10392
1087*/RemotePCSuite.dmg*.{0,1000}\/RemotePCSuite\.dmg.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11#macosN/A1010N/AN/AN/AN/A10393
1088*/remotepcuiu.exe*.{0,1000}\/remotepcuiu\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10394
1089*/RemotePCViewer.msi*.{0,1000}\/RemotePCViewer\.msi.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10395
1090*/res/rdpwrap.ini*.{0,1000}\/res\/rdpwrap\.ini.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap10N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10405
1091*/rest_client_zrok/*.{0,1000}\/rest_client_zrok\/.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok10#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z10423
1092*/restic-*.tar.gz*.{0,1000}\/restic\-.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10424
1093*/restic.exe*.{0,1000}\/restic\.exe.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10425
1094*/restic/releases/download/*.{0,1000}\/restic\/releases\/download\/.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10426
1095*/restic_*_windows_amd64.zip*.{0,1000}\/restic_.{0,1000}_windows_amd64\.zip.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10427
1096*/restic-master/*.{0,1000}\/restic\-master\/.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10428
1097*/reverse-tunnel.git*.{0,1000}\/reverse\-tunnel\.git.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10451
1098*/reverse-tunnel/agent/cmd*.{0,1000}\/reverse\-tunnel\/agent\/cmd.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10452
1099*/reverse-tunnel/server/service*.{0,1000}\/reverse\-tunnel\/server\/service.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10453
1100*/RevoUninProSetup.exe*.{0,1000}\/RevoUninProSetup\.exe.{0,1000}greyware_tool_keywordRevoUninstallerlegitimate tool abused by the Dispossessor ransomware groupT1562.001 - T1112 - T1059 - T1036TA0005 - TA0040N/ADispossessorDefense Evasionhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A1010N/AN/AN/AN/A10457
1101*/rfusclient.exe*.{0,1000}\/rfusclient\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10472
1102*/rmm/api/tacticalrmm/*.{0,1000}\/rmm\/api\/tacticalrmm\/.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z10487
1103*/rmm-installer.ps1*.{0,1000}\/rmm\-installer\.ps1.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z10488
1104*/root/jprq-server*.{0,1000}\/root\/jprq\-server.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq10#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z10504
1105*/root/tunnel*.{0,1000}\/root\/tunnel.{0,1000}greyware_tool_keywordtunnel.pyjam.asSSL-terminated ephemeral HTTP tunnels to your local machine - no custom software required (thanks to wireguard)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://gitlab.com/pyjam.as/tunnel10#linuxN/A1010N/AN/AN/AN/A10510
1106*/RpcDND_Console.exe*.{0,1000}\/RpcDND_Console\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10540
1107*/rpcdownloader.exe*.{0,1000}\/rpcdownloader\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10541
1108*/RPCFireWallRule.exe*.{0,1000}\/RPCFireWallRule\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10545
1109*/rpcperfviewer.exe*.{0,1000}\/rpcperfviewer\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10549
1110*/RPCProxyLatency.exe*.{0,1000}\/RPCProxyLatency\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10550
1111*/rserver3.exe*.{0,1000}\/rserver3\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10554
1112*/rsocks.git*.{0,1000}\/rsocks\.git.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10556
1113*/rsocks.git*.{0,1000}\/rsocks\.git.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10#linuxN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z10557
1114*/rsocks.toml*.{0,1000}\/rsocks\.toml.{0,1000}greyware_tool_keywordrsocksA SOCKS 4/5 reverse proxy serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/tonyseek/rsocks10#linuxN/A1010131132022-09-20T07:11:29Z2015-03-08T22:31:31Z10558
1115*/rsocks/releases/download/*.{0,1000}\/rsocks\/releases\/download\/.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10559
1116*/rsocks_linux_amd64*.{0,1000}\/rsocks_linux_amd64.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11#linuxN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10560
1117*/rsocks_windows_386.exe*.{0,1000}\/rsocks_windows_386\.exe.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10561
1118*/rtun-freebsd-amd64*.{0,1000}\/rtun\-freebsd\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10580
1119*/rtun-linux-amd64*.{0,1000}\/rtun\-linux\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10581
1120*/rtun-linux-arm64*.{0,1000}\/rtun\-linux\-arm64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10582
1121*/rtun-mac-amd64*.{0,1000}\/rtun\-mac\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10583
1122*/rtun-server-freebsd-amd64*.{0,1000}\/rtun\-server\-freebsd\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10584
1123*/rtun-server-linux-amd64*.{0,1000}\/rtun\-server\-linux\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10585
1124*/rtun-server-linux-arm64*.{0,1000}\/rtun\-server\-linux\-arm64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10586
1125*/rtun-server-mac-amd64*.{0,1000}\/rtun\-server\-mac\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10587
1126*/rtun-server-windows-amd64.exe*.{0,1000}\/rtun\-server\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10588
1127*/rtun-windows-amd64.exe*.{0,1000}\/rtun\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10589
1128*/RustDesk.exe*.{0,1000}\/RustDesk\.exe.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10639
1129*/rustdesk.git*.{0,1000}\/rustdesk\.git.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10640
1130*/rustdesk/rustdesk/releases/*.{0,1000}\/rustdesk\/rustdesk\/releases\/.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10641
1131*/rutserv.exe*.{0,1000}\/rutserv\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10649
1132*/rutview.exe*.{0,1000}\/rutview\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10650
1133*/rvim -c ':py3 import os*os.execl(\"/bin/sh\*.{0,1000}\/rvim\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10651
1134*/s4n7h0/NSE*.{0,1000}\/s4n7h0\/NSE.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install10#linuxN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z10658
1135*/sbin/dropbear*.{0,1000}\/sbin\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z10696
1136*/sdelete.exe*.{0,1000}\/sdelete\.exe.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10747
1137*/SDelete.zip*.{0,1000}\/SDelete\.zip.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10748
1138*/sdelete64.exe*.{0,1000}\/sdelete64\.exe.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10749
1139*/sdelete64a.exe*.{0,1000}\/sdelete64a\.exe.{0,1000}greyware_tool_keywordsdeletedelete one or more files and/or directories, or to cleanse the free space on a logical disk - abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10750
1140*/send.exploit.in/*.{0,1000}\/send\.exploit\.in\/.{0,1000}greyware_tool_keywordsend.exploit.infile-sharing platform used by ransomware groupsT1567TA0010N/ABlack BastaData Exfiltrationhttps://www.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf11#filehostingserviceN/A1010N/AN/AN/AN/A10784
1141*/SetACL.exe*.{0,1000}\/SetACL\.exe.{0,1000}greyware_tool_keywordSetACLManage Windows permissions from the command lineT1069 - T1222TA0002 - TA0004 - TA0005N/AN/ADefense Evasionhttps://helgeklein.com/download/11N/AN/A610N/AN/AN/AN/A10810
1142*/SetACL64..exe*.{0,1000}\/SetACL64\.\.exe.{0,1000}greyware_tool_keywordSetACLManage Windows permissions from the command lineT1069 - T1222TA0002 - TA0004 - TA0005N/AN/ADefense Evasionhttps://helgeklein.com/download/11N/AN/A610N/AN/AN/AN/A10811
1143*/set-proxy.ps1*.{0,1000}\/set\-proxy\.ps1.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z10814
1144*/sftp *@*:* .{0,1000}/sftp\s.{0,1000}\@.{0,1000}\:.{0,1000}greyware_tool_keywordsftpDetects the use of tools that copy files from or to remote systemsT1041 - T1105 - T1106TA0002 - TA0008 - TA0010N/ABlack BastaData Exfiltrationhttps://attack.mitre.org/techniques/T1105/10#linuxgreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A10819
1145*/sftp *get*.wallet*.{0,1000}sftp.*get.*(\.pem|\.key|\.wallet)\b.{0,1000}greyware_tool_keywordsftpsftp transfers of sensitive filesT1041 - T1105 - T1106TA0002 - TA0008 - TA0010N/AN/AData Exfiltrationhttps://attack.mitre.org/techniques/T1105/10#linuxgreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A10820
1146*/sftp *put*.tar.gz*.{0,1000}sftp\s.*put.*(\.tar\.gz|\.zip|\.rar|\.7z)\b.{0,1000}greyware_tool_keywordsftpsftp archive transfersT1041 - T1105 - T1106TA0002 - TA0008 - TA0010N/AN/AData Exfiltrationhttps://attack.mitre.org/techniques/T1105/10#linuxgreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A10821
1147*/Shadowsocks-*.zip*.{0,1000}\/Shadowsocks\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10839
1148*/Shadowsocks.zip*.{0,1000}\/Shadowsocks\.zip.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10840
1149*/shadowsocks_service.*.{0,1000}\/shadowsocks_service\..{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10#linuxN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10841
1150*/shadowsocks-manager.sock*.{0,1000}\/shadowsocks\-manager\.sock.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust10#linuxN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10842
1151*/shadowsocks-rust.default*.{0,1000}\/shadowsocks\-rust\.default.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10843
1152*/shadowsocks-rust.git*.{0,1000}\/shadowsocks\-rust\.git.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10844
1153*/shadowsocks-rust.init*.{0,1000}\/shadowsocks\-rust\.init.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10845
1154*/shadowsocks-rust.service*.{0,1000}\/shadowsocks\-rust\.service.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10846
1155*/shadowsocks-service*.{0,1000}\/shadowsocks\-service.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10847
1156*/shadowsocks-windows.git*.{0,1000}\/shadowsocks\-windows\.git.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10848
1157*/simplehelper64.exe*.{0,1000}\/simplehelper64\.exe.{0,1000}greyware_tool_keywordSimpleHelpSimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackCatRMMsimple-help.com11N/AN/A1010N/AN/AN/AN/A11275
1158*/SirTunnel.git*.{0,1000}\/SirTunnel\.git.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z11296
1159*/sirtunnel.py*.{0,1000}\/sirtunnel\.py.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z11297
1160*/sish.git*.{0,1000}\/sish\.git.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish11N/AN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z11299
1161*/sish.log*.{0,1000}\/sish\.log.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish10#linuxN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z11300
1162*/sish/cmd/*.{0,1000}\/sish\/cmd\/.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish10#linuxN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z11301
1163*/SoftEtherVPN-*.tar.xz*.{0,1000}\/SoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11494
1164*/SoftEtherVPN.git*.{0,1000}\/SoftEtherVPN\.git.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNabused https://asec.ahnlab.com/en/66843/8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11495
1165*/SoftEtherVPN/releases/tag/*.{0,1000}\/SoftEtherVPN\/releases\/tag\/.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11496
1166*/softether-vpnclient-*.exe*.{0,1000}\/softether\-vpnclient\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11497
1167*/softether-vpnserver-*.deb*.{0,1000}\/softether\-vpnserver\-.{0,1000}\.deb.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11498
1168*/softether-vpnserver.service*.{0,1000}\/softether\-vpnserver\.service.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN10#VPN #linuxN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11499
1169*/softether-vpnserver_*.exe*.{0,1000}\/softether\-vpnserver_.{0,1000}\.exe.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11500
1170*/SolarWinds-Dameware-DRS-St.exe*.{0,1000}\/SolarWinds\-Dameware\-DRS\-St\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/ADameware Remote Support1010N/AN/AN/AN/A11502
1171*/sources.list.d/tailscale.list*.{0,1000}\/sources\.list\.d\/tailscale\.list.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11506
1172*/spacerunner.exe*.{0,1000}\/spacerunner\.exe.{0,1000}greyware_tool_keywordSpaceRunnerenables the compilation of a C# program that will execute arbitrary PowerShell code without launching PowerShell processes through the use of runspace.T1059.001 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/Mr-B0b/SpaceRunner10N/AN/A72195382020-07-26T10:39:53Z2020-07-26T09:31:09Z11507
1173*/SplashtopStreamer/SPLog.txt*.{0,1000}\/SplashtopStreamer\/SPLog\.txt.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://ruler-project.github.io/ruler-project/RULER/remote/Splashtop/10#linuxN/A1010N/AN/AN/AN/A11528
1174*/src/expose serve *.{0,1000}\/src\/expose\sserve\s.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose10#linuxN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z11586
1175*/sshpass /bin/sh -p*.{0,1000}\/sshpass\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z11611
1176*/sshtunnel -*.{0,1000}\/sshtunnel\s\-.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel10#linuxN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11616
1177*/sshtunnel.git*.{0,1000}\/sshtunnel\.git.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11617
1178*/sshtunnel.py*.{0,1000}\/sshtunnel\.py.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11618
1179*/sshtunnel/tarball/*.{0,1000}\/sshtunnel\/tarball\/.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11619
1180*/sshtunnel/zipball/*.{0,1000}\/sshtunnel\/zipball\/.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11620
1181*/sshuttle.git*.{0,1000}\/sshuttle\.git.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11621
1182*/sshuttle.py*.{0,1000}\/sshuttle\.py.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11622
1183*/sshuttle/tarball*.{0,1000}\/sshuttle\/tarball.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11623
1184*/sshuttle/zipball*.{0,1000}\/sshuttle\/zipball.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11624
1185*/sshx-server/*.{0,1000}\/sshx\-server\/.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z11626
1186*/stdbuf -i0 /bin/sh -p*.{0,1000}\/stdbuf\s\-i0\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z11666
1187*/stunnel-*.tar.gz*.{0,1000}\/stunnel\-.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html10#linuxN/A78N/AN/AN/AN/A11691
1188*/stunnel-latest.tar.gz*.{0,1000}\/stunnel\-latest\.tar\.gz.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11692
1189*/stunnel-latest-android.zip*.{0,1000}\/stunnel\-latest\-android\.zip.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11693
1190*/stunnel-latest-win64-installer.exe*.{0,1000}\/stunnel\-latest\-win64\-installer\.exe.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11694
1191*/suo5.git*.{0,1000}\/suo5\.git.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11718
1192*/suo5/releases/*.{0,1000}\/suo5\/releases\/.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11719
1193*/suo5-darwin-amd64*.{0,1000}\/suo5\-darwin\-amd64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11720
1194*/suo5-darwin-arm64*.{0,1000}\/suo5\-darwin\-arm64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11721
The file is too large to be shown. View Raw