mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
785 KiB
785 KiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | *&browser=tor&api=false* | .{0,1000}\&browser\=tor\&api\=false.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 4049 |
| 3 | *./nmap* | .{0,1000}\.\/nmap.{0,1000} | greyware_tool_keyword | nmap | A very common tool. Network host vuln and port detector. | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap | 1 | 1 | #linux | greyware tool - risks of False positive ! | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 4173 |
| 4 | *._tcp.argotunnel.com* | .{0,1000}\._tcp\.argotunnel\.com.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 4234 |
| 5 | *.a.pinggy.online* | .{0,1000}\.a\.pinggy\.online.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4237 |
| 6 | *.api.mega.co.nz* | .{0,1000}\.api\.mega\.co\.nz.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4242 |
| 7 | *.api.splashtop.com* | .{0,1000}\.api\.splashtop\.com.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c72 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4243 |
| 8 | *.apitest.barracudamsp.com* | .{0,1000}\.apitest\.barracudamsp\.com.{0,1000} | greyware_tool_keyword | BarracudaRMM | Deliver remote support services - formely AVG | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.barracudamsp.com/products/rmm/barracuda-rmm | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4244 |
| 9 | *.asse.devtunnels.ms* | .{0,1000}\.asse\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4249 |
| 10 | *.aweray.net* | .{0,1000}\.aweray\.net.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4252 |
| 11 | *.beyondtrustcloud.com/session_complete* | .{0,1000}\.beyondtrustcloud\.com\/session_complete.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4258 |
| 12 | *.comodo.com/static/frontend/static-pages/enroll-wizard/token* | .{0,1000}\.comodo\.com\/static\/frontend\/static\-pages\/enroll\-wizard\/token.{0,1000} | greyware_tool_keyword | ComodoRMM (Itarian RMM) | Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://one.comodo.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4275 |
| 13 | *.console.gotoassist.com* | .{0,1000}\.console\.gotoassist\.com.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4279 |
| 14 | *.d.requestbin.net* | .{0,1000}\.d\.requestbin\.net.{0,1000} | greyware_tool_keyword | requestbin.net | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://requestbin.net | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 4282 |
| 15 | *.dev1.fleetdeck.io* | .{0,1000}\.dev1\.fleetdeck\.io.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 4285 |
| 16 | *.dnslog.cn:* | .{0,1000}\.dnslog\.cn\:.{0,1000} | greyware_tool_keyword | dnslog.cn | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://dnslog.cn | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 4289 |
| 17 | *.exec*.interact.sh* | .{0,1000}\.exec.{0,1000}\.interact\.sh.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 4660 |
| 18 | *.free.pinggy.online* | .{0,1000}\.free\.pinggy\.online.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4665 |
| 19 | *.gofile.io/uploadFile* | .{0,1000}\.gofile\.io\/uploadFile.{0,1000} | greyware_tool_keyword | gofile.io | legitimate service abused by lots of stealer to exfiltrate data | T1567.002 | TA0010 | N/A | Hive - Royal - LockBit - Vice Society - BlackSuit - Conti | Data Exfiltration | https://gofile.io | 1 | 1 | #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4670 |
| 20 | *.in.zrok.io* | .{0,1000}\.in\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4677 |
| 21 | *.l.tunwg.com* | .{0,1000}\.l\.tunwg\.com.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 4686 |
| 22 | *.localltunnel.me* | .{0,1000}\.localltunnel\.me.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 4696 |
| 23 | *.loclx.io:* | .{0,1000}\.loclx\.io\:.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 4697 |
| 24 | *.mspa.n-able.com* | .{0,1000}\.mspa\.n\-able\.com.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4703 |
| 25 | *.myftp.biz* | .{0,1000}\.myftp\.biz.{0,1000} | greyware_tool_keyword | myftp.biz | dyndns - lots of subdomains associated with malwares - could be used in various ways for both legitimate and malicious activities (malicious mostly) | T1071 - T1021 - T1095 - T1059 | TA0010 - TA0008 - TA0009 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/hagezi/dns-blocklists/blob/9d6562bddc175b59241d5935531f648cd6b6d9c8/rpz/dyndns.txt#L103 | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | 10725 | 340 | 2025-04-22T19:18:32Z | 2022-04-25T07:13:09Z | 4704 |
| 26 | *.myftp.org* | .{0,1000}\.myftp\.org.{0,1000} | greyware_tool_keyword | myftp.org | dyndns - lots of subdomains associated with malwares - myftp.org could be used in various ways for both legitimate and malicious activities (malicious mostly) | T1071 - T1021 - T1095 - T1059 | TA0010 - TA0008 - TA0009 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/pan-unit42/iocs/blob/master/rat_nest/iocs.csv | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 8 | 711 | 152 | 2025-04-05T02:03:37Z | 2015-06-04T13:37:09Z | 4705 |
| 27 | *.ngrok.me* | .{0,1000}\.ngrok\.me.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 4709 |
| 28 | *.realtime.services.box.net* | .{0,1000}\.realtime\.services\.box\.net.{0,1000} | greyware_tool_keyword | Box | Attackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackers | T1567.002 - T1071.001 - T1036 - T1048.002 | TA0005 - TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://app.box.com/ | 1 | 1 | #dnsquery | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 4861 |
| 29 | *.rel.tunnels.api.visualstudio.com* | .{0,1000}\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4862 |
| 30 | *.relay.splashtop.com* | .{0,1000}\.relay\.splashtop\.com.{0,1000} | greyware_tool_keyword | Splashtop | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - Cactus | RMM | https://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c72 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4863 |
| 31 | *.remotepc.com* | .{0,1000}\.remotepc\.com.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4864 |
| 32 | *.remotepc.com* | .{0,1000}\.remotepc\.com.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | network | 10 | 10 | N/A | N/A | N/A | N/A | 4865 |
| 33 | *.remoteutilities.com* | .{0,1000}\.remoteutilities\.com.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4866 |
| 34 | *.remoteview.logmein.com* | .{0,1000}\.remoteview\.logmein\.com.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4867 |
| 35 | *.router.teamviewer.com* | .{0,1000}\.router\.teamviewer\.com.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 1 | N/A | FP risk - teamviewer usage | 10 | 10 | N/A | N/A | N/A | N/A | 4871 |
| 36 | *.servicedesk.atera.com/GetAgent* | .{0,1000}\.servicedesk\.atera\.com\/GetAgent.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4885 |
| 37 | *.share.zrok.io* | .{0,1000}\.share\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4904 |
| 38 | *.srv.browser.lol* | .{0,1000}\.srv\.browser\.lol.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 4910 |
| 39 | *.static.mega.co.nz* | .{0,1000}\.static\.mega\.co\.nz.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4915 |
| 40 | *.trycloudfare.com*DavWWWRoot* | .{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4923 |
| 41 | *.tunnel.pyjam.as* | .{0,1000}\.tunnel\.pyjam\.as.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4924 |
| 42 | *.tunnelto.dev* | .{0,1000}\.tunnelto\.dev.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 4929 |
| 43 | *.userstorage.mega.co.nz/ul/* | .{0,1000}\.userstorage\.mega\.co\.nz\/ul\/.{0,1000} | greyware_tool_keyword | mega.co.nz | uploading data to mega cloud | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR - Dispossessor | Data Exfiltration | https://mega.io/ | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4944 |
| 44 | *.v2.argotunnel.com* | .{0,1000}\.v2\.argotunnel\.com.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 4945 |
| 45 | *.xeox.com* | .{0,1000}\.xeox\.com.{0,1000} | greyware_tool_keyword | xeox | Easily access and manage Windows devices remotely within XEOX - RMM abused by threat actors | T1021 - T1078 - T1219 - T1105 - T1046 | TA0011 - TA0010 - TA0003 - TA0005 | N/A | Dispossessor | RMM | https://xeox.com/remote-access/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4956 |
| 46 | *.zohoassist.com.cn* | .{0,1000}\.zohoassist\.com\.cn.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4979 |
| 47 | *.zohoassist.jp* | .{0,1000}\.zohoassist\.jp.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4980 |
| 48 | *.zrok.quigley.com* | .{0,1000}\.zrok\.quigley\.com.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 4981 |
| 49 | */*.loclx.io* | .{0,1000}\/.{0,1000}\.loclx\.io.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 4983 |
| 50 | */3proxy-*.deb* | .{0,1000}\/3proxy\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5088 |
| 51 | */3proxy-*.rpm* | .{0,1000}\/3proxy\-.{0,1000}\.rpm.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5089 |
| 52 | */3proxy-*.zip* | .{0,1000}\/3proxy\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5090 |
| 53 | */3proxy.exe* | .{0,1000}\/3proxy\.exe.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5091 |
| 54 | */3proxy.git* | .{0,1000}\/3proxy\.git.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5092 |
| 55 | */3proxy.log* | .{0,1000}\/3proxy\.log.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | #logfile #linux | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 5093 |
| 56 | */a.pinggy.io* | .{0,1000}\/a\.pinggy\.io.{0,1000} | greyware_tool_keyword | pinggy | Create HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs. | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://pinggy.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5100 |
| 57 | */AADInternals.git* | .{0,1000}\/AADInternals\.git.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 5102 |
| 58 | */action1_agent(My_Organization).msi* | .{0,1000}\/action1_agent\(My_Organization\)\.msi.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | product name | 10 | 10 | N/A | N/A | N/A | N/A | 5123 |
| 59 | */AD_Miner.git* | .{0,1000}\/AD_Miner\.git.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5127 |
| 60 | */AD_Miner/releases/* | .{0,1000}\/AD_Miner\/releases\/.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5128 |
| 61 | */adaudit.git* | .{0,1000}\/adaudit\.git.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5138 |
| 62 | */adaudit.ps1* | .{0,1000}\/adaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5140 |
| 63 | */AD-common-queries.git* | .{0,1000}\/AD\-common\-queries\.git.{0,1000} | greyware_tool_keyword | AD-common-queries | Collection of common ADSI queries for Domain Account enumeration | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 1 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 5147 |
| 64 | */AdFind.zip* | .{0,1000}\/AdFind\.zip.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5186 |
| 65 | */ADGet.exe* | .{0,1000}\\ADGet\.exe.{0,1000} | greyware_tool_keyword | adget | gather valuable informations about the AD environment | T1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482 | TA0001 - TA0002 - TA0003 - TA0007 - TA0011 | N/A | N/A | Discovery | https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5198 |
| 66 | */ADRecon* | .{0,1000}\/ADRecon.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commands | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/sense-of-security/ADRecon | 1 | 1 | N/A | N/A | 10 | 10 | 1786 | 292 | 2020-06-15T05:23:14Z | 2017-11-29T23:01:53Z | 5212 |
| 67 | */ADRecon.ps1* | .{0,1000}\/ADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 5214 |
| 68 | */Advanced_Port_Scanner_*.exe* | .{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 5218 |
| 69 | */Ahk2Exe.exe* | .{0,1000}\/Ahk2Exe\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5255 |
| 70 | */Ahk2Exe.git* | .{0,1000}\/Ahk2Exe\.git.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5256 |
| 71 | */Ahk2Exe.zip* | .{0,1000}\/Ahk2Exe\.zip.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5257 |
| 72 | */Ahk2Exe1.*.zip* | .{0,1000}\/Ahk2Exe1\..{0,1000}\.zip.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5258 |
| 73 | */ahk-install.exe* | .{0,1000}\/ahk\-install\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5259 |
| 74 | */ahk-v2.exe* | .{0,1000}\/ahk\-v2\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5260 |
| 75 | */Alpemix.zip* | .{0,1000}\/Alpemix\.zip.{0,1000} | greyware_tool_keyword | Alpemix | connect to your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.alpemix.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5281 |
| 76 | */amalshaji/portr-admin/* | .{0,1000}\/amalshaji\/portr\-admin\/.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 5282 |
| 77 | */amidaware/rmmagent/releases/download/* | .{0,1000}\/amidaware\/rmmagent\/releases\/download\/.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 5288 |
| 78 | */Amperage.exe* | .{0,1000}\/Amperage\.exe.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5291 |
| 79 | */AmperageKit.git* | .{0,1000}\/AmperageKit\.git.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5292 |
| 80 | */AmperageKit/releases/* | .{0,1000}\/AmperageKit\/releases\/.{0,1000} | greyware_tool_keyword | AmperageKit | enabling Recall in Windows 11 version 24H2 on unsupported devices | T1005 - T1113 - T1056.001 - T1003 | TA0009 - TA0010 - TA0006 - TA0007 | N/A | N/A | Sniffing & Spoofing | https://github.com/thebookisclosed/AmperageKit | 1 | 1 | N/A | N/A | 8 | 5 | 406 | 26 | 2024-06-21T16:37:12Z | 2024-05-30T23:00:45Z | 5293 |
| 81 | */Anydesk.exe | .{0,1000}\/Anydesk\.exe | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://anydesk.com/ | 1 | 1 | N/A | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 5333 |
| 82 | */anyplace-control/data2/*.exe* | .{0,1000}\/anyplace\-control\/data2\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | AnyplaceControl | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyplace-control[.]com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5334 |
| 83 | */AnyViewerSetup.exe* | .{0,1000}\/AnyViewerSetup\.exe.{0,1000} | greyware_tool_keyword | anyviewer | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyviewer.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5336 |
| 84 | */Apemix.exe* | .{0,1000}\/Apemix\.exe.{0,1000} | greyware_tool_keyword | Alpemix | connect to your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.alpemix.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5342 |
| 85 | */api/latest/fleet/mdm/bootstrap?token=* | .{0,1000}\/api\/latest\/fleet\/mdm\/bootstrap\?token\=.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 5350 |
| 86 | */api/v1/fleet/mdm/sso/callback* | .{0,1000}\/api\/v1\/fleet\/mdm\/sso\/callback.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 5365 |
| 87 | */Assistance rapide Installer.exe* | .{0,1000}\/Assistance\srapide\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 5428 |
| 88 | */Assistenza rapida Installer.exe* | .{0,1000}\/Assistenza\srapida\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 5429 |
| 89 | */atnow.exe* | .{0,1000}\/atnow\.exe.{0,1000} | greyware_tool_keyword | atnow | AtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TA | T1053 - T1059 | TA0002 | N/A | APT18 - APT29 - APT32 - Cobalt - RTM | Persistence | https://www.nirsoft.net/utils/atnow.html | 1 | 1 | N/A | N/A | 7 | 7 | N/A | N/A | N/A | N/A | 5454 |
| 90 | */atnow.zip* | .{0,1000}\/atnow\.zip.{0,1000} | greyware_tool_keyword | atnow | AtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TA | T1053 - T1059 | TA0002 | N/A | APT18 - APT29 - APT32 - Cobalt - RTM | Persistence | https://www.nirsoft.net/utils/atnow.html | 1 | 1 | N/A | N/A | 7 | 7 | N/A | N/A | N/A | N/A | 5455 |
| 91 | */AttendedUDP.zip* | .{0,1000}\/AttendedUDP\.zip.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5466 |
| 92 | */AutoHotkey.exe* | .{0,1000}\/AutoHotkey\.exe.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5478 |
| 93 | */AutoHotkey.git* | .{0,1000}\/AutoHotkey\.git.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5479 |
| 94 | */AutoHotkey/releases/download/* | .{0,1000}\/AutoHotkey\/releases\/download\/.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5480 |
| 95 | */AutoHotkey_*.zip* | .{0,1000}\/AutoHotkey_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5481 |
| 96 | */AutoHotkey_1*_setup.exe* | .{0,1000}\/AutoHotkey_1.{0,1000}_setup\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5482 |
| 97 | */AutoHotkey_2*_setup.exe* | .{0,1000}\/AutoHotkey_2.{0,1000}_setup\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5483 |
| 98 | */AutoHotkey64.exe* | .{0,1000}\/AutoHotkey64\.exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 5484 |
| 99 | */AutoHotkey64.exe* | .{0,1000}\/AutoHotkey64\.exe.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 5485 |
| 100 | */Aweray_Remote_*.exe* | .{0,1000}\/Aweray_Remote_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5505 |
| 101 | */Aweray_Remote_*.zip* | .{0,1000}\/Aweray_Remote_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5506 |
| 102 | */bin/x64/connectd.exe* | .{0,1000}\/bin\/x64\/connectd\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | #linux | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 5666 |
| 103 | */BitLockerToGo.exe* | .{0,1000}\/BitLockerToGo\.exe.{0,1000} | greyware_tool_keyword | BitLockerToGo | BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data | T1218 - T1055 - T1112 - T1056 - T1555 | TA0005 - TA0007 - TA0009 | Lumma Stealer | N/A | Defense Evasion | https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/ | 0 | 1 | N/A | high FP - hunting only | 3 | 8 | N/A | N/A | N/A | N/A | 5676 |
| 104 | */bomgar-rep.exe* | .{0,1000}\/bomgar\-rep\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5761 |
| 105 | */bomgar-scc-*.exe* | .{0,1000}\/bomgar\-scc\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5763 |
| 106 | */bomgar-scc.exe* | .{0,1000}\/bomgar\-scc\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5764 |
| 107 | */boringproxy.git* | .{0,1000}\/boringproxy\.git.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5767 |
| 108 | */boringproxy-client.service* | .{0,1000}\/boringproxy\-client\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5768 |
| 109 | */boringproxy-server.service* | .{0,1000}\/boringproxy\-server\.service.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 5769 |
| 110 | */BoxDrive.msi* | .{0,1000}\/BoxDrive\.msi.{0,1000} | greyware_tool_keyword | Box | Attackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackers | T1567.002 - T1071.001 - T1036 - T1048.002 | TA0005 - TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://app.box.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 5770 |
| 111 | */btunnel.exe* | .{0,1000}\/btunnel\.exe.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 5847 |
| 112 | */cloudflared.git* | .{0,1000}\/cloudflared\.git.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6091 |
| 113 | */cloudflared-linux-*.deb* | .{0,1000}\/cloudflared\-linux\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | #linux | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6093 |
| 114 | */cloudflared-linux-*.rpm* | .{0,1000}\/cloudflared\-linux\-.{0,1000}\.rpm.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | #linux | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 6094 |
| 115 | */cmd/tailscaled* | .{0,1000}\/cmd\/tailscaled.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 6105 |
| 116 | */config/apps/http/servers/sirtunnel/routes* | .{0,1000}\/config\/apps\/http\/servers\/sirtunnel\/routes.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 6181 |
| 117 | */connectd.aarch64-win.exe* | .{0,1000}\/connectd\.aarch64\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 6189 |
| 118 | */connectd.x86_64-win.exe* | .{0,1000}\/connectd\.x86_64\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 6190 |
| 119 | */croc.exe* | .{0,1000}\/croc\.exe.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6271 |
| 120 | */croc/releases/download/v10* | .{0,1000}\/croc\/releases\/download\/v10.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6273 |
| 121 | */croc/releases/latest* | .{0,1000}\/croc\/releases\/latest.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 6274 |
| 122 | */crowbar.git* | .{0,1000}\/crowbar\.git.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6285 |
| 123 | */crowbar_1.0.0_darwin_386.zip* | .{0,1000}\/crowbar_1\.0\.0_darwin_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6286 |
| 124 | */crowbar_1.0.0_darwin_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_darwin_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6287 |
| 125 | */crowbar_1.0.0_freebsd_386.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6288 |
| 126 | */crowbar_1.0.0_freebsd_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6289 |
| 127 | */crowbar_1.0.0_freebsd_arm.zip* | .{0,1000}\/crowbar_1\.0\.0_freebsd_arm\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6290 |
| 128 | */crowbar_1.0.0_linux_386.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_386\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6291 |
| 129 | */crowbar_1.0.0_linux_amd64.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6292 |
| 130 | */crowbar_1.0.0_linux_arm.tar.gz* | .{0,1000}\/crowbar_1\.0\.0_linux_arm\.tar\.gz.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | #linux | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6293 |
| 131 | */crowbar_1.0.0_openbsd_386.zip* | .{0,1000}\/crowbar_1\.0\.0_openbsd_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6294 |
| 132 | */crowbar_1.0.0_openbsd_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_openbsd_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6295 |
| 133 | */crowbar_1.0.0_windows_386.zip* | .{0,1000}\/crowbar_1\.0\.0_windows_386\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6296 |
| 134 | */crowbar_1.0.0_windows_amd64.zip* | .{0,1000}\/crowbar_1\.0\.0_windows_amd64\.zip.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 6297 |
| 135 | */damewareagent.exe* | .{0,1000}\/damewareagent\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6397 |
| 136 | */dataplicity-agent.git* | .{0,1000}\/dataplicity\-agent\.git.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6439 |
| 137 | */dataplicity-agent/releases/download* | .{0,1000}\/dataplicity\-agent\/releases\/download.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 6440 |
| 138 | */download*mediafire.com/ | .{0,1000}\/download.{0,1000}mediafire\.com\/ | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1083 - T1560 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 6750 |
| 139 | */download/fiddler/fiddler-everywhere-windows* | .{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 6751 |
| 140 | */download/pcunlocker* | .{0,1000}\/download\/pcunlocker.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6754 |
| 141 | */downloads/ultravnc.html* | .{0,1000}\/downloads\/ultravnc\.html.{0,1000} | greyware_tool_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6771 |
| 142 | */dropbear.git* | .{0,1000}\/dropbear\.git.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 1 | N/A | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6792 |
| 143 | */dropbear/releases/* | .{0,1000}\/dropbear\/releases\/.{0,1000} | greyware_tool_keyword | dropbear | A smallish SSH server and client | T1021.004 - T1570 | TA0003 | N/A | COZY BEAR | Persistence | https://github.com/mkj/dropbear | 1 | 1 | N/A | N/A | 8 | 10 | 1851 | 411 | 2025-03-16T12:50:35Z | 2013-03-19T11:15:36Z | 6795 |
| 144 | */dropbear-sshj.git* | .{0,1000}\/dropbear\-sshj\.git.{0,1000} | greyware_tool_keyword | SSH-J.com | This is Dropbear SSH server modified to be used as a public SSH jump & port forwarding service | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://bitbucket.org/ValdikSS/dropbear-sshj/src/master/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6798 |
| 145 | */DuckDNS.7z* | .{0,1000}\/DuckDNS\.7z.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6809 |
| 146 | */DuckDNS.git* | .{0,1000}\/DuckDNS\.git.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6810 |
| 147 | */DuckDNS.zip"* | .{0,1000}\/DuckDNS\.zip\".{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6811 |
| 148 | */duckdns/duck.log* | .{0,1000}\/duckdns\/duck\.log.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | #logfile #linux | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6812 |
| 149 | */duckdns/duck.sh* | .{0,1000}\/duckdns\/duck\.sh.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6813 |
| 150 | */duckdns-powershell.git* | .{0,1000}\/duckdns\-powershell\.git.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 6814 |
| 151 | */DWMRC_St_64.msi* | .{0,1000}\/DWMRC_St_64\.msi.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6860 |
| 152 | */DWRCC.exe* | .{0,1000}\/DWRCC\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6861 |
| 153 | */DWRCCMD.exe* | .{0,1000}\/DWRCCMD\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6862 |
| 154 | */DWRCS.exe* | .{0,1000}\/DWRCS\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 6863 |
| 155 | */ehorus_agent_installer-* | .{0,1000}\/ehorus_agent_installer\-.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6906 |
| 156 | */Eraser 6.0.10.2620.exe* | .{0,1000}\/Eraser\s6\.0\.10\.2620\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6980 |
| 157 | */Eraser 6.0.8.2273.exe* | .{0,1000}\/Eraser\s6\.0\.8\.2273\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6981 |
| 158 | */Eraser 6.0.9.2343.exe* | .{0,1000}\/Eraser\s6\.0\.9\.2343\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6982 |
| 159 | */Eraser 6.2.0.2994.exe* | .{0,1000}\/Eraser\s6\.2\.0\.2994\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6983 |
| 160 | */EraserSetup.exe* | .{0,1000}\/EraserSetup\.exe.{0,1000} | greyware_tool_keyword | eraser | It completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensic | T1070 - T1488 - T1561 | TA0005 | N/A | BlackSuit - Royal | Defense Evasion | https://sourceforge.net/projects/eraser | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 6984 |
| 161 | */expose/database/expose.db* | .{0,1000}\/expose\/database\/expose\.db.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 7151 |
| 162 | */expose/raw/master/builds/expose* | .{0,1000}\/expose\/raw\/master\/builds\/expose.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 7152 |
| 163 | */Fiddler Everywhere *.*.*.exe* | .{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 7190 |
| 164 | */FileZilla_*_sponsored-setup.exe* | .{0,1000}\/FileZilla_.{0,1000}_sponsored\-setup\.exe.{0,1000} | greyware_tool_keyword | FileZilla | FileZilla admintool used by threat actors for persistence and data exfiltration | T1505 - T1041 | TA0003 - TA0009 -TA0010 | N/A | Dispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155 | Data Exfiltration | https://filezilla-project.org/ | 1 | 1 | N/A | PUA risk of legitimate usage | 5 | 7 | N/A | N/A | N/A | N/A | 7199 |
| 165 | */FileZilla_Server_*.deb* | .{0,1000}\/FileZilla_Server_.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | FileZilla | FileZilla admintool used by threat actors for persistence and data exfiltration | T1505 - T1041 | TA0003 - TA0009 -TA0010 | N/A | Dispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155 | Data Exfiltration | https://filezilla-project.org/ | 1 | 1 | N/A | PUA risk of legitimate usage | 5 | 7 | N/A | N/A | N/A | N/A | 7200 |
| 166 | */fleet_v*_linux.tar.gz* | .{0,1000}\/fleet_v.{0,1000}_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | #linux | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7216 |
| 167 | */fleetd.crx* | .{0,1000}\/fleetd\.crx.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7217 |
| 168 | */fleetdm/fleet/releases/download/* | .{0,1000}\/fleetdm\/fleet\/releases\/download\/.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7218 |
| 169 | */fleetdm/fleet/releases/latest* | .{0,1000}\/fleetdm\/fleet\/releases\/latest.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 7219 |
| 170 | */FreeFileSync.exe* | .{0,1000}\/FreeFileSync\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7247 |
| 171 | */FreeFileSync.tar.gz* | .{0,1000}\/FreeFileSync\.tar\.gz.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7248 |
| 172 | */FreeFileSync_*.tar.gz* | .{0,1000}\/FreeFileSync_.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7249 |
| 173 | */FreeFileSync_*_Windows_Setup.exe* | .{0,1000}\/FreeFileSync_.{0,1000}_Windows_Setup\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7250 |
| 174 | */FreeFileSync_x64.exe* | .{0,1000}\/FreeFileSync_x64\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7251 |
| 175 | */FreeFileSyncPortable_*.exe* | .{0,1000}\/FreeFileSyncPortable_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7252 |
| 176 | */frp.git* | .{0,1000}\/frp\.git.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7258 |
| 177 | */frp_0.*.*_darwin_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7259 |
| 178 | */frp_0.*.*_darwin_arm64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7260 |
| 179 | */frp_0.*.*_freebsd_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_freebsd_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7261 |
| 180 | */frp_0.*.*_linux_amd64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7262 |
| 181 | */frp_0.*.*_linux_arm.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7263 |
| 182 | */frp_0.*.*_linux_arm64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7264 |
| 183 | */frp_0.*.*_linux_mips.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7265 |
| 184 | */frp_0.*.*_linux_mips64.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7266 |
| 185 | */frp_0.*.*_linux_mips64le.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64le\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7267 |
| 186 | */frp_0.*.*_linux_mipsle.tar.gz* | .{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mipsle\.tar\.gz.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | #linux | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7268 |
| 187 | */frpc.exe* | .{0,1000}\/frpc\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 7270 |
| 188 | */github.com*.exe?raw=true* | .{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7414 |
| 189 | */github.com/*/archive/refs/tags/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7415 |
| 190 | */github.com/*/raw/main/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7416 |
| 191 | */github.com/*/raw/main/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7417 |
| 192 | */github.com/*/raw/main/*.app* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7418 |
| 193 | */github.com/*/raw/main/*.as* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7419 |
| 194 | */github.com/*/raw/main/*.asc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7420 |
| 195 | */github.com/*/raw/main/*.asp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7421 |
| 196 | */github.com/*/raw/main/*.bash* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | #linux | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7422 |
| 197 | */github.com/*/raw/main/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7423 |
| 198 | */github.com/*/raw/main/*.beacon* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7424 |
| 199 | */github.com/*/raw/main/*.bin* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7425 |
| 200 | */github.com/*/raw/main/*.bpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7426 |
| 201 | */github.com/*/raw/main/*.c* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7427 |
| 202 | */github.com/*/raw/main/*.cer* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7428 |
| 203 | */github.com/*/raw/main/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7429 |
| 204 | */github.com/*/raw/main/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7430 |
| 205 | */github.com/*/raw/main/*.cpp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7431 |
| 206 | */github.com/*/raw/main/*.crt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7432 |
| 207 | */github.com/*/raw/main/*.cs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7433 |
| 208 | */github.com/*/raw/main/*.csh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7434 |
| 209 | */github.com/*/raw/main/*.dat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7435 |
| 210 | */github.com/*/raw/main/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7436 |
| 211 | */github.com/*/raw/main/*.docm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7437 |
| 212 | */github.com/*/raw/main/*.dos* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7438 |
| 213 | */github.com/*/raw/main/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7439 |
| 214 | */github.com/*/raw/main/*.go* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7440 |
| 215 | */github.com/*/raw/main/*.gz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7441 |
| 216 | */github.com/*/raw/main/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7442 |
| 217 | */github.com/*/raw/main/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7443 |
| 218 | */github.com/*/raw/main/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7444 |
| 219 | */github.com/*/raw/main/*.js* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7445 |
| 220 | */github.com/*/raw/main/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7446 |
| 221 | */github.com/*/raw/main/*.log* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7447 |
| 222 | */github.com/*/raw/main/*.mac* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7448 |
| 223 | */github.com/*/raw/main/*.mam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7449 |
| 224 | */github.com/*/raw/main/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7450 |
| 225 | */github.com/*/raw/main/*.msp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7451 |
| 226 | */github.com/*/raw/main/*.nexe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7452 |
| 227 | */github.com/*/raw/main/*.nim* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7453 |
| 228 | */github.com/*/raw/main/*.otm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7454 |
| 229 | */github.com/*/raw/main/*.out* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7455 |
| 230 | */github.com/*/raw/main/*.ova* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7456 |
| 231 | */github.com/*/raw/main/*.pem* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7457 |
| 232 | */github.com/*/raw/main/*.pfx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7458 |
| 233 | */github.com/*/raw/main/*.pl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7459 |
| 234 | */github.com/*/raw/main/*.plx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7460 |
| 235 | */github.com/*/raw/main/*.pm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7461 |
| 236 | */github.com/*/raw/main/*.ppk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7462 |
| 237 | */github.com/*/raw/main/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7463 |
| 238 | */github.com/*/raw/main/*.psm1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7464 |
| 239 | */github.com/*/raw/main/*.pub* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7465 |
| 240 | */github.com/*/raw/main/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7466 |
| 241 | */github.com/*/raw/main/*.pyc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7467 |
| 242 | */github.com/*/raw/main/*.pyo* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7468 |
| 243 | */github.com/*/raw/main/*.rar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7469 |
| 244 | */github.com/*/raw/main/*.raw* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7470 |
| 245 | */github.com/*/raw/main/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7471 |
| 246 | */github.com/*/raw/main/*.rgs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7472 |
| 247 | */github.com/*/raw/main/*.RGS* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7473 |
| 248 | */github.com/*/raw/main/*.run* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7474 |
| 249 | */github.com/*/raw/main/*.scpt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7475 |
| 250 | */github.com/*/raw/main/*.script* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7476 |
| 251 | */github.com/*/raw/main/*.sct* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7477 |
| 252 | */github.com/*/raw/main/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7478 |
| 253 | */github.com/*/raw/main/*.ssh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7479 |
| 254 | */github.com/*/raw/main/*.sys* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7480 |
| 255 | */github.com/*/raw/main/*.teamserver* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7481 |
| 256 | */github.com/*/raw/main/*.temp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7482 |
| 257 | */github.com/*/raw/main/*.tgz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7483 |
| 258 | */github.com/*/raw/main/*.tmp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7484 |
| 259 | */github.com/*/raw/main/*.vb* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7485 |
| 260 | */github.com/*/raw/main/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7486 |
| 261 | */github.com/*/raw/main/*.vbscript* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7487 |
| 262 | */github.com/*/raw/main/*.ws* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7488 |
| 263 | */github.com/*/raw/main/*.wsf* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7489 |
| 264 | */github.com/*/raw/main/*.wsh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7490 |
| 265 | */github.com/*/raw/main/*.X86* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7491 |
| 266 | */github.com/*/raw/main/*.X86_64* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7492 |
| 267 | */github.com/*/raw/main/*.xlam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7493 |
| 268 | */github.com/*/raw/main/*.xlm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7494 |
| 269 | */github.com/*/raw/main/*.xlsm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7495 |
| 270 | */github.com/*/raw/main/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7496 |
| 271 | */github.com/*/raw/refs/heads/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7497 |
| 272 | */github.com/*/raw/refs/heads/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7498 |
| 273 | */github.com/*/raw/refs/heads/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7499 |
| 274 | */github.com/*/raw/refs/heads/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7500 |
| 275 | */github.com/*/raw/refs/heads/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7501 |
| 276 | */github.com/*/raw/refs/heads/*.cpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7502 |
| 277 | */github.com/*/raw/refs/heads/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7503 |
| 278 | */github.com/*/raw/refs/heads/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7504 |
| 279 | */github.com/*/raw/refs/heads/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7505 |
| 280 | */github.com/*/raw/refs/heads/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7506 |
| 281 | */github.com/*/raw/refs/heads/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7507 |
| 282 | */github.com/*/raw/refs/heads/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7508 |
| 283 | */github.com/*/raw/refs/heads/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7509 |
| 284 | */github.com/*/raw/refs/heads/*.pif* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7510 |
| 285 | */github.com/*/raw/refs/heads/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7511 |
| 286 | */github.com/*/raw/refs/heads/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7512 |
| 287 | */github.com/*/raw/refs/heads/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7513 |
| 288 | */github.com/*/raw/refs/heads/*.scr* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7514 |
| 289 | */github.com/*/raw/refs/heads/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7515 |
| 290 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7516 |
| 291 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7517 |
| 292 | */github.com/*/raw/refs/heads/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7518 |
| 293 | */go-gost/core/* | .{0,1000}\/go\-gost\/core\/.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7563 |
| 294 | */go-http-tunnel.git.git* | .{0,1000}\/go\-http\-tunnel\.git\.git.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 7564 |
| 295 | */go-http-tunnel/cmd/* | .{0,1000}\/go\-http\-tunnel\/cmd\/.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 7565 |
| 296 | */go-localtunnel.git* | .{0,1000}\/go\-localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/NoahShen/gotunnelme | 1 | 1 | N/A | N/A | 10 | 10 | 171 | 45 | 2018-01-06T04:41:15Z | 2013-10-18T02:46:51Z | 7570 |
| 297 | */GoodSync-vsub-Setup.exe* | .{0,1000}\/GoodSync\-vsub\-Setup\.exe.{0,1000} | greyware_tool_keyword | Goodsync | GoodSync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | N/A | Data Exfiltration | https://www.goodsync.com/ | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 7579 |
| 298 | */gost.tar.gz* | .{0,1000}\/gost\.tar\.gz.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7597 |
| 299 | */gost/raw/master/install.sh* | .{0,1000}\/gost\/raw\/master\/install\.sh.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7598 |
| 300 | */gost/releases/download/*.tar.gz* | .{0,1000}\/gost\/releases\/download\/.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 7599 |
| 301 | */gotunnelme.git* | .{0,1000}\/gotunnelme\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/NoahShen/gotunnelme | 1 | 1 | N/A | N/A | 10 | 10 | 171 | 45 | 2018-01-06T04:41:15Z | 2013-10-18T02:46:51Z | 7603 |
| 302 | */gt-win-x86_64.exe* | .{0,1000}\/gt\-win\-x86_64\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 7682 |
| 303 | */host-7.2.2.0.msi* | .{0,1000}\/host\-7\.2\.2\.0\.msi.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7810 |
| 304 | */hypertunnel.git* | .{0,1000}\/hypertunnel\.git.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7992 |
| 305 | */hypertunnel-tcp-relay*.tar.gz* | .{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7993 |
| 306 | */hypertunnel-tcp-relay*.zip* | .{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 7994 |
| 307 | */install-fleetctl.sh* | .{0,1000}\/install\-fleetctl\.sh.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 8101 |
| 308 | */interactsh/* | .{0,1000}\/interactsh\/.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C5 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8106 |
| 309 | */interactsh-client* | .{0,1000}\/interactsh\-client.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C6 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8107 |
| 310 | */interactsh-collaborator* | .{0,1000}\/interactsh\-collaborator.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C15 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8108 |
| 311 | */interactsh-server* | .{0,1000}\/interactsh\-server.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C8 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 8109 |
| 312 | */Invoke-Maldaptive.git* | .{0,1000}\/Invoke\-Maldaptive\.git.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 1 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 8153 |
| 313 | */IObitUnlocker.exe* | .{0,1000}\/IObitUnlocker\.exe.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 1 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 8172 |
| 314 | */ipscan.exe* | .{0,1000}\/ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8199 |
| 315 | */ipscan.git* | .{0,1000}\/ipscan\.git.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8200 |
| 316 | */jprq.git* | .{0,1000}\/jprq\.git.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8251 |
| 317 | */jprq-darwin-arm64* | .{0,1000}\/jprq\-darwin\-arm64.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8255 |
| 318 | */jprq-linux-386* | .{0,1000}\/jprq\-linux\-386.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8256 |
| 319 | */jprq-linux-arm64* | .{0,1000}\/jprq\-linux\-arm64.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8257 |
| 320 | */jprq-windows-386.exe* | .{0,1000}\/jprq\-windows\-386\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8258 |
| 321 | */jprq-windows-amd64.exe* | .{0,1000}\/jprq\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 8259 |
| 322 | */lansearch.exe* | .{0,1000}\/lansearch\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8435 |
| 323 | */LansweeperSetup_*.exe* | .{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 8436 |
| 324 | */latest/download/tunwg* | .{0,1000}\/latest\/download\/tunwg.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 8453 |
| 325 | */level-windows-amd64.exe* | .{0,1000}\/level\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8492 |
| 326 | */level-windows-arm64.exe* | .{0,1000}\/level\-windows\-arm64\.exe.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8493 |
| 327 | */LMI_Rescue.exe* | .{0,1000}\/LMI_Rescue\.exe.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8558 |
| 328 | */LMIRTechConsole.exe* | .{0,1000}\/LMIRTechConsole\.exe.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8559 |
| 329 | */localtunnel.git* | .{0,1000}\/localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8596 |
| 330 | */localtunnel.git* | .{0,1000}\/localtunnel\.git.{0,1000} | greyware_tool_keyword | localtunnels | client for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 8 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8597 |
| 331 | */localtunnel.js* | .{0,1000}\/localtunnel\.js.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 8598 |
| 332 | */localtunnel-server.git* | .{0,1000}\/localtunnel\-server\.git.{0,1000} | greyware_tool_keyword | localtunnels | server for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/server | 1 | 1 | N/A | N/A | 8 | 10 | 3163 | 1033 | 2024-03-20T09:14:46Z | 2013-06-16T22:30:48Z | 8600 |
| 333 | */loclx.exe* | .{0,1000}\/loclx\.exe.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 8606 |
| 334 | */loclx-windows-amd64.zip* | .{0,1000}\/loclx\-windows\-amd64\.zip.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 8607 |
| 335 | */lsa-whisperer-*.zip* | .{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8658 |
| 336 | */lsa-whisperer.git* | .{0,1000}\/lsa\-whisperer\.git.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8659 |
| 337 | */LTProxy.git* | .{0,1000}\/LTProxy\.git.{0,1000} | greyware_tool_keyword | LTProxy | Linux Transparent Proxy (Similar to Proxifiter) | T1090 - T1573.001 - T1571 - T1071.001 | TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://github.com/L-codes/LTProxy | 1 | 1 | #linux | N/A | 10 | 1 | 31 | 5 | 2024-11-27T05:09:47Z | 2021-11-11T15:17:54Z | 8660 |
| 338 | */MEGAclient.exe* | .{0,1000}\/MEGAclient\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8734 |
| 339 | */MEGAcmd.exe* | .{0,1000}\/MEGAcmd\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8735 |
| 340 | */MEGAcmd.sh* | .{0,1000}\/MEGAcmd\.sh.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8736 |
| 341 | */MEGAcmdServer.exe* | .{0,1000}\/MEGAcmdServer\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8737 |
| 342 | */MEGAcmdSetup.exe* | .{0,1000}\/MEGAcmdSetup\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8738 |
| 343 | */MEGAcmdSetup32.exe* | .{0,1000}\/MEGAcmdSetup32\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8739 |
| 344 | */MEGAcmdSetup64.exe* | .{0,1000}\/MEGAcmdSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8740 |
| 345 | */MEGAcmdSetup64.exe* | .{0,1000}\/MEGAcmdSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8741 |
| 346 | */MEGAcmdShell.exe* | .{0,1000}\/MEGAcmdShell\.exe.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 8742 |
| 347 | */megasync.exe* | .{0,1000}\/megasync\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8744 |
| 348 | */MEGAsyncSetup32.exe* | .{0,1000}\/MEGAsyncSetup32\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8745 |
| 349 | */MEGAsyncSetup64.exe* | .{0,1000}\/MEGAsyncSetup64\.exe.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8746 |
| 350 | */MeshAgent.git* | .{0,1000}\/MeshAgent\.git.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshAgent | 1 | 1 | N/A | N/A | 10 | 3 | 264 | 96 | 2025-03-19T18:43:56Z | 2017-10-12T21:26:52Z | 8775 |
| 351 | */MeshCentral.git* | .{0,1000}\/MeshCentral\.git.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8776 |
| 352 | */meshinstall.sh* | .{0,1000}\/meshinstall\.sh.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8778 |
| 353 | */meshinstall-bsd-rcd.sh* | .{0,1000}\/meshinstall\-bsd\-rcd\.sh.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 8779 |
| 354 | */Microsoft Azure Storage Explorer.app* | .{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.app.{0,1000} | greyware_tool_keyword | Azure Storage Explorer | legitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data Exfiltration | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Rhysida | Data Exfiltration | https://azure.microsoft.com/en-us/products/storage/storage-explorer | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 8812 |
| 355 | */Microsoft Azure Storage Explorer.zip* | .{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.zip.{0,1000} | greyware_tool_keyword | Azure Storage Explorer | legitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data Exfiltration | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Rhysida | Data Exfiltration | https://azure.microsoft.com/en-us/products/storage/storage-explorer | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 8813 |
| 356 | */MITMPluginLogViewer* | .{0,1000}\/MITMPluginLogViewer.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 8865 |
| 357 | */MITMServerHijacking* | .{0,1000}\/MITMServerHijacking.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 8867 |
| 358 | */mzcv-x64.zip* | .{0,1000}\/mzcv\-x64\.zip.{0,1000} | greyware_tool_keyword | MozillaCookiesView | nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors | T1070 - T1552.001 - T1125 - T1005 | TA0009 - TA0005 | N/A | MuddyWater | Credential Access | https://www.nirsoft.net/utils/mzcv.html | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8994 |
| 359 | */nats-rmm.conf* | .{0,1000}\/nats\-rmm\.conf.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 9019 |
| 360 | */neoreg.py* | .{0,1000}\/neoreg\.py.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9047 |
| 361 | */Neo-reGeorg.git* | .{0,1000}\/Neo\-reGeorg\.git.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9048 |
| 362 | */NeoreGeorg.java* | .{0,1000}\/NeoreGeorg\.java.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9049 |
| 363 | */Neo-reGeorg/tarball* | .{0,1000}\/Neo\-reGeorg\/tarball.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9050 |
| 364 | */Neo-reGeorg/zipball* | .{0,1000}\/Neo\-reGeorg\/zipball.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 9051 |
| 365 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 9108 |
| 366 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9109 |
| 367 | */netscan_linux.tar.gz* | .{0,1000}\/netscan_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9110 |
| 368 | */netscan_macos.dmg* | .{0,1000}\/netscan_macos\.dmg.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #macos | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9111 |
| 369 | */netscan_setup.exe* | .{0,1000}\/netscan_setup\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9112 |
| 370 | */netscan64.exe* | .{0,1000}\/netscan64\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9113 |
| 371 | */netshrun.c* | .{0,1000}\/netshrun\.c.{0,1000} | greyware_tool_keyword | NetshRun | Netsh.exe relies on extensions taken from Registry which means it may be used as a persistence and you go one step further extending netsh with a DLL allowing you to do whatever you want | T1546.008 - T1112 - T1037 - T1055 - T1218.001 | TA0003 - TA0002 - TA0008 | N/A | N/A | Exploitation tool | https://github.com/gtworek/PSBits/blob/master/NetShRun | 1 | 1 | N/A | N/A | N/A | 10 | 3337 | 542 | 2025-03-12T19:59:23Z | 2019-06-29T13:22:36Z | 9117 |
| 372 | */ngrok.git* | .{0,1000}\/ngrok\.git.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9137 |
| 373 | */ngrok.go* | .{0,1000}\/ngrok\.go.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9138 |
| 374 | */ngrokd.go* | .{0,1000}\/ngrokd\.go.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 9140 |
| 375 | */NimScan.exe* | .{0,1000}\/NimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9175 |
| 376 | */NimScan.git* | .{0,1000}\/NimScan\.git.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9176 |
| 377 | */NimScan.nim* | .{0,1000}\/NimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9177 |
| 378 | */nircmd.exe* | .{0,1000}\/nircmd\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9184 |
| 379 | */nircmd.zip* | .{0,1000}\/nircmd\.zip.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9185 |
| 380 | */nircmdc.exe* | .{0,1000}\/nircmdc\.exe.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9186 |
| 381 | */nircmd-x64.zip* | .{0,1000}\/nircmd\-x64\.zip.{0,1000} | greyware_tool_keyword | nircmd | Nirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface | T1059 - T1036 | TA0005 - TA0002 - TA0003 | N/A | N/A | Defense Evasion | https://www.nirsoft.net/utils/nircmd.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9187 |
| 382 | */Nmap/folder/check15* | .{0,1000}\/Nmap\/folder\/check15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9198 |
| 383 | */Nmap/folder/check16* | .{0,1000}\/Nmap\/folder\/check16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9199 |
| 384 | */Nmap/folder/check17* | .{0,1000}\/Nmap\/folder\/check17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9200 |
| 385 | */nmaplowercheck15* | .{0,1000}\/nmaplowercheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://nmap.org/book/nse-usage.html | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | N/A | N/A | N/A | N/A | 9204 |
| 386 | */nmaplowercheck16* | .{0,1000}\/nmaplowercheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9205 |
| 387 | */nmaplowercheck17* | .{0,1000}\/nmaplowercheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9206 |
| 388 | */nmap-scada* | .{0,1000}\/nmap\-scada.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9208 |
| 389 | */NmapUpperCheck15* | .{0,1000}\/NmapUpperCheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9209 |
| 390 | */NmapUpperCheck16* | .{0,1000}\/NmapUpperCheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9210 |
| 391 | */NmapUpperCheck17* | .{0,1000}\/NmapUpperCheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9211 |
| 392 | */nmap-vulners* | .{0,1000}\/nmap\-vulners.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9212 |
| 393 | */nse-install.git* | .{0,1000}\/nse\-install\.git.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 9260 |
| 394 | */nspowershell.exe* | .{0,1000}\/nspowershell\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9264 |
| 395 | */nssadmui.exe* | .{0,1000}\/nssadmui\.exe.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9265 |
| 396 | */OfflineSamTool.exe* | .{0,1000}\/OfflineSamTool\.exe.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9370 |
| 397 | */openvpn.exe* | .{0,1000}\/openvpn\.exe.{0,1000} | greyware_tool_keyword | OPENVPN | OpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate data | T1071 - T1573 - T1133 | TA0003 - TA0008 - TA0011 | N/A | N/A | Defense Evasion | https://openvpn.net/ | 1 | 1 | #VPN | N/A | 6 | 8 | N/A | N/A | N/A | N/A | 9396 |
| 398 | */oset.exe* | .{0,1000}\/oset\.exe.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9447 |
| 399 | */oset.zip* | .{0,1000}\/oset\.zip.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9448 |
| 400 | */OshiUpload.git* | .{0,1000}\/OshiUpload\.git.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 9450 |
| 401 | */PAExec.cpp* | .{0,1000}\/PAExec\.cpp.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9480 |
| 402 | */paexec.exe | .{0,1000}\/paexec\.exe | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9481 |
| 403 | */PAExec.git* | .{0,1000}\/PAExec\.git.{0,1000} | greyware_tool_keyword | PAExec | PAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec program | T1047 - T1105 - T1204 | TA0003 - TA0008 - TA0040 | N/A | N/A | Lateral Movement | https://github.com/poweradminllc/PAExec | 1 | 1 | N/A | N/A | 10 | 6 | 560 | 177 | 2025-02-21T15:14:44Z | 2013-11-13T04:05:27Z | 9482 |
| 404 | */pagekite.py* | .{0,1000}\/pagekite\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9486 |
| 405 | */pagekite-0.3.21.py* | .{0,1000}\/pagekite\-0\.3\.21\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9487 |
| 406 | */pagekite-0.4.6a.py* | .{0,1000}\/pagekite\-0\.4\.6a\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9488 |
| 407 | */pagekite-0.5.6d.py* | .{0,1000}\/pagekite\-0\.5\.6d\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9489 |
| 408 | */pagekite-0.5.8a.py* | .{0,1000}\/pagekite\-0\.5\.8a\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9490 |
| 409 | */pagekite-gtk.py* | .{0,1000}\/pagekite\-gtk\.py.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 9491 |
| 410 | */PCHunter.exe* | .{0,1000}\/PCHunter\.exe.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9569 |
| 411 | */PCHunter_free.zip* | .{0,1000}\/PCHunter_free\.zip.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9570 |
| 412 | */PCMonitorManager.exe* | .{0,1000}\/PCMonitorManager\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9573 |
| 413 | */PCMonitorSrv.exe* | .{0,1000}\/PCMonitorSrv\.exe.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9574 |
| 414 | */pcmontask.exe* | .{0,1000}\/pcmontask\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9575 |
| 415 | */pcmrdp-client.dll* | .{0,1000}\/pcmrdp\-client\.dll.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9576 |
| 416 | */pcunlocker.iso* | .{0,1000}\/pcunlocker\.iso.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9577 |
| 417 | */pcunlocker_trial.zip* | .{0,1000}\/pcunlocker_trial\.zip.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9578 |
| 418 | */pgrok.exe* | .{0,1000}\/pgrok\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 9651 |
| 419 | */pgrok.git* | .{0,1000}\/pgrok\.git.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9652 |
| 420 | */pgrokd.exe* | .{0,1000}\/pgrokd\.exe.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/jerson/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 283 | 55 | 2022-05-30T14:53:46Z | 2019-07-31T13:23:51Z | 9654 |
| 421 | */pgrokd_*.zip* | .{0,1000}\/pgrokd_.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 9656 |
| 422 | */pingcastle.git* | .{0,1000}\/pingcastle\.git.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9695 |
| 423 | */PingCastle.zip* | .{0,1000}\/PingCastle\.zip.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9696 |
| 424 | */pingcastle/releases/download/* | .{0,1000}\/pingcastle\/releases\/download\/.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 9697 |
| 425 | */PortQry.exe* | .{0,1000}\/PortQry\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9748 |
| 426 | */PortQryV2.exe* | .{0,1000}\/PortQryV2\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9749 |
| 427 | */portr.exe* | .{0,1000}\/portr\.exe.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9750 |
| 428 | */portr.git* | .{0,1000}\/portr\.git.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9751 |
| 429 | */portr/releases* | .{0,1000}\/portr\/releases.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9752 |
| 430 | */portr_*_Darwin_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Darwin_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9753 |
| 431 | */portr_*_Darwin_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Darwin_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9754 |
| 432 | */portr_*_Linux_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Linux_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9755 |
| 433 | */portr_*_Linux_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Linux_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | #linux | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9756 |
| 434 | */portr_*_Windows_arm64.zip* | .{0,1000}\/portr_.{0,1000}_Windows_arm64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9757 |
| 435 | */portr_*_Windows_x86_64.zip* | .{0,1000}\/portr_.{0,1000}_Windows_x86_64\.zip.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9758 |
| 436 | */portr_admin/*.py* | .{0,1000}\/portr_admin\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 9759 |
| 437 | */privoxy.exe* | .{0,1000}\/privoxy\.exe.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 9904 |
| 438 | */Procdump.zip* | .{0,1000}\/Procdump\.zip.{0,1000} | greyware_tool_keyword | Procdump | dump lsass process with procdump | T1003.001 | TA0006 | N/A | LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor | Credential Access | https://learn.microsoft.com/en-us/sysinternals/downloads/procdump | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9907 |
| 439 | */processhacker-*-bin.zip* | .{0,1000}\/processhacker\-.{0,1000}\-bin\.zip.{0,1000} | greyware_tool_keyword | processhacker | Interactions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injection | T1055.001 - T1055.012 - T1003.001 - T1056.005 | TA0005 - TA0003 - TA0040 - TA0006 - TA0009 | N/A | N/A | Persistence | https://processhacker.sourceforge.io/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 9910 |
| 440 | */processhacker/files/latest/download* | .{0,1000}\/processhacker\/files\/latest\/download.{0,1000} | greyware_tool_keyword | processhacker | Interactions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injection | T1055.001 - T1055.012 - T1003.001 - T1056.005 | TA0005 - TA0003 - TA0040 - TA0006 - TA0009 | N/A | N/A | Persistence | https://processhacker.sourceforge.io/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 9911 |
| 441 | */ProduKey.exe* | .{0,1000}\/ProduKey\.exe.{0,1000} | greyware_tool_keyword | produkey | ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer. | T1003.001 - T1003.002 - T1012 - T1057 - T1518 | TA0006 - TA0007 - TA0009 | N/A | Evilnum | Credential Access | https://www.nirsoft.net/utils/product_cd_key_viewer.html | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 9915 |
| 442 | */Proxifier.exe* | .{0,1000}\/Proxifier\.exe.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9929 |
| 443 | */ProxifierPE.zip* | .{0,1000}\/ProxifierPE\.zip.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9931 |
| 444 | */ProxifierSetup.exe* | .{0,1000}\/ProxifierSetup\.exe.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 9932 |
| 445 | */ps2exe.ps1* | .{0,1000}\/ps2exe\.ps1.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 1 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 9952 |
| 446 | */pslist.exe* | .{0,1000}\/pslist\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9972 |
| 447 | */pslist64.exe* | .{0,1000}\/pslist64\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9973 |
| 448 | */pulseway_x64.deb* | .{0,1000}\/pulseway_x64\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10002 |
| 449 | */Pulseway_x64.msi* | .{0,1000}\/Pulseway_x64\.msi.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10003 |
| 450 | */pulseway_x86.deb* | .{0,1000}\/pulseway_x86\.deb.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10004 |
| 451 | */py2exe/* | .{0,1000}\/py2exe\/.{0,1000} | greyware_tool_keyword | py2exe | py2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attacker | T1027.002 - T1045 - T1059.001 - T1587.001 | TA0005 - TA0042 | Operation Wocao | N/A | Resource Development | https://github.com/py2exe/py2exe | 1 | 1 | N/A | greyware_tools high risks of false positives | N/A | 10 | 927 | 102 | 2024-11-12T19:44:34Z | 2019-03-11T13:16:35Z | 10061 |
| 452 | */pyjam.as/tunnel* | .{0,1000}\/pyjam\.as\/tunnel.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10070 |
| 453 | */PyPagekite.git* | .{0,1000}\/PyPagekite\.git.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10083 |
| 454 | */PyPagekite/tarball/* | .{0,1000}\/PyPagekite\/tarball\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10084 |
| 455 | */PyPagekite/zipball/* | .{0,1000}\/PyPagekite\/zipball\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 10085 |
| 456 | */pyshark.git* | .{0,1000}\/pyshark\.git.{0,1000} | greyware_tool_keyword | pyshark | Python wrapper for tshark allowing python packet parsing using wireshark dissectors | T1040 - T1213 - T1105 - T1572 | TA0009 - TA0007 | N/A | N/A | Discovery | https://github.com/KimiNewt/pyshark | 1 | 1 | N/A | N/A | 6 | 10 | 2355 | 439 | 2024-12-04T15:41:20Z | 2013-12-28T14:38:22Z | 10096 |
| 457 | */QNAP_NAS/megacmdpkg* | .{0,1000}\/QNAP_NAS\/megacmdpkg.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 10116 |
| 458 | */Quasar.git* | .{0,1000}\/Quasar\.git.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10125 |
| 459 | */Quasar.v*.zip* | .{0,1000}\/Quasar\.v.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10126 |
| 460 | */Quasar/releases* | .{0,1000}\/Quasar\/releases.{0,1000} | greyware_tool_keyword | Quasar | Open-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#. | T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125 | TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040 | N/A | Patchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - Molerats | RMM | https://github.com/quasar/Quasar | 1 | 1 | N/A | N/A | N/A | 10 | 9187 | 2551 | 2024-02-29T06:37:37Z | 2014-07-08T12:27:59Z | 10127 |
| 461 | */Quick Assist Installer.exe* | .{0,1000}\/Quick\sAssist\sInstaller\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 10129 |
| 462 | */Quick%20Assist%20Installer.exe* | .{0,1000}\/Quick\%20Assist\%20Installer\.exe.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 10130 |
| 463 | */Radmin.exe* | .{0,1000}\/Radmin\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10142 |
| 464 | */Radmin_Server_*.msi* | .{0,1000}\/Radmin_Server_.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10143 |
| 465 | */Radmin_Viewer_*.msi* | .{0,1000}\/Radmin_Viewer_.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10144 |
| 466 | */Radmin_VPN_1.*.exe* | .{0,1000}\/Radmin_VPN_1\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10145 |
| 467 | */rathole.exe | .{0,1000}\/rathole\.exe | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10168 |
| 468 | */rathole.git* | .{0,1000}\/rathole\.git.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10169 |
| 469 | */rathole/src/* | .{0,1000}\/rathole\/src\/.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10170 |
| 470 | */rathole-aarch64-* | .{0,1000}\/rathole\-aarch64\-.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10171 |
| 471 | */rathole-arm* | .{0,1000}\/rathole\-arm.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10172 |
| 472 | */rathole-main/* | .{0,1000}\/rathole\-main\/.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10173 |
| 473 | */rathole-mipsel-* | .{0,1000}\/rathole\-mipsel\-.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10174 |
| 474 | */rathole-x86_64* | .{0,1000}\/rathole\-x86_64.{0,1000} | greyware_tool_keyword | rathole | expose the service on the device behind the NAT to the Internet, via a server with a public IP. | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/rapiz1/rathole | 1 | 1 | N/A | N/A | 10 | 10 | 10580 | 549 | 2024-07-06T20:09:48Z | 2021-12-14T05:03:07Z | 10175 |
| 475 | */raw/main/speedtest.exe* | .{0,1000}\/raw\/main\/speedtest\.exe.{0,1000} | greyware_tool_keyword | speedtest | legitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration efforts | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | Dispossessor - Dagon Locker | Data Exfiltration | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 10185 | |
| 476 | */raw/master/speedtest.exe* | .{0,1000}\/raw\/master\/speedtest\.exe.{0,1000} | greyware_tool_keyword | speedtest | legitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration efforts | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | Dispossessor - Dagon Locker | Data Exfiltration | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 10188 | |
| 477 | */rclone.git* | .{0,1000}\/rclone\.git.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10200 |
| 478 | */rclone.rar* | .{0,1000}\/rclone\.rar.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10201 |
| 479 | */rclone.zip* | .{0,1000}\/rclone\.zip.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10202 |
| 480 | */rclone/releases/download/* | .{0,1000}\/rclone\/releases\/download\/.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 10203 |
| 481 | */rdpscan.git* | .{0,1000}\/rdpscan\.git.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10223 |
| 482 | */rdpscan-macos.zip* | .{0,1000}\/rdpscan\-macos\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10224 |
| 483 | */rdpscan-windows.zip* | .{0,1000}\/rdpscan\-windows\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10225 |
| 484 | */RDPWInst.exe* | .{0,1000}\/RDPWInst\.exe.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10235 |
| 485 | */RDPWInst-v*.msi* | .{0,1000}\/RDPWInst\-v.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10236 |
| 486 | */rdpwrap.dll* | .{0,1000}\/rdpwrap\.dll.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10237 |
| 487 | */rdpwrap.git* | .{0,1000}\/rdpwrap\.git.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10238 |
| 488 | */RDPWrap-v*.zip* | .{0,1000}\/RDPWrap\-v.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | rdpwrap | RDP Wrapper Library used by malwares | T1021 | TA0008 | N/A | N/A | Lateral Movement | https://github.com/stascorp/rdpwrap | 1 | 1 | N/A | N/A | 10 | 10 | 15332 | 3911 | 2024-06-18T15:08:33Z | 2014-10-22T23:18:28Z | 10239 |
| 489 | */RealTimeSync.exe* | .{0,1000}\/RealTimeSync\.exe.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 10246 |
| 490 | */RedTeaming-Tactics-and-Techniques.git* | .{0,1000}\/RedTeaming\-Tactics\-and\-Techniques\.git.{0,1000} | greyware_tool_keyword | ired.team | Red Teaming Tactics and Techniques | T1593.003 | TA0043 | N/A | N/A | Reconnaissance | https://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques | 1 | 1 | N/A | N/A | 7 | 10 | 4234 | 1071 | 2024-08-22T07:17:31Z | 2019-03-02T13:33:33Z | 10302 |
| 491 | */release/gt-win-x86_64.exe* | .{0,1000}\/release\/gt\-win\-x86_64\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 10336 |
| 492 | */release/sshx-server* | .{0,1000}\/release\/sshx\-server.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 10337 |
| 493 | */releases/download/Ahk2Exe* | .{0,1000}\/releases\/download\/Ahk2Exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 10339 |
| 494 | */RemCom.exe* | .{0,1000}\/RemCom\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10352 |
| 495 | */RemCom.git* | .{0,1000}\/RemCom\.git.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10353 |
| 496 | */RemComSvc.exe* | .{0,1000}\/RemComSvc\.exe.{0,1000} | greyware_tool_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 1 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 10354 |
| 497 | */Remote.It-Installer-* | .{0,1000}\/Remote\.It\-Installer\-.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10356 |
| 498 | */RemoteControlSetup.exe* | .{0,1000}\/RemoteControlSetup\.exe.{0,1000} | greyware_tool_keyword | ComodoRMM (Itarian RMM) | Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://one.comodo.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10369 |
| 499 | */RemoteDesktop.exe* | .{0,1000}\/RemoteDesktop\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10370 |
| 500 | */remoteit.exe* | .{0,1000}\/remoteit\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10373 |
| 501 | */remoteit.x86-win.exe* | .{0,1000}\/remoteit\.x86\-win\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10374 |
| 502 | */remoteit/connectd/releases* | .{0,1000}\/remoteit\/connectd\/releases.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 10375 |
| 503 | */remoteit/desktop* | .{0,1000}\/remoteit\/desktop.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10376 |
| 504 | */remoteit-desktop.exe* | .{0,1000}\/remoteit\-desktop\.exe.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/desktop | 1 | 1 | N/A | N/A | 10 | 10 | 46 | 11 | 2025-04-11T23:19:29Z | 2019-01-12T00:59:20Z | 10377 |
| 505 | */remotemoe.git* | .{0,1000}\/remotemoe\.git.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 10382 |
| 506 | */remotepc.deb* | .{0,1000}\/remotepc\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10384 |
| 507 | */remotepc.deb* | .{0,1000}\/remotepc\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10385 |
| 508 | */RemotePC.exe* | .{0,1000}\/RemotePC\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10386 |
| 509 | */RemotePC.exe* | .{0,1000}\/RemotePC\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10387 |
| 510 | */RemotePC.lnk* | .{0,1000}\/RemotePC\.lnk.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10388 |
| 511 | */RemotePC.tmp* | .{0,1000}\/RemotePC\.tmp.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10389 |
| 512 | */remotepc-attended.deb* | .{0,1000}\/remotepc\-attended\.deb.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10390 |
| 513 | */RemotePCAttended.dmg* | .{0,1000}\/RemotePCAttended\.dmg.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | #macos | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10391 |
| 514 | */remotepclauncher.exe* | .{0,1000}\/remotepclauncher\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10392 |
| 515 | */RemotePCSuite.dmg* | .{0,1000}\/RemotePCSuite\.dmg.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | #macos | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10393 |
| 516 | */remotepcuiu.exe* | .{0,1000}\/remotepcuiu\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10394 |
| 517 | */RemotePCViewer.msi* | .{0,1000}\/RemotePCViewer\.msi.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10395 |
| 518 | */restic-*.tar.gz* | .{0,1000}\/restic\-.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10424 |
| 519 | */restic.exe* | .{0,1000}\/restic\.exe.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10425 |
| 520 | */restic/releases/download/* | .{0,1000}\/restic\/releases\/download\/.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10426 |
| 521 | */restic_*_windows_amd64.zip* | .{0,1000}\/restic_.{0,1000}_windows_amd64\.zip.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10427 |
| 522 | */restic-master/* | .{0,1000}\/restic\-master\/.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 10428 |
| 523 | */reverse-tunnel.git* | .{0,1000}\/reverse\-tunnel\.git.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10451 |
| 524 | */reverse-tunnel/agent/cmd* | .{0,1000}\/reverse\-tunnel\/agent\/cmd.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10452 |
| 525 | */reverse-tunnel/server/service* | .{0,1000}\/reverse\-tunnel\/server\/service.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10453 |
| 526 | */RevoUninProSetup.exe* | .{0,1000}\/RevoUninProSetup\.exe.{0,1000} | greyware_tool_keyword | RevoUninstaller | legitimate tool abused by the Dispossessor ransomware group | T1562.001 - T1112 - T1059 - T1036 | TA0005 - TA0040 | N/A | Dispossessor | Defense Evasion | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10457 |
| 527 | */rfusclient.exe* | .{0,1000}\/rfusclient\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10472 |
| 528 | */rmm/api/tacticalrmm/* | .{0,1000}\/rmm\/api\/tacticalrmm\/.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 10487 |
| 529 | */rmm-installer.ps1* | .{0,1000}\/rmm\-installer\.ps1.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 10488 |
| 530 | */RpcDND_Console.exe* | .{0,1000}\/RpcDND_Console\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10540 |
| 531 | */rpcdownloader.exe* | .{0,1000}\/rpcdownloader\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10541 |
| 532 | */RPCFireWallRule.exe* | .{0,1000}\/RPCFireWallRule\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10545 |
| 533 | */rpcperfviewer.exe* | .{0,1000}\/rpcperfviewer\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10549 |
| 534 | */RPCProxyLatency.exe* | .{0,1000}\/RPCProxyLatency\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10550 |
| 535 | */rserver3.exe* | .{0,1000}\/rserver3\.exe.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10554 |
| 536 | */rsocks.git* | .{0,1000}\/rsocks\.git.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10556 |
| 537 | */rsocks/releases/download/* | .{0,1000}\/rsocks\/releases\/download\/.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10559 |
| 538 | */rsocks_linux_amd64* | .{0,1000}\/rsocks_linux_amd64.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | #linux | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10560 |
| 539 | */rsocks_windows_386.exe* | .{0,1000}\/rsocks_windows_386\.exe.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 10561 |
| 540 | */rtun-freebsd-amd64* | .{0,1000}\/rtun\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10580 |
| 541 | */rtun-linux-amd64* | .{0,1000}\/rtun\-linux\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10581 |
| 542 | */rtun-linux-arm64* | .{0,1000}\/rtun\-linux\-arm64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10582 |
| 543 | */rtun-mac-amd64* | .{0,1000}\/rtun\-mac\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10583 |
| 544 | */rtun-server-freebsd-amd64* | .{0,1000}\/rtun\-server\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10584 |
| 545 | */rtun-server-linux-amd64* | .{0,1000}\/rtun\-server\-linux\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10585 |
| 546 | */rtun-server-linux-arm64* | .{0,1000}\/rtun\-server\-linux\-arm64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | #linux | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10586 |
| 547 | */rtun-server-mac-amd64* | .{0,1000}\/rtun\-server\-mac\-amd64.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10587 |
| 548 | */rtun-server-windows-amd64.exe* | .{0,1000}\/rtun\-server\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10588 |
| 549 | */rtun-windows-amd64.exe* | .{0,1000}\/rtun\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | reverse-tunnel | rtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/snsinfu/reverse-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 217 | 42 | 2023-10-15T07:29:32Z | 2018-07-09T21:41:50Z | 10589 |
| 550 | */RustDesk.exe* | .{0,1000}\/RustDesk\.exe.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10639 |
| 551 | */rustdesk.git* | .{0,1000}\/rustdesk\.git.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10640 |
| 552 | */rustdesk/rustdesk/releases/* | .{0,1000}\/rustdesk\/rustdesk\/releases\/.{0,1000} | greyware_tool_keyword | RustDesk | Rustdesk open suorce remote control software abused by scammers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | Akira - Scattered Spider* | RMM | https://github.com/rustdesk/rustdesk | 1 | 1 | N/A | N/A | 10 | 10 | 87186 | 12334 | 2025-04-22T15:18:36Z | 2020-09-28T15:36:08Z | 10641 |
| 553 | */rutserv.exe* | .{0,1000}\/rutserv\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10649 |
| 554 | */rutview.exe* | .{0,1000}\/rutview\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10650 |
| 555 | */sdelete.exe* | .{0,1000}\/sdelete\.exe.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10747 |
| 556 | */SDelete.zip* | .{0,1000}\/SDelete\.zip.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10748 |
| 557 | */sdelete64.exe* | .{0,1000}\/sdelete64\.exe.{0,1000} | greyware_tool_keyword | sdelete | SDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10749 |
| 558 | */sdelete64a.exe* | .{0,1000}\/sdelete64a\.exe.{0,1000} | greyware_tool_keyword | sdelete | delete one or more files and/or directories, or to cleanse the free space on a logical disk - abused by attackers | T1485 - T1070.004 | TA0005 - TA0040 | N/A | APT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDER | Defense Evasion | https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10750 |
| 559 | */send.exploit.in/* | .{0,1000}\/send\.exploit\.in\/.{0,1000} | greyware_tool_keyword | send.exploit.in | file-sharing platform used by ransomware groups | T1567 | TA0010 | N/A | Black Basta | Data Exfiltration | https://www.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10784 |
| 560 | */SetACL.exe* | .{0,1000}\/SetACL\.exe.{0,1000} | greyware_tool_keyword | SetACL | Manage Windows permissions from the command line | T1069 - T1222 | TA0002 - TA0004 - TA0005 | N/A | N/A | Defense Evasion | https://helgeklein.com/download/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10810 |
| 561 | */SetACL64..exe* | .{0,1000}\/SetACL64\.\.exe.{0,1000} | greyware_tool_keyword | SetACL | Manage Windows permissions from the command line | T1069 - T1222 | TA0002 - TA0004 - TA0005 | N/A | N/A | Defense Evasion | https://helgeklein.com/download/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 10811 |
| 562 | */set-proxy.ps1* | .{0,1000}\/set\-proxy\.ps1.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 10814 |
| 563 | */Shadowsocks-*.zip* | .{0,1000}\/Shadowsocks\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10839 |
| 564 | */Shadowsocks.zip* | .{0,1000}\/Shadowsocks\.zip.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10840 |
| 565 | */shadowsocks-rust.default* | .{0,1000}\/shadowsocks\-rust\.default.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10843 |
| 566 | */shadowsocks-rust.git* | .{0,1000}\/shadowsocks\-rust\.git.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10844 |
| 567 | */shadowsocks-rust.init* | .{0,1000}\/shadowsocks\-rust\.init.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10845 |
| 568 | */shadowsocks-rust.service* | .{0,1000}\/shadowsocks\-rust\.service.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10846 |
| 569 | */shadowsocks-service* | .{0,1000}\/shadowsocks\-service.{0,1000} | greyware_tool_keyword | shadowsocks | Rust port - shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-rust | 1 | 1 | N/A | N/A | 10 | 10 | 9312 | 1273 | 2025-04-21T14:29:22Z | 2014-10-15T11:02:36Z | 10847 |
| 570 | */shadowsocks-windows.git* | .{0,1000}\/shadowsocks\-windows\.git.{0,1000} | greyware_tool_keyword | shadowsocks | shadowsocks is a fast tunnel proxy that helps you bypass firewalls | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/shadowsocks/shadowsocks-windows | 1 | 1 | N/A | N/A | 10 | 10 | 58770 | 16368 | 2025-01-01T08:09:55Z | 2013-01-14T07:54:16Z | 10848 |
| 571 | */simplehelper64.exe* | .{0,1000}\/simplehelper64\.exe.{0,1000} | greyware_tool_keyword | SimpleHelp | SimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackCat | RMM | simple-help.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11275 |
| 572 | */SirTunnel.git* | .{0,1000}\/SirTunnel\.git.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 11296 |
| 573 | */sirtunnel.py* | .{0,1000}\/sirtunnel\.py.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 11297 |
| 574 | */sish.git* | .{0,1000}\/sish\.git.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 1 | N/A | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 11299 |
| 575 | */SoftEtherVPN-*.tar.xz* | .{0,1000}\/SoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11494 |
| 576 | */SoftEtherVPN.git* | .{0,1000}\/SoftEtherVPN\.git.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | abused https://asec.ahnlab.com/en/66843/ | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11495 |
| 577 | */SoftEtherVPN/releases/tag/* | .{0,1000}\/SoftEtherVPN\/releases\/tag\/.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11496 |
| 578 | */softether-vpnclient-*.exe* | .{0,1000}\/softether\-vpnclient\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11497 |
| 579 | */softether-vpnserver-*.deb* | .{0,1000}\/softether\-vpnserver\-.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11498 |
| 580 | */softether-vpnserver_*.exe* | .{0,1000}\/softether\-vpnserver_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 11500 |
| 581 | */SolarWinds-Dameware-DRS-St.exe* | .{0,1000}\/SolarWinds\-Dameware\-DRS\-St\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | Dameware Remote Support | 10 | 10 | N/A | N/A | N/A | N/A | 11502 |
| 582 | */sources.list.d/tailscale.list* | .{0,1000}\/sources\.list\.d\/tailscale\.list.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11506 |
| 583 | */sshtunnel.git* | .{0,1000}\/sshtunnel\.git.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11617 |
| 584 | */sshtunnel.py* | .{0,1000}\/sshtunnel\.py.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11618 |
| 585 | */sshtunnel/tarball/* | .{0,1000}\/sshtunnel\/tarball\/.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11619 |
| 586 | */sshtunnel/zipball/* | .{0,1000}\/sshtunnel\/zipball\/.{0,1000} | greyware_tool_keyword | sshtunnel | SSH tunnels to remote server | T1572 - T1219 | TA0005 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/pahaz/sshtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1256 | 186 | 2024-03-10T15:20:42Z | 2014-06-11T21:14:05Z | 11620 |
| 587 | */sshuttle.git* | .{0,1000}\/sshuttle\.git.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11621 |
| 588 | */sshuttle.py* | .{0,1000}\/sshuttle\.py.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11622 |
| 589 | */sshuttle/tarball* | .{0,1000}\/sshuttle\/tarball.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11623 |
| 590 | */sshuttle/zipball* | .{0,1000}\/sshuttle\/zipball.{0,1000} | greyware_tool_keyword | sshuttle | Transparent proxy server that works as a poor man's VPN. Forwards over ssh | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/sshuttle/sshuttle | 1 | 1 | #linux | N/A | 10 | 10 | 12200 | 754 | 2025-04-04T20:48:27Z | 2014-09-15T04:51:13Z | 11624 |
| 591 | */sshx-server/* | .{0,1000}\/sshx\-server\/.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 11626 |
| 592 | */stunnel-latest.tar.gz* | .{0,1000}\/stunnel\-latest\.tar\.gz.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11692 |
| 593 | */stunnel-latest-android.zip* | .{0,1000}\/stunnel\-latest\-android\.zip.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11693 |
| 594 | */stunnel-latest-win64-installer.exe* | .{0,1000}\/stunnel\-latest\-win64\-installer\.exe.{0,1000} | greyware_tool_keyword | stunnel | Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programs | T1573 - T1071 - T1090 | TA0010 - TA0011 - TA0003 | N/A | APT37 - APT38 - Kimsuky | C2 | https://www.stunnel.org/index.html | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 11694 |
| 595 | */suo5.git* | .{0,1000}\/suo5\.git.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11718 |
| 596 | */suo5/releases/* | .{0,1000}\/suo5\/releases\/.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11719 |
| 597 | */suo5-darwin-amd64* | .{0,1000}\/suo5\-darwin\-amd64.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11720 |
| 598 | */suo5-darwin-arm64* | .{0,1000}\/suo5\-darwin\-arm64.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11721 |
| 599 | */suo5-gui-darwin.app.zip* | .{0,1000}\/suo5\-gui\-darwin\.app\.zip.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11722 |
| 600 | */suo5-gui-linux* | .{0,1000}\/suo5\-gui\-linux.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11723 |
| 601 | */suo5-gui-windows.exe* | .{0,1000}\/suo5\-gui\-windows\.exe.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11724 |
| 602 | */suo5-linux-amd64* | .{0,1000}\/suo5\-linux\-amd64.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11725 |
| 603 | */suo5-linux-arm64* | .{0,1000}\/suo5\-linux\-arm64.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | #linux | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11726 |
| 604 | */suo5-windows-amd64.exe* | .{0,1000}\/suo5\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 11727 |
| 605 | */Supremo.exe* | .{0,1000}\/Supremo\.exe.{0,1000} | greyware_tool_keyword | Supremo | Supremo - Remote access software | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta | RMM | https://www.supremocontrol.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11736 |
| 606 | */syncthing.exe* | .{0,1000}\/syncthing\.exe.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | N/A | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 11754 |
| 607 | */syncthing/releases/latest* | .{0,1000}\/syncthing\/releases\/latest.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | N/A | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 11755 |
| 608 | */syncthing-linux-* | .{0,1000}\/syncthing\-linux\-.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | #linux | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 11756 |
| 609 | */tacticalagent-v*-*.exe* | .{0,1000}\/tacticalagent\-v.{0,1000}\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11779 |
| 610 | */tacticalagent-v*-linux-arm.exe* | .{0,1000}\/tacticalagent\-v.{0,1000}\-linux\-arm\.exe.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | #linux | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11780 |
| 611 | */tacticalagent-v*-windows-amd64.exe* | .{0,1000}\/tacticalagent\-v.{0,1000}\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11781 |
| 612 | */tacticalrmm.exe* | .{0,1000}\/tacticalrmm\.exe.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11782 |
| 613 | */tacticalrmm.git* | .{0,1000}\/tacticalrmm\.git.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11783 |
| 614 | */tacticalrmm/master/install.sh* | .{0,1000}\/tacticalrmm\/master\/install\.sh.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11784 |
| 615 | */tacticalrmm/releases/latest* | .{0,1000}\/tacticalrmm\/releases\/latest.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11785 |
| 616 | */tacticalrmm-web.git* | .{0,1000}\/tacticalrmm\-web\.git.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 11786 |
| 617 | */tailscale.exe* | .{0,1000}\/tailscale\.exe.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11789 |
| 618 | */tailscale/client/* | .{0,1000}\/tailscale\/client\/.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11791 |
| 619 | */tailscale:unstable* | .{0,1000}\/tailscale\:unstable.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11793 |
| 620 | */tailscale_*_*.deb* | .{0,1000}\/tailscale_.{0,1000}_.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11794 |
| 621 | */tailscale_*_*.tgz* | .{0,1000}\/tailscale_.{0,1000}_.{0,1000}\.tgz.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11795 |
| 622 | */tailscaled.defaults* | .{0,1000}\/tailscaled\.defaults.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11796 |
| 623 | */tailscaled.go* | .{0,1000}\/tailscaled\.go.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11797 |
| 624 | */tailscaled.sock* | .{0,1000}\/tailscaled\.sock.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11798 |
| 625 | */tailscale-setup-*-*.msi* | .{0,1000}\/tailscale\-setup\-.{0,1000}\-.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11799 |
| 626 | */tailscale-setup-*.exe* | .{0,1000}\/tailscale\-setup\-.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11800 |
| 627 | */TDSSKiller.exe* | .{0,1000}\/TDSSKiller\.exe.{0,1000} | greyware_tool_keyword | TDSKiller | TDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Avaddon | Defense Evasion | https://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 11828 |
| 628 | */tdsskiller.zip* | .{0,1000}\/tdsskiller\.zip.{0,1000} | greyware_tool_keyword | TDSKiller | TDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Avaddon | Defense Evasion | https://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 11829 |
| 629 | */test_tailscale.sh* | .{0,1000}\/test_tailscale\.sh.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 11865 |
| 630 | */tightvnc-*.msi* | .{0,1000}\/tightvnc\-.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11919 |
| 631 | */tkc_agent_dre.deb* | .{0,1000}\/tkc_agent_dre\.deb.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11931 |
| 632 | */tmate-ssh-server.* | .{0,1000}\/tmate\-ssh\-server\..{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate-ssh-server | 1 | 1 | #linux | N/A | 10 | 10 | 642 | 148 | 2024-06-21T11:52:24Z | 2013-06-09T23:58:55Z | 11936 |
| 633 | */tmate-ssh-server.git* | .{0,1000}\/tmate\-ssh\-server\.git.{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate-ssh-server | 1 | 1 | #linux | N/A | 10 | 10 | 642 | 148 | 2024-06-21T11:52:24Z | 2013-06-09T23:58:55Z | 11937 |
| 634 | */tmate-ssh-server/releases/* | .{0,1000}\/tmate\-ssh\-server\/releases\/.{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate-ssh-server | 1 | 1 | #linux | N/A | 10 | 10 | 642 | 148 | 2024-06-21T11:52:24Z | 2013-06-09T23:58:55Z | 11938 |
| 635 | */tunnel.nosocket.php* | .{0,1000}\/tunnel\.nosocket\.php.{0,1000} | greyware_tool_keyword | Neo-reGeorg | Neo-reGeorg is a project that seeks to aggressively refactor reGeorg | T1090 - T1095 - T1572 | TA0003 - TA0011 - TA0005 - TA0010 | N/A | IRIDIUM | Data Exfiltration | https://github.com/L-codes/Neo-reGeorg | 1 | 1 | N/A | N/A | 10 | 10 | 3049 | 455 | 2025-02-18T07:26:54Z | 2019-07-08T14:25:42Z | 12129 |
| 636 | */tunneld.service* | .{0,1000}\/tunneld\.service.{0,1000} | greyware_tool_keyword | go-http-tunnel | Fast and secure tunnels over HTTP/2 | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/mmatczuk/go-http-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 3261 | 308 | 2025-04-16T21:49:57Z | 2016-10-12T12:59:38Z | 12135 |
| 637 | */tunneller.git* | .{0,1000}\/tunneller\.git.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12136 |
| 638 | */tunneller/releases/* | .{0,1000}\/tunneller\/releases\/.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12137 |
| 639 | */tunneller-darwin-amd64* | .{0,1000}\/tunneller\-darwin\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12138 |
| 640 | */tunneller-darwin-amd64* | .{0,1000}\/tunneller\-darwin\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12139 |
| 641 | */tunneller-darwin-amd64* | .{0,1000}\/tunneller\-darwin\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12140 |
| 642 | */tunneller-darwin-amd64* | .{0,1000}\/tunneller\-darwin\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12141 |
| 643 | */tunneller-darwin-i386* | .{0,1000}\/tunneller\-darwin\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12142 |
| 644 | */tunneller-darwin-i386* | .{0,1000}\/tunneller\-darwin\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12143 |
| 645 | */tunneller-darwin-i386* | .{0,1000}\/tunneller\-darwin\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12144 |
| 646 | */tunneller-darwin-i386* | .{0,1000}\/tunneller\-darwin\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12145 |
| 647 | */tunneller-freebsd-amd64* | .{0,1000}\/tunneller\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12146 |
| 648 | */tunneller-freebsd-amd64* | .{0,1000}\/tunneller\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12147 |
| 649 | */tunneller-freebsd-amd64* | .{0,1000}\/tunneller\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12148 |
| 650 | */tunneller-freebsd-amd64* | .{0,1000}\/tunneller\-freebsd\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12149 |
| 651 | */tunneller-freebsd-i386* | .{0,1000}\/tunneller\-freebsd\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12150 |
| 652 | */tunneller-freebsd-i386* | .{0,1000}\/tunneller\-freebsd\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12151 |
| 653 | */tunneller-freebsd-i386* | .{0,1000}\/tunneller\-freebsd\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12152 |
| 654 | */tunneller-freebsd-i386* | .{0,1000}\/tunneller\-freebsd\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | N/A | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12153 |
| 655 | */tunneller-linux-amd64* | .{0,1000}\/tunneller\-linux\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12154 |
| 656 | */tunneller-linux-amd64* | .{0,1000}\/tunneller\-linux\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12155 |
| 657 | */tunneller-linux-amd64* | .{0,1000}\/tunneller\-linux\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12156 |
| 658 | */tunneller-linux-amd64* | .{0,1000}\/tunneller\-linux\-amd64.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12157 |
| 659 | */tunneller-linux-i386* | .{0,1000}\/tunneller\-linux\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12158 |
| 660 | */tunneller-linux-i386* | .{0,1000}\/tunneller\-linux\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12159 |
| 661 | */tunneller-linux-i386* | .{0,1000}\/tunneller\-linux\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12160 |
| 662 | */tunneller-linux-i386* | .{0,1000}\/tunneller\-linux\-i386.{0,1000} | greyware_tool_keyword | tunneller | Tunneller allows you to expose services which are running on localhost or on your local network to the public internet. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/skx/tunneller | 1 | 1 | #linux | N/A | 10 | 10 | 487 | 41 | 2024-08-13T07:36:22Z | 2019-04-21T11:05:11Z | 12161 |
| 663 | */tunnelmole-client.git* | .{0,1000}\/tunnelmole\-client\.git.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 12164 |
| 664 | */tunnelmole-service* | .{0,1000}\/tunnelmole\-service.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 12165 |
| 665 | */tunnelmole-service.git* | .{0,1000}\/tunnelmole\-service\.git.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 12166 |
| 666 | */tunnelto.git* | .{0,1000}\/tunnelto\.git.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 12168 |
| 667 | */tunnelto/releases/latest* | .{0,1000}\/tunnelto\/releases\/latest.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 12169 |
| 668 | */tunnelto_server* | .{0,1000}\/tunnelto_server.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 12170 |
| 669 | */tunnelto_server/* | .{0,1000}\/tunnelto_server\/.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 12171 |
| 670 | */tunwg.exe* | .{0,1000}\/tunwg\.exe.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 12175 |
| 671 | */tunwg.git* | .{0,1000}\/tunwg\.git.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 12176 |
| 672 | */tunwg@latest* | .{0,1000}\/tunwg\@latest.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 12177 |
| 673 | */tunwg-arm64.exe* | .{0,1000}\/tunwg\-arm64\.exe.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 12178 |
| 674 | */unlocker-setup.exe* | .{0,1000}\/unlocker\-setup\.exe.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 1 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 12231 |
| 675 | */updog-*.tar.gz* | .{0,1000}\/updog\-.{0,1000}\.tar\.gz.{0,1000} | greyware_tool_keyword | updog | Updog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth. | T1567 - T1074.001 - T1020 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://github.com/sc0tfree/updog | 1 | 1 | N/A | N/A | 9 | 10 | 3052 | 314 | 2024-03-13T15:52:39Z | 2020-02-18T15:29:21Z | 12243 |
| 676 | */updog.git* | .{0,1000}\/updog\.git.{0,1000} | greyware_tool_keyword | updog | Updog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth. | T1567 - T1074.001 - T1020 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://github.com/sc0tfree/updog | 1 | 1 | N/A | N/A | 9 | 10 | 3052 | 314 | 2024-03-13T15:52:39Z | 2020-02-18T15:29:21Z | 12244 |
| 677 | */updog/archive/updog-* | .{0,1000}\/updog\/archive\/updog\-.{0,1000} | greyware_tool_keyword | updog | Updog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth. | T1567 - T1074.001 - T1020 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://github.com/sc0tfree/updog | 1 | 1 | N/A | N/A | 9 | 10 | 3052 | 314 | 2024-03-13T15:52:39Z | 2020-02-18T15:29:21Z | 12245 |
| 678 | */uvs_v415eng.zip* | .{0,1000}\/uvs_v415eng\.zip.{0,1000} | greyware_tool_keyword | Universal Virus Sniffer | Universal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | Phobos | Defense Evasion | https://www.majorgeeks.com/files/details/universal_virus_sniffer.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 12390 |
| 679 | */vbs2exe.exe* | .{0,1000}\/vbs2exe\.exe.{0,1000} | greyware_tool_keyword | redpill | Assist reverse tcp shells in post-exploration tasks | T1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003 | TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011 | N/A | N/A | Exploitation tool | https://github.com/r00t-3xp10it/redpill | 1 | 1 | N/A | N/A | 10 | 3 | 218 | 52 | 2024-03-19T15:03:16Z | 2021-02-20T23:59:07Z | 12424 |
| 680 | */viewerhostkeypopup.exe* | .{0,1000}\/viewerhostkeypopup\.exe.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC RMM tool - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.remotedesktop.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12446 |
| 681 | */VncSharp.exe* | .{0,1000}\/VncSharp\.exe.{0,1000} | greyware_tool_keyword | VncSharp | VncSharp is a GPL implementation of the VNC Remote Framebuffer (RFB) Protocol for the .NET Framework | T1021.001 - T1219 - T1071.001 | TA0007 - TA0008 | Carbanak | FIN7 - Carbanak | Lateral Movement | https://github.com/humphd/VncSharp | 1 | 1 | N/A | N/A | 8 | 3 | 246 | 179 | 2019-02-18T16:04:27Z | 2012-03-05T15:23:41Z | 12471 |
| 682 | */VncSharp.git* | .{0,1000}\/VncSharp\.git.{0,1000} | greyware_tool_keyword | VncSharp | VncSharp is a GPL implementation of the VNC Remote Framebuffer (RFB) Protocol for the .NET Framework | T1021.001 - T1219 - T1071.001 | TA0007 - TA0008 | Carbanak | FIN7 - Carbanak | Lateral Movement | https://github.com/humphd/VncSharp | 1 | 1 | N/A | N/A | 8 | 3 | 246 | 179 | 2019-02-18T16:04:27Z | 2012-03-05T15:23:41Z | 12472 |
| 683 | */VPDAgent.exe* | .{0,1000}\/VPDAgent\.exe.{0,1000} | greyware_tool_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12482 |
| 684 | */VSAX_x64.msi* | .{0,1000}\/VSAX_x64\.msi.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12483 |
| 685 | */vsxrc-clip.exe* | .{0,1000}\/vsxrc\-clip\.exe.{0,1000} | greyware_tool_keyword | kaseya VSA | Kaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.kaseya.com/products/vsa/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12486 |
| 686 | */webhook.site.git* | .{0,1000}\/webhook\.site\.git.{0,1000} | greyware_tool_keyword | webhook.site | test HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmation | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/webhooksite/webhook.site | 1 | 1 | N/A | N/A | 10 | 10 | 5806 | 457 | 2025-04-04T10:42:59Z | 2016-03-21T08:45:42Z | 12535 |
| 687 | */webvulnscan1*.exe* | .{0,1000}\/webvulnscan1.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Acunetix Web Vulnerability Scanner | Vulnerability Scanner abused by threat actors | T1190 - T1046 - T1210 - T1213 | TA0001 - TA0008 - TA0009 | N/A | Clever Kitten - EMBER BEAR | Vulnerability Scanner | https://www.acunetix.com/vulnerability-scanner/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 12554 |
| 688 | */webvulnscan2*.exe* | .{0,1000}\/webvulnscan2.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Acunetix Web Vulnerability Scanner | Vulnerability Scanner abused by threat actors | T1190 - T1046 - T1210 - T1213 | TA0001 - TA0008 - TA0009 | N/A | Clever Kitten - EMBER BEAR | Vulnerability Scanner | https://www.acunetix.com/vulnerability-scanner/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 12555 |
| 689 | */webvulnscan3*.exe* | .{0,1000}\/webvulnscan3.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Acunetix Web Vulnerability Scanner | Vulnerability Scanner abused by threat actors | T1190 - T1046 - T1210 - T1213 | TA0001 - TA0008 - TA0009 | N/A | Clever Kitten - EMBER BEAR | Vulnerability Scanner | https://www.acunetix.com/vulnerability-scanner/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 12556 |
| 690 | */Win7Taskbar.dll* | .{0,1000}\/Win7Taskbar\.dll.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12585 |
| 691 | */Wireguard.zip* | .{0,1000}\/Wireguard\.zip.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12654 |
| 692 | */wireguard-amd64-*.msi* | .{0,1000}\/wireguard\-amd64\-.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12655 |
| 693 | */wireguard-installer.exe* | .{0,1000}\/wireguard\-installer\.exe.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12656 |
| 694 | */wireguard-installer.rar* | .{0,1000}\/wireguard\-installer\.rar.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12657 |
| 695 | */wireproxy.conf* | .{0,1000}\/wireproxy\.conf.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12659 |
| 696 | */wireproxy.git* | .{0,1000}\/wireproxy\.git.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | N/A | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12660 |
| 697 | */wireproxy.service* | .{0,1000}\/wireproxy\.service.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12661 |
| 698 | */wireproxy/releases/* | .{0,1000}\/wireproxy\/releases\/.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | N/A | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12662 |
| 699 | */wireproxy_darwin* | .{0,1000}\/wireproxy_darwin.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12663 |
| 700 | */wireproxy_linux_* | .{0,1000}\/wireproxy_linux_.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | #linux | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12664 |
| 701 | */wireproxy_windows* | .{0,1000}\/wireproxy_windows.{0,1000} | greyware_tool_keyword | wireproxy | Wireguard client that exposes itself as a socks5 proxy | T1572 - T1090 - T1071.004 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/pufferffish/wireproxy | 1 | 1 | N/A | N/A | 10 | 10 | 4893 | 299 | 2025-04-16T22:58:51Z | 2022-03-11T12:32:10Z | 12665 |
| 702 | */wiretap.Dockerfile* | .{0,1000}\/wiretap\.Dockerfile.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12672 |
| 703 | */wiretap.exe* | .{0,1000}\/wiretap\.exe.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12673 |
| 704 | */wiretap.git* | .{0,1000}\/wiretap\.git.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12674 |
| 705 | */wiretap/releases/download/* | .{0,1000}\/wiretap\/releases\/download\/.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12676 |
| 706 | */wiretap_*_linux_386.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_linux_386\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | #linux | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12677 |
| 707 | */wiretap_*_linux_amd64.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_linux_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | #linux | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12678 |
| 708 | */wiretap_*_linux_arm64.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_linux_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | #linux | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12679 |
| 709 | */wiretap_*_linux_armv6.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_linux_armv6\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | #linux | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12680 |
| 710 | */wiretap_*_windows_386.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_windows_386\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12681 |
| 711 | */wiretap_*_windows_amd64.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_windows_amd64\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12682 |
| 712 | */wiretap_*_windows_arm64.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_windows_arm64\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12683 |
| 713 | */wiretap_*_windows_armv6.tar.gz* | .{0,1000}\/wiretap_.{0,1000}_windows_armv6\.tar\.gz.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 12684 |
| 714 | */x86_64-pc-windows-msvc/release/gt.exe* | .{0,1000}\/x86_64\-pc\-windows\-msvc\/release\/gt\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 12757 |
| 715 | */x86_64-pc-windows-msvc/release/gt.exe* | .{0,1000}\/x86_64\-pc\-windows\-msvc\/release\/gt\.exe.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 12758 |
| 716 | */xmrig-*-gcc-win64.zip* | .{0,1000}\/xmrig\-.{0,1000}\-gcc\-win64\.zip.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 1 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 12772 |
| 717 | */xmrig.exe* | .{0,1000}\/xmrig\.exe.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 1 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 12773 |
| 718 | */xmrig.git* | .{0,1000}\/xmrig\.git.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 1 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 12774 |
| 719 | */yak_darwin_amd64.zip* | .{0,1000}\/yak_darwin_amd64\.zip.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | #linux | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 12796 |
| 720 | */yak_linux_amd64.zip* | .{0,1000}\/yak_linux_amd64\.zip.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | #linux | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 12797 |
| 721 | */yak_windows_amd64.zip* | .{0,1000}\/yak_windows_amd64\.zip.{0,1000} | greyware_tool_keyword | yakit | security platform with fuzzers - webshell and MITM (chinese burp) | T1557 - T1557.003 - T1569.002 | TA0001 - TA0040 | N/A | N/A | Sniffing & Spoofing | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 7 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 12798 |
| 722 | */ZA_Connect.exe* | .{0,1000}\/ZA_Connect\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12802 |
| 723 | */ZAAudioClient.exe* | .{0,1000}\/ZAAudioClient\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12803 |
| 724 | */ZAFileTransfer.exe* | .{0,1000}\/ZAFileTransfer\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12804 |
| 725 | */ZAService.exe* | .{0,1000}\/ZAService\.exe.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12805 |
| 726 | */zrok.exe* | .{0,1000}\/zrok\.exe.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 12819 |
| 727 | */zrok.git* | .{0,1000}\/zrok\.git.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 12820 |
| 728 | */zrok.zip* | .{0,1000}\/zrok\.zip.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 12821 |
| 729 | */zrok-amd64_darwin_amd64* | .{0,1000}\/zrok\-amd64_darwin_amd64.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 12822 |
| 730 | */zrok-arm64_darwin_arm64* | .{0,1000}\/zrok\-arm64_darwin_arm64.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | #linux | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 12823 |
| 731 | *:8040/SetupWizard.aspx* | .{0,1000}\:8040\/SetupWizard\.aspx.{0,1000} | greyware_tool_keyword | ScreenConnect | ConnectWise Control formerly known as Screenconnect is a remote desktop software application. | T1021.001 - T1133 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater | RMM | https://screenconnect.connectwise.com/download | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12861 |
| 732 | *:8070/tomcat/code/suo5.jsp* | .{0,1000}\:8070\/tomcat\/code\/suo5\.jsp.{0,1000} | greyware_tool_keyword | suo5 | http proxy tunneling tool | T1071 - T1073 - T1075 - T1105 - T1571 | TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/zema1/suo5 | 1 | 1 | N/A | N/A | 10 | 10 | 2332 | 217 | 2025-04-14T03:33:51Z | 2022-11-22T11:45:26Z | 12863 |
| 733 | *:9001/proxy/mdmserver1/account* | .{0,1000}\:9001\/proxy\/mdmserver1\/account.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 12866 |
| 734 | *@email.webhook.site* | .{0,1000}\@email\.webhook\.site.{0,1000} | greyware_tool_keyword | webhook.site | test HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmation | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/webhooksite/webhook.site | 1 | 1 | N/A | N/A | 10 | 10 | 5806 | 457 | 2025-04-04T10:42:59Z | 2016-03-21T08:45:42Z | 12877 |
| 735 | *159.69.126.209* | .{0,1000}159\.69\.126\.209.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 22267 |
| 736 | *3proxy/3proxy* | .{0,1000}3proxy\/3proxy.{0,1000} | greyware_tool_keyword | 3proxy | 3proxy - tiny free proxy server | T1090 - T1583 - T1001 - T1132 | TA0040 - TA0001 - TA0005 - TA0006 | N/A | Lazarus Group | Defense Evasion | https://github.com/3proxy/3proxy | 1 | 1 | N/A | N/A | 8 | 10 | 4212 | 817 | 2025-04-16T18:29:51Z | 2014-04-08T08:59:11Z | 25293 |
| 737 | *-443.devtunnels.ms* | .{0,1000}\-443\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 25624 |
| 738 | *4shared.com/*upload* | .{0,1000}4shared\.com\/.{0,1000}upload.{0,1000} | greyware_tool_keyword | 4shared.com | Uploading on 4shared.com | T1105 - T1567 - T1071 | TA0010 | N/A | Turla | Data Exfiltration | 4shared.com | 1 | 1 | #filehostingservice | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 26469 |
| 739 | *5ety7tpkim5me6eszuwcje7bmy25pbtrjtue7zkqqgziljwqy3rrikqd.onion* | .{0,1000}5ety7tpkim5me6eszuwcje7bmy25pbtrjtue7zkqqgziljwqy3rrikqd\.onion.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 27610 |
| 740 | *625ae9460120.ngrok.io* | .{0,1000}625ae9460120\.ngrok\.io.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 27826 |
| 741 | *7k3j6g3h67l23j345wennkoc4a2223rhjkba22o77ihzdj3achwa.remote.moe* | .{0,1000}7k3j6g3h67l23j345wennkoc4a2223rhjkba22o77ihzdj3achwa\.remote\.moe.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 29864 |
| 742 | *a.aomeisoftware.com* | .{0,1000}a\.aomeisoftware\.com.{0,1000} | greyware_tool_keyword | anyviewer | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyviewer.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 32143 |
| 743 | *AADInternals.exe* | .{0,1000}AADInternals\.exe.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 32935 |
| 744 | *AADInternals.pdb* | .{0,1000}AADInternals\.pdb.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 32936 |
| 745 | *AADInternals.psd1* | .{0,1000}AADInternals\.psd1.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 32937 |
| 746 | *AADInternals.psm1* | .{0,1000}AADInternals\.psm1.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 32938 |
| 747 | *Ab4y98/VerySimpleAnyDeskBackdoor* | .{0,1000}Ab4y98\/VerySimpleAnyDeskBackdoor.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps1 | 1 | 1 | N/A | simple backdoor with anydesk | 10 | 1 | 1 | 0 | 2025-04-17T19:04:37Z | 2023-12-05T22:08:51Z | 32983 |
| 748 | *ACLScanner.exe* | .{0,1000}ACLScanner\.exe.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commands | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/vletoux/pingcastle | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33142 |
| 749 | *acontrol.atera.com* | .{0,1000}acontrol\.atera\.com.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33147 |
| 750 | *action1_agent.exe* | .{0,1000}action1_agent\.exe.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33161 |
| 751 | *action1_remote.exe* | .{0,1000}action1_remote\.exe.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33163 |
| 752 | *action1_update.exe* | .{0,1000}action1_update\.exe.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33164 |
| 753 | *activate.netsupportsoftware.com* | .{0,1000}activate\.netsupportsoftware\.com.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33166 |
| 754 | *adexplorer.exe* | .{0,1000}adexplorer\.exe.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 1 | N/A | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 33396 |
| 755 | *adexplorer.zip* | .{0,1000}adexplorer\.zip.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 1 | N/A | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 33398 |
| 756 | *adexplorer64.exe* | .{0,1000}adexplorer64\.exe.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 1 | N/A | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 33399 |
| 757 | *adexplorer64a.exe* | .{0,1000}adexplorer64a\.exe.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 1 | N/A | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 33400 |
| 758 | *adfind.bat* | .{0,1000}adfind\.bat.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 33417 |
| 759 | *adfind.exe* | .{0,1000}adfind\.exe.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 33427 |
| 760 | *adiskreader.disks.raw* | .{0,1000}adiskreader\.disks\.raw.{0,1000} | greyware_tool_keyword | adiskreader | Async Python library to parse local and remote disk images | T1020 - T1048 - T1074 - T1560.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://github.com/skelsec/adiskreader | 1 | 1 | N/A | N/A | 4 | 1 | 76 | 7 | 2025-03-15T19:48:39Z | 2023-12-18T11:54:31Z | 33447 |
| 761 | *adiskreader.disks.vhdx* | .{0,1000}adiskreader\.disks\.vhdx.{0,1000} | greyware_tool_keyword | adiskreader | Async Python library to parse local and remote disk images | T1020 - T1048 - T1074 - T1560.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://github.com/skelsec/adiskreader | 1 | 1 | N/A | N/A | 4 | 1 | 76 | 7 | 2025-03-15T19:48:39Z | 2023-12-18T11:54:31Z | 33448 |
| 762 | *admin.*.swi-dre.com* | .{0,1000}admin\..{0,1000}\.swi\-dre\.com.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33456 |
| 763 | *ADRecon.ps1* | .{0,1000}ADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | N/A | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 33475 |
| 764 | *adrecon/ADRecon* | .{0,1000}adrecon\/ADRecon.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 33476 |
| 765 | *ADRecon-master.zip* | .{0,1000}ADRecon\-master\.zip.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 33478 |
| 766 | *Advanced Monitoring Agent HTTP Retriever 1.1* | .{0,1000}Advanced\sMonitoring\sAgent\sHTTP\sRetriever\s1\.1.{0,1000} | greyware_tool_keyword | Nsight RMM | Nsight RMM usage | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Scattered Spider* | RMM | https://www.n-able.com/products/n-sight-rmm | 1 | 1 | #useragent | user-agent | 10 | 10 | N/A | N/A | N/A | N/A | 33497 |
| 767 | *Advanced_IP_Scanner*.exe* | .{0,1000}Advanced_IP_Scanner.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 33500 |
| 768 | *advanced_ip_scanner_console.exe* | .{0,1000}advanced_ip_scanner_console\.exe.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 33501 |
| 769 | *advanced_port_scanner.exe* | .{0,1000}advanced_port_scanner\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 33502 |
| 770 | *advanced_port_scanner_console.exe* | .{0,1000}advanced_port_scanner_console\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 33503 |
| 771 | *AeroAdmin_2.exe* | .{0,1000}AeroAdmin_2\.exe.{0,1000} | greyware_tool_keyword | aeroadmin | RMM software - full remote control / file transfer | T1021.001 - T1048.003 | TA0008 - TA0011 - TA0009 - TA0010 | N/A | N/A | RMM | https://ulm.aeroadmin.com/AeroAdmin.exe | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33600 |
| 772 | *agent.fleetdeck.io/*?win* | .{0,1000}agent\.fleetdeck\.io\/.{0,1000}\?win.{0,1000} | greyware_tool_keyword | fleetdeck | FleetDeck is a Remote Desktop & Virtual Terminal solution tailored for techs to manage large fleets of computers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://fleetdeck.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33681 |
| 773 | *agent01.xeox.com* | .{0,1000}agent01\.xeox\.com.{0,1000} | greyware_tool_keyword | xeox | Easily access and manage Windows devices remotely within XEOX - RMM abused by threat actors | T1021 - T1078 - T1219 - T1105 - T1046 | TA0011 - TA0010 - TA0003 - TA0005 | N/A | Dispossessor | RMM | https://xeox.com/remote-access/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33709 |
| 774 | *agent-api.atera.com* | .{0,1000}agent\-api\.atera\.com.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33710 |
| 775 | *agents.level.io* | .{0,1000}agents\.level\.io.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33714 |
| 776 | *agrinman/tap/tunnelto* | .{0,1000}agrinman\/tap\/tunnelto.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 33728 |
| 777 | *agrinman/tunnelto* | .{0,1000}agrinman\/tunnelto.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 33729 |
| 778 | *alt.meshcentral.com* | .{0,1000}alt\.meshcentral\.com.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshCentral | 1 | 1 | N/A | N/A | 10 | 10 | 4874 | 640 | 2025-04-21T16:50:06Z | 2017-08-28T16:21:11Z | 33821 |
| 779 | *amalshaji/portr* | .{0,1000}amalshaji\/portr.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 33828 |
| 780 | *amalshaji/taps/portr* | .{0,1000}amalshaji\/taps\/portr.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 33829 |
| 781 | *amidaware/tacticalrmm* | .{0,1000}amidaware\/tacticalrmm.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 33835 |
| 782 | *anderspitman/SirTunnel* | .{0,1000}anderspitman\/SirTunnel.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 33869 |
| 783 | *angryip/ipscan* | .{0,1000}angryip\/ipscan.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 33884 |
| 784 | *AnydeskBackdoor.ps1* | .{0,1000}AnydeskBackdoor\.ps1.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps1 | 1 | 1 | N/A | simple backdoor with anydesk | 10 | 1 | 1 | 0 | 2025-04-17T19:04:37Z | 2023-12-05T22:08:51Z | 33914 |
| 785 | *AnyplaceControlInstall.exe* | .{0,1000}AnyplaceControlInstall\.exe.{0,1000} | greyware_tool_keyword | AnyplaceControl | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyplace-control[.]com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33915 |
| 786 | *api.btunnel.in* | .{0,1000}api\.btunnel\.in.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 33938 |
| 787 | *api.cyberghostvpn.com* | .{0,1000}api\.cyberghostvpn\.com.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 33939 |
| 788 | *api.dataplicity.com* | .{0,1000}api\.dataplicity\.com.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 33940 |
| 789 | *api.freefilesync.org* | .{0,1000}api\.freefilesync\.org.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 33941 |
| 790 | *api.gofile.io/getServer* | .{0,1000}api\.gofile\.io\/getServer.{0,1000} | greyware_tool_keyword | gofile.io | legitimate service abused by lots of stealer to exfiltrate data | T1567.002 | TA0010 | N/A | Hive - Royal - LockBit - Vice Society - BlackSuit - Conti | Data Exfiltration | https://gofile.io | 1 | 1 | #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 33942 |
| 791 | *api.localxpose.io* | .{0,1000}api\.localxpose\.io.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 33943 |
| 792 | *api.remot3.it* | .{0,1000}api\.remot3\.it.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 33944 |
| 793 | *api.surfshark.com/* | .{0,1000}api\.surfshark\.com\/.{0,1000} | greyware_tool_keyword | surfshark VPN | usage of surfsharkVPN client | T1090 - T1573 | TA0005 - TA010 | N/A | N/A | Defense Evasion | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 33945 | |
| 794 | *api.telegram.org* | .{0,1000}api\.telegram\.org.{0,1000} | greyware_tool_keyword | telegram | telegram API usage -given the increasing adoption of Telegram by malware for command and control (C2) operations. it's essential to monitor and restrict its usage within corporate networks and on company devices | T1071.004 - T1102 - T1047 | TA0011 - TA0002 - TA0005 | N/A | Gamaredon | C2 | api.telegram.org | 0 | 1 | N/A | High False positive Risk ! | 1 | 9 | N/A | N/A | N/A | N/A | 33946 |
| 795 | *api/v1/fleet/sso/callback* | .{0,1000}api\/v1\/fleet\/sso\/callback.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 33948 |
| 796 | *api01.remot3.it* | .{0,1000}api01\.remot3\.it.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 33952 |
| 797 | *api-telemetry.servers.getgo.com* | .{0,1000}api\-telemetry\.servers\.getgo\.com.{0,1000} | greyware_tool_keyword | GoToMyPC | GoToMyPC is remote desktop software that allows users to access computers remotely using a web browser | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | N/A | RMM | https://www.gotomypc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33957 |
| 798 | *asapi.aweray.net* | .{0,1000}asapi\.aweray\.net.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34112 |
| 799 | *asse.rel.tunnels.api.visualstudio.com* | .{0,1000}asse\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 34140 |
| 800 | *assist.zoho.com* | .{0,1000}assist\.zoho\.com.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34148 |
| 801 | *as-tk.aweray.com* | .{0,1000}as\-tk\.aweray\.com.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34161 |
| 802 | *as-tk.aweray.com/track* | .{0,1000}as\-tk\.aweray\.com\/track.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34162 |
| 803 | *ataylor32/duckdns-powershell* | .{0,1000}ataylor32\/duckdns\-powershell.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 34171 |
| 804 | *atera_del.bat* | .{0,1000}atera_del\.bat.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34172 |
| 805 | *atera_del2.bat* | .{0,1000}atera_del2\.bat.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34173 |
| 806 | *auc1.rel.tunnels.api.visualstudio.com* | .{0,1000}auc1\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 34250 |
| 807 | *aue.rel.tunnels.api.visualstudio.com* | .{0,1000}aue\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 34254 |
| 808 | *aue.rel.tunnels.api.visualstudio.com* | .{0,1000}aue\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34255 |
| 809 | *aue-data.rel.tunnels.api.visualstudio.com* | .{0,1000}aue\-data\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34256 |
| 810 | *auth11.aeroadmin.com* | .{0,1000}auth11\.aeroadmin\.com.{0,1000} | greyware_tool_keyword | aeroadmin | RMM software - full remote control / file transfer | T1021.001 - T1048.003 | TA0008 - TA0011 - TA0009 - TA0010 | N/A | N/A | RMM | https://ulm.aeroadmin.com/AeroAdmin.exe | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34262 |
| 811 | *AutoHotkey/Ahk2Exe* | .{0,1000}AutoHotkey\/Ahk2Exe.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 34297 |
| 812 | *AutoHotkey/AutoHotkey* | .{0,1000}AutoHotkey\/AutoHotkey.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 34298 |
| 813 | *AutoHotkeySC.bin* | .{0,1000}AutoHotkeySC\.bin.{0,1000} | greyware_tool_keyword | AutoHotkey | AutoHotkey - macro-creation and automation-oriented scripting utility for Windows | T1056.001 - T1027 - T1059.001 - T1140 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/AutoHotkey | 1 | 1 | N/A | abused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected | 6 | 10 | 10188 | 1001 | 2025-03-29T02:12:26Z | 2009-11-25T11:08:21Z | 34299 |
| 814 | *auvik.agent.exe* | .{0,1000}auvik\.agent\.exe.{0,1000} | greyware_tool_keyword | auvik | cloud-based network management software | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.auvik.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34326 |
| 815 | *AuvikService.exe* | .{0,1000}AuvikService\.exe.{0,1000} | greyware_tool_keyword | auvik | cloud-based network management software | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.auvik.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34327 |
| 816 | *Aweray_Remote.exe* | .{0,1000}Aweray_Remote\.exe.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34370 |
| 817 | *awerayimg.com* | .{0,1000}awerayimg\.com.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 34371 |
| 818 | *AzureADConnectAuthenticationAgentService.exe* | .{0,1000}AzureADConnectAuthenticationAgentService\.exe.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 34400 |
| 819 | *b4ldr/nse-scripts* | .{0,1000}b4ldr\/nse\-scripts.{0,1000} | greyware_tool_keyword | nmap | Install and update external NSE script for nmap | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Vulnerability Scanner | https://github.com/shadawck/nse-install | 1 | 1 | N/A | N/A | 7 | 1 | 7 | 1 | 2020-08-28T11:27:08Z | 2020-08-24T16:55:55Z | 34746 |
| 820 | *berstend/hypertunnel* | .{0,1000}berstend\/hypertunnel.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 35818 |
| 821 | *beyondcode/expose* | .{0,1000}beyondcode\/expose.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 35839 |
| 822 | *bfleegjcoffelppfmadimianphbcdjkb* | .{0,1000}bfleegjcoffelppfmadimianphbcdjkb.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | #browser_extensionid | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 35900 |
| 823 | *bit.ly/2alyerp* | .{0,1000}bit\.ly\/2alyerp.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 35962 |
| 824 | *bluekeepscanner.exe* | .{0,1000}bluekeepscanner\.exe.{0,1000} | greyware_tool_keyword | pingcastle | active directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commands | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/vletoux/pingcastle | 1 | 1 | N/A | N/A | 10 | N/A | 36096 | ||||
| 825 | *bomgar-rdp.exe* | .{0,1000}bomgar\-rdp\.exe.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 36187 |
| 826 | *boot.net.anydesk.com* | .{0,1000}boot\.net\.anydesk\.com.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - Dispossessor | RMM | https://anydesk.com/ | 1 | 1 | N/A | risk of false positives - compliance detection | 10 | 10 | N/A | N/A | N/A | N/A | 36191 |
| 827 | *bored-tunnel-client_Windows_x86_64.* | .{0,1000}bored\-tunnel\-client_Windows_x86_64\..{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 36197 |
| 828 | *boringproxy/boringproxy* | .{0,1000}boringproxy\/boringproxy.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 36199 |
| 829 | *boringproxy_db.json* | .{0,1000}boringproxy_db\.json.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 36200 |
| 830 | *brimstone/rsocks* | .{0,1000}brimstone\/rsocks.{0,1000} | greyware_tool_keyword | rsocks | reverse socks5 client & server | T1090 - T1571 - T1071 - T1095 | TA0011 - TA0001 - TA0008 | N/A | Scattered Spider* | C2 | https://github.com/brimstone/rsocks | 1 | 1 | N/A | N/A | 10 | 10 | 85 | 29 | 2020-01-09T20:45:32Z | 2018-01-05T03:09:07Z | 36233 |
| 831 | *browser.lol/create* | .{0,1000}browser\.lol\/create.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 36238 |
| 832 | *brs.rel.tunnels.api.visualstudio.com* | .{0,1000}brs\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 36270 |
| 833 | *builds.level.io* | .{0,1000}builds\.level\.io.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 36389 |
| 834 | *c3pool_miner.bat* | .{0,1000}c3pool_miner\.bat.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 36968 |
| 835 | *c3pool_miner.service* | .{0,1000}c3pool_miner\.service.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 36969 |
| 836 | *c3pool_miner.sh* | .{0,1000}c3pool_miner\.sh.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 36970 |
| 837 | *cdn*.boxcdn.net* | .{0,1000}cdn.{0,1000}\.boxcdn\.net.{0,1000} | greyware_tool_keyword | Box | Attackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackers | T1567.002 - T1071.001 - T1036 - T1048.002 | TA0005 - TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://app.box.com/ | 1 | 1 | #dnsquery | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 37922 |
| 838 | *chat.us.n-able.com* | .{0,1000}chat\.us\.n\-able\.com.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38135 |
| 839 | *ChromeCookiesView.exe* | .{0,1000}ChromeCookiesView\.exe.{0,1000} | greyware_tool_keyword | ChromeCookiesView | displays the list of all cookies stored by Google Chrome Web browser - abused by attackers | T1539 - T1005 - T1070.004 - T1552.001 | TA0006 - TA0008 - TA0009 | N/A | Evilnum - MuddyWater | Credential Access | https://www.nirsoft.net/utils/chrome_cookies_view.html | 1 | 1 | N/A | https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf | 8 | 10 | N/A | N/A | N/A | N/A | 38236 |
| 840 | *chromecookiesview.zip* | .{0,1000}chromecookiesview\.zip.{0,1000} | greyware_tool_keyword | ChromeCookiesView | displays the list of all cookies stored by Google Chrome Web browser - abused by attackers | T1539 - T1005 - T1070.004 - T1552.001 | TA0006 - TA0008 - TA0009 | N/A | Evilnum - MuddyWater | Credential Access | https://www.nirsoft.net/utils/chrome_cookies_view.html | 1 | 1 | N/A | https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf | 8 | 10 | N/A | N/A | N/A | N/A | 38237 |
| 841 | *chromecookiesview-x64.zip* | .{0,1000}chromecookiesview\-x64\.zip.{0,1000} | greyware_tool_keyword | ChromeCookiesView | displays the list of all cookies stored by Google Chrome Web browser - abused by attackers | T1539 - T1005 - T1070.004 - T1552.001 | TA0006 - TA0008 - TA0009 | N/A | Evilnum - MuddyWater | Credential Access | https://www.nirsoft.net/utils/chrome_cookies_view.html | 1 | 1 | N/A | https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf | 8 | 10 | N/A | N/A | N/A | N/A | 38238 |
| 842 | *chrome-remote-desktop_current_amd64.deb* | .{0,1000}chrome\-remote\-desktop_current_amd64\.deb.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38253 |
| 843 | *chromeremotedesktophost.msi* | .{0,1000}chromeremotedesktophost\.msi.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38254 |
| 844 | *client.teamviewer.com* | .{0,1000}client\.teamviewer\.com.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 1 | N/A | FP risk - teamviewer usage | 10 | 10 | N/A | N/A | N/A | N/A | 38332 |
| 845 | *client-api.aweray.com* | .{0,1000}client\-api\.aweray\.com.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38333 |
| 846 | *cloud.telebit.remot* | .{0,1000}cloud\.telebit\.remot.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38351 |
| 847 | *cloudflared-amd64.pkg* | .{0,1000}cloudflared\-amd64\.pkg.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 38367 |
| 848 | *cloudflared-windows-386.exe* | .{0,1000}cloudflared\-windows\-386\.exe.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 38368 |
| 849 | *cloudflared-windows-amd64.exe* | .{0,1000}cloudflared\-windows\-amd64\.exe.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 38369 |
| 850 | *cloudflared-windows-amd64.msi* | .{0,1000}cloudflared\-windows\-amd64\.msi.{0,1000} | greyware_tool_keyword | cloudflared | cloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your origins | T1572 - T1090 - T1071 | TA0001 - TA0011 | N/A | BlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6 | C2 | https://github.com/cloudflare/cloudflared | 1 | 1 | N/A | N/A | 10 | 10 | 10383 | 927 | 2025-04-10T16:59:49Z | 2017-10-13T19:54:47Z | 38370 |
| 851 | *cmd/boringproxy* | .{0,1000}cmd\/boringproxy.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 38469 |
| 852 | *cmd/crowbard/* | .{0,1000}cmd\/crowbard\/.{0,1000} | greyware_tool_keyword | crowbar | Tunnel TCP over a plain HTTP session | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | Dispossessor | C2 | https://github.com/q3k/crowbar | 1 | 1 | N/A | N/A | 10 | 10 | 476 | 41 | 2021-01-24T08:21:05Z | 2015-02-03T18:40:00Z | 38472 |
| 853 | *code.onedev.io/SoftEther/VPN.git* | .{0,1000}code\.onedev\.io\/SoftEther\/VPN\.git.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 38566 |
| 854 | *codeload.github.com/* | .{0,1000}codeload\.github\.com\/.{0,1000} | greyware_tool_keyword | github | Github executables download initiated - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 38576 |
| 855 | *commanderupdate.fleetdeck.io* | .{0,1000}commanderupdate\.fleetdeck\.io.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 38680 |
| 856 | *comserver.corporate.beanywhere.com* | .{0,1000}comserver\.corporate\.beanywhere\.com.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38737 |
| 857 | *control.*.logmeinrescue.com* | .{0,1000}control\..{0,1000}\.logmeinrescue\.com.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38804 |
| 858 | *control.rsc-app*.logmeinrescue.com | .{0,1000}control\.rsc\-app.{0,1000}\.logmeinrescue\.com | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38805 |
| 859 | *controlserver.anyviewer.com* | .{0,1000}controlserver\.anyviewer\.com.{0,1000} | greyware_tool_keyword | anyviewer | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyviewer.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38806 |
| 860 | *crash.syncthing.net* | .{0,1000}crash\.syncthing\.net.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | N/A | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 38968 |
| 861 | *curl*.interact.sh* | .{0,1000}curl.{0,1000}\.interact\.sh.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C3 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 39219 |
| 862 | *cwn-log-collector-production-clone.*.elasticbeanstalk.com* | .{0,1000}cwn\-log\-collector\-production\-clone\..{0,1000}\.elasticbeanstalk\.com.{0,1000} | greyware_tool_keyword | ComodoRMM (Itarian RMM) | Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://one.comodo.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 39290 |
| 863 | *CyberGhost.exe* | .{0,1000}CyberGhost\.exe.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 39304 |
| 864 | *CyberGhost.Service.exe* | .{0,1000}CyberGhost\.Service\.exe.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 39306 |
| 865 | *CyberGhostVPNSetup.exe* | .{0,1000}CyberGhostVPNSetup\.exe.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 39314 |
| 866 | *damewareagent.msi* | .{0,1000}damewareagent\.msi.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 40119 |
| 867 | *damewareremoteeverywhereagent.exe* | .{0,1000}damewareremoteeverywhereagent\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 40120 |
| 868 | *damewareremoteeverywhereconsole.exe* | .{0,1000}damewareremoteeverywhereconsole\.exe.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 40121 |
| 869 | *daps94/SirTunnel* | .{0,1000}daps94\/SirTunnel.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 40135 |
| 870 | *dashboard.tunnelmole.com* | .{0,1000}dashboard\.tunnelmole\.com.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 40158 |
| 871 | *-data.rel.tunnels.api.visualstudio.com* | .{0,1000}\-data\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 40164 |
| 872 | *data.syncthing.net* | .{0,1000}data\.syncthing\.net.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | N/A | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 40165 |
| 873 | *device.remote.it* | .{0,1000}device\.remote\.it.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 40778 |
| 874 | *d-h.st/users/powertool* | .{0,1000}d\-h\.st\/users\/powertool.{0,1000} | greyware_tool_keyword | Powertool | tool abused by threat actors to desactive Antivirus | T1562.001 - T1089 - T1562.009 | TA0005 | N/A | Play - Dispossessor | Defense Evasion | https://www.softpedia.com/get/Antivirus/Removal-Tools/ithurricane-PowerTool.shtml | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 40866 |
| 875 | *disk2vhd.exe* | .{0,1000}disk2vhd\.exe.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41032 |
| 876 | *Disk2vhd.zip* | .{0,1000}Disk2vhd\.zip.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41033 |
| 877 | *disk2vhd64.exe* | .{0,1000}disk2vhd64\.exe.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41034 |
| 878 | *dl.wireshark.org* | .{0,1000}dl\.wireshark\.org.{0,1000} | greyware_tool_keyword | wireshark | Wireshark is a network protocol analyzer. | T1040 - T1052.001 - T1046 | TA0001 - TA0002 - TA0007 | N/A | Black Basta | Sniffing & Spoofing | https://www.wireshark.org/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 41089 |
| 879 | *donate.ssl.xmrig.com* | .{0,1000}donate\.ssl\.xmrig\.com.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 41401 |
| 880 | *donate.v2.xmrig.com:3333* | .{0,1000}donate\.v2\.xmrig\.com\:3333.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 1 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 41402 |
| 881 | *donate.xmrig.com* | .{0,1000}donate\.xmrig\.com.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 41403 |
| 882 | *download.anydesk.com* | .{0,1000}download\.anydesk\.com.{0,1000} | greyware_tool_keyword | anydesk | Anydesk RMM usage | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | BlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt | RMM | https://anydesk.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41455 |
| 883 | *download.cyberghostvpn.com* | .{0,1000}download\.cyberghostvpn\.com.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 41456 |
| 884 | *download.filezilla-project.org* | .{0,1000}download\.filezilla\-project\.org.{0,1000} | greyware_tool_keyword | FileZilla | FileZilla admintool used by threat actors for persistence and data exfiltration | T1505 - T1041 | TA0003 - TA0009 -TA0010 | N/A | Dispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155 | Data Exfiltration | https://filezilla-project.org/ | 1 | 1 | N/A | PUA risk of legitimate usage | 5 | 7 | N/A | N/A | N/A | N/A | 41457 |
| 885 | *download.global.mspa.n-able.com/* | .{0,1000}download\.global\.mspa\.n\-able\.com\/.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Remote Control utilities | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/fr/remote-support-software | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41458 |
| 886 | *download.radmin.com* | .{0,1000}download\.radmin\.com.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41460 |
| 887 | *download.radmin-vpn.com* | .{0,1000}download\.radmin\-vpn\.com.{0,1000} | greyware_tool_keyword | Radmin | Radmin is a remote control program that lets you work on another computer through your own | T1021 - T1076 - T1563 | TA0008 - TA0009 - TA0002 | N/A | Akira | RMM | https://www.radmin.com/download/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41461 |
| 888 | *download.remotepc.com* | .{0,1000}download\.remotepc\.com.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41462 |
| 889 | *download.teamviewer.com.cdn.cloudflare.net* | .{0,1000}download\.teamviewer\.com\.cdn\.cloudflare\.net.{0,1000} | greyware_tool_keyword | teamviewer | TeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackers | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | LockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDA | RMM | https://www.teamviewer.com/ | 1 | 1 | N/A | FP risk - teamviewer usage | 10 | 10 | N/A | N/A | N/A | N/A | 41463 |
| 890 | *download.wireguard.com/windows-client/* | .{0,1000}download\.wireguard\.com\/windows\-client\/.{0,1000} | greyware_tool_keyword | wiretap | Wiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run. | T1572 | TA0011 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/sandialabs/wiretap | 1 | 1 | N/A | N/A | 10 | 10 | 939 | 41 | 2025-04-16T21:54:13Z | 2022-11-19T00:19:05Z | 41465 |
| 891 | *downloads.nordcdn.com/apps/vpn-extension/* | .{0,1000}downloads\.nordcdn\.com\/apps\/vpn\-extension\/.{0,1000} | greyware_tool_keyword | NordVPN | OVPN configuration for nordvpn accessed within corporate network | T1090.003 - T1133 - T1572 | TA0003 - TA0001 - TA0011 - TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://nordvpn.com | 1 | 1 | #VPN | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 41486 |
| 892 | *downloads.remote.it/remoteit/install_agent.sh* | .{0,1000}downloads\.remote\.it\/remoteit\/install_agent\.sh.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | N/A | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 41487 |
| 893 | *downloads.surfshark.com* | .{0,1000}downloads\.surfshark\.com.{0,1000} | greyware_tool_keyword | surfshark VPN | usage of surfsharkVPN client | T1090 - T1573 | TA0005 - TA010 | N/A | N/A | Defense Evasion | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 41488 | |
| 894 | *downloads.zohocdn.com* | .{0,1000}downloads\.zohocdn\.com.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41489 |
| 895 | *downloads.zohodl.com.cn* | .{0,1000}downloads\.zohodl\.com\.cn.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 41490 |
| 896 | *downloads2.surfshark.com* | .{0,1000}downloads2\.surfshark\.com.{0,1000} | greyware_tool_keyword | surfshark VPN | usage of surfsharkVPN client | T1090 - T1573 | TA0005 - TA010 | N/A | N/A | Defense Evasion | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 41492 | |
| 897 | *ekzhang/bore* | .{0,1000}ekzhang\/bore.{0,1000} | greyware_tool_keyword | bore | bore is a simple CLI tool for making tunnels to localhost | T1090 - T1090.003 - T1572 - T1572.001 | TA0042 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/ekzhang/bore | 1 | 1 | N/A | N/A | 10 | 10 | 9634 | 410 | 2025-04-14T21:52:18Z | 2022-04-04T02:47:54Z | 43040 |
| 898 | *ekzhang/sshx* | .{0,1000}ekzhang\/sshx.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 43041 |
| 899 | *elddy/NimScan* | .{0,1000}elddy\/NimScan.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 43046 |
| 900 | *eun1.rel.tunnels.api.visualstudio.com* | .{0,1000}eun1\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 43295 |
| 901 | *euw.rel.tunnels.api.visualstudio.com* | .{0,1000}euw\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 43297 |
| 902 | *eval-*.beyondtrustcloud.com* | .{0,1000}eval\-.{0,1000}\.beyondtrustcloud\.com.{0,1000} | greyware_tool_keyword | Bomgar | Bomgar beyoundtrust Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.beyondtrust.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 43299 |
| 903 | *EvanMcBroom/lsa-whisperer* | .{0,1000}EvanMcBroom\/lsa\-whisperer.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 43301 |
| 904 | *f38fg.tunnelmole.net* | .{0,1000}f38fg\.tunnelmole\.net.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 43896 |
| 905 | *fasmide/remotemoe* | .{0,1000}fasmide\/remotemoe.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 44459 |
| 906 | *fatedier/frp* | .{0,1000}fatedier\/frp.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 44465 |
| 907 | *fee.xmrig.com* | .{0,1000}fee\.xmrig\.com.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 44773 |
| 908 | *feedback.cyberghostvpn.com* | .{0,1000}feedback\.cyberghostvpn\.com.{0,1000} | greyware_tool_keyword | CyberGhost VPN | External VPN usage within coporate network | T1567 - T1090 | TA0003 - TA0005 - TA0009 - TA0010 - TA0011 | N/A | N/A | Defense Evasion | https://www.cyberghostvpn.com/ | 1 | 1 | #VPN | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 44778 |
| 909 | *File Shredder setup.exe* | .{0,1000}File\sShredder\ssetup\.exe.{0,1000} | greyware_tool_keyword | Shredder | File Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recovery | T1070 - T1485 - T1565.001 | TA0005 - TA0040 | N/A | N/A | Defense Evasion | https://www.fileshredder.org/ | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 44891 |
| 910 | *File Shredder.exe* | .{0,1000}File\sShredder\.exe.{0,1000} | greyware_tool_keyword | Shredder | File Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recovery | T1070 - T1485 - T1565.001 | TA0005 - TA0040 | N/A | N/A | Defense Evasion | https://www.fileshredder.org/ | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 44892 |
| 911 | *file_shredder_setup.exe* | .{0,1000}file_shredder_setup\.exe.{0,1000} | greyware_tool_keyword | Shredder | File Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recovery | T1070 - T1485 - T1565.001 | TA0005 - TA0040 | N/A | N/A | Defense Evasion | https://www.fileshredder.org/ | 1 | 1 | N/A | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 44895 |
| 912 | *filetransfer.io/upload/* | .{0,1000}filetransfer\.io\/upload\/.{0,1000} | greyware_tool_keyword | filetransfer.io | uploading to filetransfer.io | T1105 - T1021 - T1560.003 - T1071.001 - T1071.002 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://filetransfer.io | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 44920 |
| 913 | *fleetdeck.io/prototype3/commander_svc* | .{0,1000}fleetdeck\.io\/prototype3\/commander_svc.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45170 |
| 914 | *fleetdeck_agent.exe* | .{0,1000}fleetdeck_agent\.exe.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45171 |
| 915 | *fleetdeck_agent_svc.exe* | .{0,1000}fleetdeck_agent_svc\.exe.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45172 |
| 916 | *fleetdeck_commander_launcher.exe* | .{0,1000}fleetdeck_commander_launcher\.exe.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45173 |
| 917 | *fleetdeck_commander_svc.exe* | .{0,1000}fleetdeck_commander_svc\.exe.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45174 |
| 918 | *fleetdeck_installer.exe* | .{0,1000}fleetdeck_installer\.exe.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 45175 |
| 919 | *frpc_windows_amd64.exe* | .{0,1000}frpc_windows_amd64\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 45361 |
| 920 | *frpc_windows_arm64.exe* | .{0,1000}frpc_windows_arm64\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 45362 |
| 921 | *frps_windows_amd64.exe* | .{0,1000}frps_windows_amd64\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 45364 |
| 922 | *frps_windows_arm64.exe* | .{0,1000}frps_windows_arm64\.exe.{0,1000} | greyware_tool_keyword | frp | A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. | T1572 - T1090 - T1599 | TA0010 - TA0040 | N/A | N/A | Data Exfiltration | https://github.com/fatedier/frp | 1 | 1 | N/A | N/A | 10 | 10 | 92956 | 13929 | 2025-04-16T17:34:14Z | 2015-12-21T15:24:59Z | 45365 |
| 923 | *gateway.zohoassist.com* | .{0,1000}gateway\.zohoassist\.com.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 45482 |
| 924 | *geo.netsupportsoftware.com* | .{0,1000}geo\.netsupportsoftware\.com.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 45608 |
| 925 | *Gerenios/AADInternals* | .{0,1000}Gerenios\/AADInternals.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 45614 |
| 926 | *getcroc.schollz.com* | .{0,1000}getcroc\.schollz\.com.{0,1000} | greyware_tool_keyword | croc | croc is a tool that allows any two computers to simply and securely transfer files and folders | T1567.002 - T1090.002 - T1573.002 - T1102.003 | TA0010 - TA0005 - TA0008 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/schollz/croc | 1 | 1 | N/A | N/A | 8 | 10 | 29989 | 1197 | 2025-04-16T23:30:54Z | 2017-10-17T15:20:18Z | 45947 |
| 927 | *ghcr.io/agrinman/tunnelto* | .{0,1000}ghcr\.io\/agrinman\/tunnelto.{0,1000} | greyware_tool_keyword | tunnelto.dev | Expose your local web server to the internet with a public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/agrinman/tunnelto | 1 | 1 | N/A | N/A | 10 | 10 | 2167 | 118 | 2022-09-24T21:28:44Z | 2020-03-22T05:39:49Z | 46378 |
| 928 | *ghcr.io/ao-space/gt:client-dev* | .{0,1000}ghcr\.io\/ao\-space\/gt\:client\-dev.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 46379 |
| 929 | *ghcr.io/ao-space/gt:server-dev* | .{0,1000}ghcr\.io\/ao\-space\/gt\:server\-dev.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 46380 |
| 930 | *github*/xmrig/xmrig* | .{0,1000}github.{0,1000}\/xmrig\/xmrig.{0,1000} | greyware_tool_keyword | xmrig | CPU/GPU cryptominer often used by attackers on compromised machines | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/xmrig/xmrig/ | 1 | 1 | N/A | N/A | 9 | 10 | 9173 | 3602 | 2025-04-17T09:12:31Z | 2017-04-15T05:57:53Z | 46427 |
| 931 | *github*ao-space/gt* | .{0,1000}github.{0,1000}ao\-space\/gt.{0,1000} | greyware_tool_keyword | gt | Fast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost. | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ao-space/gt | 1 | 1 | N/A | N/A | 10 | 10 | 132 | 36 | 2024-10-30T00:37:47Z | 2021-11-29T03:09:56Z | 46428 |
| 932 | *github*koding/tunnel* | .{0,1000}github.{0,1000}koding\/tunnel.{0,1000} | greyware_tool_keyword | tunnel | Tunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outside | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/koding/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 328 | 72 | 2023-10-20T13:43:58Z | 2015-05-28T07:26:42Z | 46429 |
| 933 | *github.com*/jprq/releases/download/* | .{0,1000}github\.com.{0,1000}\/jprq\/releases\/download\/.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 46430 |
| 934 | *github.com/tailscale* | .{0,1000}github\.com\/tailscale.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 46441 |
| 935 | *gitlab.com/SoftEther/VPN.git* | .{0,1000}gitlab\.com\/SoftEther\/VPN\.git.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 46445 |
| 936 | *global.rel.tunnels.api.visualstudio.com* | .{0,1000}global\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 46468 |
| 937 | *global.rel.tunnels.api.visualstudio.com* | .{0,1000}global\.rel\.tunnels\.api\.visualstudio\.com.{0,1000} | greyware_tool_keyword | vscode | Starts a reverse connection over global.rel.tunnels.api.visualstudio.com via websockets | T1090.003 - T1059.001 - T1071.001 | TA0011 - TA0002 | N/A | N/A | C2 | https://badoption.eu/blog/2023/01/31/code_c2.html | 0 | 1 | N/A | risk of False positive | 10 | 10 | N/A | N/A | N/A | N/A | 46469 |
| 938 | *go-gost/gost* | .{0,1000}go\-gost\/gost.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 46573 |
| 939 | *GoodSync-vsub-2Go-Setup.exe* | .{0,1000}GoodSync\-vsub\-2Go\-Setup\.exe.{0,1000} | greyware_tool_keyword | Goodsync | GoodSync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | N/A | Data Exfiltration | https://www.goodsync.com/ | 1 | 1 | N/A | portable version | 9 | 10 | N/A | N/A | N/A | N/A | 46587 |
| 940 | *google-chrome-stable_current_amd64.deb* | .{0,1000}google\-chrome\-stable_current_amd64\.deb.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46600 |
| 941 | *GoTo MyPC Installer.exe* | .{0,1000}GoTo\sMyPC\sInstaller\.exe.{0,1000} | greyware_tool_keyword | GoToMyPC | GoToMyPC is remote desktop software that allows users to access computers remotely using a web browser | T1021.001 - T1059 - T1078 - T1133 - T1563 | TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010 | N/A | N/A | RMM | https://www.gotomypc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46641 |
| 942 | *gtfobins* | .{0,1000}gtfobins.{0,1000} | greyware_tool_keyword | gtfobins | GTFOBins is a curated list of Unix binaries that can used to bypass local security restrictions in misconfigured systems malicious use of legitimate binaries | T1059 - T1068 - T1136 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://gtfobins.github.io/ | 1 | 1 | #linux | high false positive risks - low signal | 2 | 5 | N/A | N/A | N/A | N/A | 46793 |
| 943 | *hackforums.net/* | .{0,1000}hackforums\.net\/.{0,1000} | greyware_tool_keyword | hackforums.net | Hack Forums - a well-known online community frequently referenced in various pieces of malicious code | T1588.003 | TA0011 | N/A | N/A | Exploitation tool | hackforums.net | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 46848 |
| 944 | *homeassistant.local:8123* | .{0,1000}homeassistant\.local\:8123.{0,1000} | greyware_tool_keyword | homeway.io | Expose local servers to the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://homeway.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47262 |
| 945 | *http*.sslip.io* | .{0,1000}http.{0,1000}\.sslip\.io.{0,1000} | greyware_tool_keyword | sslip.io | sslip.io is a DNS server that maps specially-crafted DNS A records to IP addresses e.g. 127-0-0-1.sslip.io maps to 127.0.0.1 | T1568.002 - T1048.003 | TA0003 - TA0004 | N/A | N/A | C2 | https://github.com/cunnie/sslip.io | 1 | 1 | N/A | letigimate tool abused by threat actor to bypass IP blockage and encrypt traffic | 6 | 10 | 737 | 79 | 2025-04-04T14:05:21Z | 2015-08-26T18:43:35Z | 47332 |
| 946 | *http*/agent-api-*.atera.com* | .{0,1000}http.{0,1000}\/agent\-api\-.{0,1000}\.atera\.com.{0,1000} | greyware_tool_keyword | Atera | control remote machines- abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | BlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - Dispossessor | RMM | https://www.atera.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47334 |
| 947 | *http://*.interact.sh* | .{0,1000}http\:\/\/.{0,1000}\.interact\.sh.{0,1000} | greyware_tool_keyword | interactsh | Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4 | T1566.002 - T1566.001 - T1071 - T1102 | TA0011 - TA0001 | N/A | N/A | C2 | https://github.com/projectdiscovery/interactsh | 1 | 1 | N/A | FP risk - legitimate service abused by attackers | 10 | 10 | 3718 | 388 | 2025-04-22T12:41:45Z | 2021-01-29T14:31:51Z | 47373 |
| 948 | *http://*.localhost.run* | .{0,1000}http\:\/\/.{0,1000}\.localhost\.run.{0,1000} | greyware_tool_keyword | localhost.run | Put a locally running HTTP HTTPS or TLS app on the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://localhost.run/ | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47374 |
| 949 | *http://*.pagekite.me* | .{0,1000}http\:\/\/.{0,1000}\.pagekite\.me.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 47384 |
| 950 | *http://*.remote.moe/* | .{0,1000}http\:\/\/.{0,1000}\.remote\.moe\/.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 47385 |
| 951 | *http://*.serveo.net* | .{0,1000}http\:\/\/.{0,1000}\.serveo\.net.{0,1000} | greyware_tool_keyword | serveo.net | Expose local servers to the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://serveo.net | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47386 |
| 952 | *http://*.ssi.sh* | .{0,1000}http\:\/\/.{0,1000}\.ssi\.sh.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 1 | N/A | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 47387 |
| 953 | *http://*.trycloudfare.com* | .{0,1000}http\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47390 |
| 954 | *http://*.tunnelmole.net* | .{0,1000}http\:\/\/.{0,1000}\.tunnelmole\.net.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 47391 |
| 955 | *http://*.zrok.io* | .{0,1000}http\:\/\/.{0,1000}\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 47392 |
| 956 | *http://*:9000/restic* | .{0,1000}http\:\/\/.{0,1000}\:9000\/restic.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 47398 |
| 957 | *http://127.0.0.1:18080* | .{0,1000}http\:\/\/127\.0\.0\.1\:18080.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 47414 |
| 958 | *http://127.0.0.1:2019/id/* | .{0,1000}http\:\/\/127\.0\.0\.1\:2019\/id\/.{0,1000} | greyware_tool_keyword | SirTunnel | SirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/anderspitman/SirTunnel | 1 | 1 | N/A | N/A | 10 | 10 | 1436 | 119 | 2024-03-24T20:15:50Z | 2020-09-23T00:15:26Z | 47415 |
| 959 | *http://127.0.0.1:3320/-/healthcheck* | .{0,1000}http\:\/\/127\.0\.0\.1\:3320\/\-\/healthcheck.{0,1000} | greyware_tool_keyword | pgrok | Poor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pgrok/pgrok | 1 | 1 | N/A | N/A | 10 | 10 | 3325 | 117 | 2025-04-19T18:37:55Z | 2023-03-08T12:43:55Z | 47417 |
| 960 | *http://127.0.0.1:4000* | .{0,1000}http\:\/\/127\.0\.0\.1\:4000.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47419 |
| 961 | *http://127.0.0.1:4040/api/logs/* | .{0,1000}http\:\/\/127\.0\.0\.1\:4040\/api\/logs\/.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 47420 |
| 962 | *http://127.0.0.1:4040/api/tunnels* | .{0,1000}http\:\/\/127\.0\.0\.1\:4040\/api\/tunnels.{0,1000} | greyware_tool_keyword | ngrok | ngrok - abused by attackers for C2 usage | T1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002 | TA0011 - TA0010 - TA0005 | N/A | Akira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - Dispossessor | C2 | https://github.com/inconshreveable/ngrok | 1 | 1 | N/A | N/A | 10 | 10 | 24316 | 4287 | 2024-04-26T18:11:18Z | 2013-03-20T09:37:43Z | 47421 |
| 963 | *http://127.0.0.1:8000/gate.html* | .{0,1000}http\:\/\/127\.0\.0\.1\:8000\/gate\.html.{0,1000} | greyware_tool_keyword | golang_c2 | C2 written in Go for red teams aka gorfice2k | T1071 - T1021 - T1090 | TA0011 - TA0008 - TA0010 | N/A | N/A | C2 | https://github.com/m00zh33/golang_c2 | 1 | 1 | N/A | N/A | 10 | 10 | 6 | 8 | 2019-03-18T00:46:41Z | 2019-03-19T02:39:59Z | 47429 |
| 964 | *http://127.0.0.1:8384* | .{0,1000}http\:\/\/127\.0\.0\.1\:8384.{0,1000} | greyware_tool_keyword | syncthing | Open Source Continuous File Synchronization - abused by attackers for data exfiltration | T1046 - T1041 - T1020 - T1567 | TA0043 - TA0007 - TA0010 | N/A | Dispossessor - UAC-0020 | Data Exfiltration | https://github.com/syncthing/syncthing | 1 | 1 | N/A | https://cert.gov.ua/article/6279600 | 9 | 10 | 69579 | 4486 | 2025-04-22T01:30:11Z | 2013-11-26T09:48:21Z | 47435 |
| 965 | *http://127.0.0.1:9191* | .{0,1000}http\:\/\/127\.0\.0\.1\:9191.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 47437 |
| 966 | *http://antibody-software.com/files/wiztreeversion.php* | .{0,1000}http\:\/\/antibody\-software\.com\/files\/wiztreeversion\.php.{0,1000} | greyware_tool_keyword | wiztree | legitimate tool abused by threat actors to obtain network files and directory listings | T1083 | TA0007 | N/A | Fox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - Royal | Discovery | N/A | 1 | 1 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 47445 |
| 967 | *http://api.guerrillamail.com/ajax.php?* | .{0,1000}http\:\/\/api\.guerrillamail\.com\/ajax\.php\?.{0,1000} | greyware_tool_keyword | guerrillamail | using the API of a disposable email address to use anytime - could be abused by malicious actors | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | https://www.guerrillamail.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47446 |
| 968 | *http://arslan.koding.io/* | .{0,1000}http\:\/\/arslan\.koding\.io\/.{0,1000} | greyware_tool_keyword | tunnel | Tunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outside | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/koding/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | 328 | 72 | 2023-10-20T13:43:58Z | 2015-05-28T07:26:42Z | 47447 |
| 969 | *http://bore.pub/* | .{0,1000}http\:\/\/bore\.pub\/.{0,1000} | greyware_tool_keyword | bore | bore is a simple CLI tool for making tunnels to localhost | T1090 - T1090.003 - T1572 - T1572.001 | TA0042 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/ekzhang/bore | 1 | 1 | N/A | N/A | 10 | 10 | 9634 | 410 | 2025-04-14T21:52:18Z | 2022-04-04T02:47:54Z | 47453 |
| 970 | *http://canarytokens.com/*/* | .{0,1000}http\:\/\/canarytokens\.com\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | canarytokens.com | free honeypot detection tokens but also abused by attacker for payload callback confirmation | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://canarytokens.com | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 47455 |
| 971 | *http://dnslog.cn/* | .{0,1000}http\:\/\/dnslog\.cn\/.{0,1000} | greyware_tool_keyword | dnslog.cn | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://dnslog.cn | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 47456 |
| 972 | *http://dsrt.dyndns.org:8888/uvs_freeupdate_en.htm* | .{0,1000}http\:\/\/dsrt\.dyndns\.org\:8888\/uvs_freeupdate_en\.htm.{0,1000} | greyware_tool_keyword | Universal Virus Sniffer | Universal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | Phobos | Defense Evasion | https://www.majorgeeks.com/files/details/universal_virus_sniffer.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47457 |
| 973 | *http://dsrt.dyndns.org:8888/uvs_register_en.htm* | .{0,1000}http\:\/\/dsrt\.dyndns\.org\:8888\/uvs_register_en\.htm.{0,1000} | greyware_tool_keyword | Universal Virus Sniffer | Universal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | Phobos | Defense Evasion | https://www.majorgeeks.com/files/details/universal_virus_sniffer.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47458 |
| 974 | *http://get-my-ip.ddns.softether-network.net/ddns/getmyip.ashx* | .{0,1000}http\:\/\/get\-my\-ip\.ddns\.softether\-network\.net\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47460 |
| 975 | *http://get-my-ip.ddns.uxcom.jp/ddns/getmyip.ashx* | .{0,1000}http\:\/\/get\-my\-ip\.ddns\.uxcom\.jp\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47461 |
| 976 | *http://get-my-ip-v6.ddns.softether-network.net/ddns/getmyip.ashx* | .{0,1000}http\:\/\/get\-my\-ip\-v6\.ddns\.softether\-network\.net\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47462 |
| 977 | *http://get-my-ip-v6.ddns.uxcom.jp/ddns/getmyip.ashx* | .{0,1000}http\:\/\/get\-my\-ip\-v6\.ddns\.uxcom\.jp\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47463 |
| 978 | *http://localhost:1337* | .{0,1000}http\:\/\/localhost\:1337.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 47472 |
| 979 | *http://localhost:1337/previewlogin* | .{0,1000}http\:\/\/localhost\:1337\/previewlogin.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 47473 |
| 980 | *http://localhost:7681* | .{0,1000}http\:\/\/localhost\:7681.{0,1000} | greyware_tool_keyword | supershell | Supershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture Payload | T1090 - T1059 - T1021 | TA0011 - TA0005 - TA0002 | N/A | N/A | C2 | https://github.com/tdragon6/Supershell | 1 | 1 | N/A | N/A | 10 | 10 | 1561 | 196 | 2023-09-26T13:53:55Z | 2023-03-25T15:02:43Z | 47480 |
| 981 | *http://local-tailscaled.sock* | .{0,1000}http\:\/\/local\-tailscaled\.sock.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47487 |
| 982 | *http://pastie.org/p/*/raw* | .{0,1000}http\:\/\/pastie\.org\/p\/.{0,1000}\/raw.{0,1000} | greyware_tool_keyword | pastie.org | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | http://pastie.org/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47503 |
| 983 | *http://pastie.org/pastes/create* | .{0,1000}http\:\/\/pastie\.org\/pastes\/create.{0,1000} | greyware_tool_keyword | pastie.org | sending data to a pastebin | T1567.002 | TA0010 | N/A | N/A | Data Exfiltration | http://pastie.org/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47504 |
| 984 | *http://requestbin.net/r/* | .{0,1000}http\:\/\/requestbin\.net\/r\/.{0,1000} | greyware_tool_keyword | requestbin.net | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://requestbin.net | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 47507 |
| 985 | *http://senet.aoi.flets-east.jp/ddns/getmyip.ashx* | .{0,1000}http\:\/\/senet\.aoi\.flets\-east\.jp\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47508 |
| 986 | *http://senet.p-ns.flets-west.jp/ddns/getmyip.ashx* | .{0,1000}http\:\/\/senet\.p\-ns\.flets\-west\.jp\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47509 |
| 987 | *http://senet-flets.v6.softether.co.jp/ddns/getmyip.ashx* | .{0,1000}http\:\/\/senet\-flets\.v6\.softether\.co\.jp\/ddns\/getmyip\.ashx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47510 |
| 988 | *http://support.kaspersky.com/viruses/tdsskiller.xmlt* | .{0,1000}http\:\/\/support\.kaspersky\.com\/viruses\/tdsskiller\.xmlt.{0,1000} | greyware_tool_keyword | TDSKiller | TDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Avaddon | Defense Evasion | https://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47515 |
| 989 | *http://tcp.btunnel.in* | .{0,1000}http\:\/\/tcp\.btunnel\.in.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 47518 |
| 990 | *http://temp.sh/*/* | .{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | temp.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47519 |
| 991 | *http://up.pagekite.net/* | .{0,1000}http\:\/\/up\.pagekite\.net\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 47522 |
| 992 | *http://update.iobit.com/infofiles/iobitunlocker.upt* | .{0,1000}http\:\/\/update\.iobit\.com\/infofiles\/iobitunlocker\.upt.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 1 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 47523 |
| 993 | *http://www.advanced-port-scanner.com/checkupdate.php* | .{0,1000}http\:\/\/www\.advanced\-port\-scanner\.com\/checkupdate\.php.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 47527 |
| 994 | *http://www.epoolsoft.com/pchunter/pchunter_free* | .{0,1000}http\:\/\/www\.epoolsoft\.com\/pchunter\/pchunter_free.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47531 |
| 995 | *http://www.epoolsoft.com/PCHunter_Standard* | .{0,1000}http\:\/\/www\.epoolsoft\.com\/PCHunter_Standard.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47532 |
| 996 | *http://www.proxifier.com/distr/last_versions/ProxifierMac* | .{0,1000}http\:\/\/www\.proxifier\.com\/distr\/last_versions\/ProxifierMac.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 47538 |
| 997 | *http://www.proxifier.com/distr/last_versions/ProxifierPortable* | .{0,1000}http\:\/\/www\.proxifier\.com\/distr\/last_versions\/ProxifierPortable.{0,1000} | greyware_tool_keyword | Proxifier | allows to proxy connections for programs | T1090 - T1071 - T1078.003 | TA0005 | N/A | Scattered Spider* - Proxifier | Defense Evasion | https://www.proxifier.com/download/ | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 47539 |
| 998 | *http://zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd.onion* | .{0,1000}http\:\/\/zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd\.onion.{0,1000} | greyware_tool_keyword | zerobin.net | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | https://zerobin.net/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47545 |
| 999 | *https://*.*.devtunnels.ms* | .{0,1000}https\:\/\/.{0,1000}\..{0,1000}\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47585 |
| 1000 | *https://*.*.devtunnels.ms* | .{0,1000}https\:\/\/.{0,1000}\..{0,1000}\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | vscode | built-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices. | T1090 - T1003 - T1571 | TA0010 - TA0002 - TA0009 | N/A | N/A | C2 | https://twitter.com/code/status/1699869087071899669 | 0 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47586 |
| 1001 | *https://*.app.github.dev/* | .{0,1000}https\:\/\/.{0,1000}\.app\.github\.dev\/.{0,1000} | greyware_tool_keyword | github | access to a GitHub Codespace environment - Github Codespaces have a public port forwarding option allowing you to make your server available for the public. | T1071 - T1572 | TA0001 - TA0005 | N/A | N/A | Collection | https://detect.fyi/how-threat-actors-use-github-bd991c11ed37 | 0 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 47587 |
| 1002 | *https://*.brs.devtunnels.ms/* | .{0,1000}https\:\/\/.{0,1000}\.brs\.devtunnels\.ms\/.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 0 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47588 |
| 1003 | *https://*.btunnel.co.in* | .{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 47589 |
| 1004 | *https://*.btunnel.co.in* | .{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 47590 |
| 1005 | *https://*.btunnel.co.in* | .{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000} | greyware_tool_keyword | btunnel.in | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://www.btunnel.in/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47591 |
| 1006 | *https://*.dev.servers.ddns.softether-network.net/ddns/ddns.aspx* | .{0,1000}https\:\/\/.{0,1000}\.dev\.servers\.ddns\.softether\-network\.net\/ddns\/ddns\.aspx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47592 |
| 1007 | *https://*.dev.servers-v6.ddns.softether-network.net/ddns/ddns.aspx* | .{0,1000}https\:\/\/.{0,1000}\.dev\.servers\-v6\.ddns\.softether\-network\.net\/ddns\/ddns\.aspx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47593 |
| 1008 | *https://*.euw.devtunnels.ms* | .{0,1000}https\:\/\/.{0,1000}\.euw\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 0 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47594 |
| 1009 | *https://*.fex.net/download/* | .{0,1000}https\:\/\/.{0,1000}\.fex\.net\/download\/.{0,1000} | greyware_tool_keyword | fex.net | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Collection | https://fex.net | 1 | 1 | #filehostingservice | downloading a file | 10 | 10 | N/A | N/A | N/A | N/A | 47595 |
| 1010 | *https://*.fex.net/upload/* | .{0,1000}https\:\/\/.{0,1000}\.fex\.net\/upload\/.{0,1000} | greyware_tool_keyword | fex.net | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Data Exfiltration | https://fex.net | 1 | 1 | #filehostingservice | uploading a file | 10 | 10 | N/A | N/A | N/A | N/A | 47596 |
| 1011 | *https://*.free.beeceptor.com* | .{0,1000}https\:\/\/.{0,1000}\.free\.beeceptor\.com.{0,1000} | greyware_tool_keyword | beeceptor.com | temporary public URL for your localhost + port combination - ideal for real-time testing - can be abused for payload callback confirmation | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://beeceptor.com/local-tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47597 |
| 1012 | *https://*.localhost.run* | .{0,1000}https\:\/\/.{0,1000}\.localhost\.run.{0,1000} | greyware_tool_keyword | localhost.run | Put a locally running HTTP HTTPS or TLS app on the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://localhost.run/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47599 |
| 1013 | *https://*.localtunnel.me* | .{0,1000}https\:\/\/.{0,1000}\.localtunnel\.me.{0,1000} | greyware_tool_keyword | localtunnels | client for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 8 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 47600 |
| 1014 | *https://*.my.auvik.com/* | .{0,1000}https\:\/\/.{0,1000}\.my\.auvik\.com\/.{0,1000} | greyware_tool_keyword | auvik | cloud-based network management software | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://www.auvik.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47601 |
| 1015 | *https://*.pagekite.me* | .{0,1000}https\:\/\/.{0,1000}\.pagekite\.me.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 47604 |
| 1016 | *https://*.pulseway.com/app/main/* | .{0,1000}https\:\/\/.{0,1000}\.pulseway\.com\/app\/main\/.{0,1000} | greyware_tool_keyword | Pulseway | Pulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Back Basta | RMM | https://www.pulseway.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47605 |
| 1017 | *https://*.remote.moe/* | .{0,1000}https\:\/\/.{0,1000}\.remote\.moe\/.{0,1000} | greyware_tool_keyword | remotemoe | remotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwards | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/fasmide/remotemoe | 1 | 1 | N/A | N/A | 10 | 10 | 288 | 32 | 2024-06-03T14:00:47Z | 2020-06-11T07:41:03Z | 47606 |
| 1018 | *https://*.screenconnect.com/Bin/*.exe* | .{0,1000}https\:\/\/.{0,1000}\.screenconnect\.com\/Bin\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | ScreenConnect | control remote servers - abused by threat actors | T1021.001 - T1078 - T1133 - T1112 | TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010 | N/A | Black Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater | RMM | screenconnect.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47607 |
| 1019 | *https://*.screenconnect.com/Host* | .{0,1000}https\:\/\/.{0,1000}\.screenconnect\.com\/Host.{0,1000} | greyware_tool_keyword | ScreenConnect | ConnectWise Control formerly known as Screenconnect is a remote desktop software application. | T1021.001 - T1133 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater | RMM | https://screenconnect.connectwise.com/download | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47608 |
| 1020 | *https://*.sendspace.com/upload* | .{0,1000}https\:\/\/.{0,1000}\.sendspace\.com\/upload.{0,1000} | greyware_tool_keyword | sendspace.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Dispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice Society | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47609 |
| 1021 | *https://*.serveo.net* | .{0,1000}https\:\/\/.{0,1000}\.serveo\.net.{0,1000} | greyware_tool_keyword | serveo.net | Expose local servers to the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://serveo.net | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47610 |
| 1022 | *https://*.ssi.sh* | .{0,1000}https\:\/\/.{0,1000}\.ssi\.sh.{0,1000} | greyware_tool_keyword | sish | HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/antoniomika/sish | 1 | 1 | N/A | N/A | 10 | 10 | 4203 | 325 | 2025-04-10T20:04:08Z | 2019-02-15T15:36:23Z | 47611 |
| 1023 | *https://*.tacticalrmm.com/* | .{0,1000}https\:\/\/.{0,1000}\.tacticalrmm\.com\/.{0,1000} | greyware_tool_keyword | tacticalrmm | A remote monitoring & management tool | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | AvosLocker - Scattered Spider* - Black Basta | RMM | https://github.com/amidaware/tacticalrmm | 1 | 1 | N/A | N/A | 10 | 10 | 3538 | 484 | 2025-04-22T19:24:13Z | 2019-10-22T22:19:12Z | 47612 |
| 1024 | *https://*.telebit.io* | .{0,1000}https\:\/\/.{0,1000}\.telebit\.io.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47613 |
| 1025 | *https://*.trycloudfare.com* | .{0,1000}https\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47616 |
| 1026 | *https://*.trycloudflare.com* | .{0,1000}https\:\/\/.{0,1000}\.trycloudflare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | Attackers abuse this service to expose malicious servers on a *.trycloudflare.com subdomain | T1567.002 - T1102 - T1071.001 - T1036 | TA0001 - TA0005 - TA0009 | N/A | N/A | Collection | https://lots-project.com/site/2a2e747279636c6f7564666c6172652e636f6d | 0 | 1 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47617 |
| 1027 | *https://*.tunnelmole.net* | .{0,1000}https\:\/\/.{0,1000}\.tunnelmole\.net.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 47618 |
| 1028 | *https://*.use.devtunnels.ms* | .{0,1000}https\:\/\/.{0,1000}\.use\.devtunnels\.ms.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 0 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47620 |
| 1029 | *https://*.zoho.com/pconnect* | .{0,1000}https\:\/\/.{0,1000}\.zoho\.com\/pconnect.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47621 |
| 1030 | *https://*.zohoassist.com/w_socket* | .{0,1000}https\:\/\/.{0,1000}\.zohoassist\.com\/w_socket.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47622 |
| 1031 | *https://*.zrok.io* | .{0,1000}https\:\/\/.{0,1000}\.zrok\.io.{0,1000} | greyware_tool_keyword | zrok | zrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/openziti/zrok | 1 | 1 | N/A | N/A | 10 | 10 | 3132 | 125 | 2025-04-22T18:36:51Z | 2022-07-18T19:14:51Z | 47623 |
| 1032 | *https://*:9000/restic* | .{0,1000}https\:\/\/.{0,1000}\:9000\/restic.{0,1000} | greyware_tool_keyword | restic | backup program used by threat actors for data exfiltration | T1567 | TA0009 - TA0010 | N/A | INC Ransom - Lynx | Data Exfiltration | https://github.com/restic/restic | 1 | 1 | N/A | N/A | 8 | 10 | 28342 | 1599 | 2025-04-14T18:02:41Z | 2014-04-27T14:07:58Z | 47627 |
| 1033 | *https://0bin.net/paste/*+* | .{0,1000}https\:\/\/0bin\.net\/paste\/.{0,1000}\+.{0,1000} | greyware_tool_keyword | 0bin.net | Accessing a paste on 0bin.net | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Collection | https://0bin.net | 1 | 1 | #PastebinLike | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 47631 |
| 1034 | *https://0bin.net/paste/create* | .{0,1000}https\:\/\/0bin\.net\/paste\/create.{0,1000} | greyware_tool_keyword | 0bin.net | Creating a paste on 0bin.net | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://0bin.net | 1 | 1 | #PastebinLike | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47632 |
| 1035 | *https://12ft.io/api/proxy?q=http* | .{0,1000}https\:\/\/12ft\.io\/api\/proxy\?q\=http.{0,1000} | greyware_tool_keyword | 12ft.io | Attackers can use 12ft.io to masquerade their domain for phishing purposes. | T1204.002 - T1036 - T1566.002 | TA0001 - TA0005 | N/A | N/A | Defense Evasion | https://12ft.io/ | 0 | 1 | N/A | N/A | 5 | 5 | N/A | N/A | N/A | N/A | 47643 |
| 1036 | *https://12ft.io/proxy?q=* | .{0,1000}https\:\/\/12ft\.io\/proxy\?q\=.{0,1000} | greyware_tool_keyword | 12ft.io | Attackers can use 12ft.io to masquerade their domain for phishing purposes. | T1204.002 - T1036 - T1566.002 | TA0001 - TA0005 | N/A | N/A | Defense Evasion | https://12ft.io/ | 0 | 1 | N/A | N/A | 5 | 5 | N/A | N/A | N/A | N/A | 47644 |
| 1037 | *https://1ty.me/* | .{0,1000}https\:\/\/1ty\.me\/.{0,1000} | greyware_tool_keyword | 1ty.me | temporary notes service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | N/A | Collection | https://1ty.me | 1 | 1 | #PastebinLike | downloading or uploading data | 10 | 10 | N/A | N/A | N/A | N/A | 47645 |
| 1038 | *https://1ty.me/?mode=ajax&cmd=create_note* | .{0,1000}https\:\/\/1ty\.me\/\?mode\=ajax\&cmd\=create_note.{0,1000} | greyware_tool_keyword | 1ty.me | temporary notes service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://1ty.me | 1 | 1 | #PastebinLike | creating note | 10 | 10 | N/A | N/A | N/A | N/A | 47646 |
| 1039 | *https://aadinternals.com/aadinternals/* | .{0,1000}https\:\/\/aadinternals\.com\/aadinternals\/.{0,1000} | greyware_tool_keyword | AADInternals | AADInternals PowerShell module for administering Azure AD and Office 365 | T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649 | TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011 | N/A | APT29 - COZY BEAR | Exploitation tool | https://github.com/Gerenios/AADInternals | 1 | 1 | N/A | N/A | 9 | 10 | 1404 | 231 | 2025-04-18T11:41:23Z | 2018-10-25T17:35:16Z | 47648 |
| 1040 | *https://aka.ms/DevTunnelCliInstall* | .{0,1000}https\:\/\/aka\.ms\/DevTunnelCliInstall.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 0 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47650 |
| 1041 | *https://aka.ms/TunnelsCliDownload/* | .{0,1000}https\:\/\/aka\.ms\/TunnelsCliDownload\/.{0,1000} | greyware_tool_keyword | dev-tunnels | Dev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooks | T1021.003 - T1105 - T1090 | TA0002 - TA0005 - TA0011 | N/A | N/A | C2 | https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47651 |
| 1042 | *https://anonfiles.com/*/* | .{0,1000}https\:\/\/anonfiles\.com\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | anonfiles.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHub | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47653 |
| 1043 | *https://anymailfinder.com/search/* | .{0,1000}https\:\/\/anymailfinder\.com\/search\/.{0,1000} | greyware_tool_keyword | anymailfinder | used by attackers to find informations about a company users | T1593 - T1596 - T1213 | TA0009 | N/A | N/A | Reconnaissance | https://anymailfinder.com | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 47654 |
| 1044 | *https://apaste.info/p/new* | .{0,1000}https\:\/\/apaste\.info\/p\/new.{0,1000} | greyware_tool_keyword | apaste.info | Creating a paste on apaste.info/ | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://apaste.info/ | 1 | 1 | #PastebinLike | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47655 |
| 1045 | *https://api.anonfiles.com/upload* | .{0,1000}https\:\/\/api\.anonfiles\.com\/upload.{0,1000} | greyware_tool_keyword | anonfiles.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHub | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47656 |
| 1046 | *https://api.dropboxapi.com/* | .{0,1000}https\:\/\/api\.dropboxapi\.com\/.{0,1000} | greyware_tool_keyword | DBC2 | DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication. | T1105 - T1071.004 - T1102 | TA0003 - TA0002 - TA0008 | N/A | BlackCat - Scattered Spider* | C2 | https://github.com/Arno0x/DBC2 | 1 | 1 | N/A | Dropbox API calls - Understanding your environment with the applications used and allowed will enhances the effectiveness of your hunt here | 10 | 10 | 295 | 86 | 2017-10-27T07:39:02Z | 2016-12-14T10:35:56Z | 47657 |
| 1047 | *https://api.fex.net/api/v1/anonymous/file* | .{0,1000}https\:\/\/api\.fex\.net\/api\/v1\/anonymous\/file.{0,1000} | greyware_tool_keyword | fex.net | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Data Exfiltration | https://fex.net | 1 | 1 | #filehostingservice | uploading a file | 10 | 10 | N/A | N/A | N/A | N/A | 47659 |
| 1048 | *https://api.freefilesync.org/new_installation* | .{0,1000}https\:\/\/api\.freefilesync\.org\/new_installation.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47660 |
| 1049 | *https://api.hunter.io/* | .{0,1000}https\:\/\/api\.hunter\.io\/.{0,1000} | greyware_tool_keyword | Hunter.io | used by attacker and pentester while gathering information. Hunter lets you find email addresses in seconds and connect with the people that matter for your business | T1597 - T1526 - T1087 - T1078 - T1056 - T1018 - T1016 - T1583 - T1589 | TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Reconnaissance | https://hunter.io/ | 1 | 1 | N/A | N/A | N/A | 10 | N/A | N/A | N/A | N/A | 47662 |
| 1050 | *https://api.openai.com/v1/files* | .{0,1000}https\:\/\/api\.openai\.com\/v1\/files.{0,1000} | greyware_tool_keyword | ratchatpt | C2 using openAI API | T1094 - T1071.001 | TA0011 - TA0002 | N/A | N/A | C2 | https://github.com/spartan-conseil/ratchatpt | 0 | 1 | N/A | risk of False positive | 10 | 10 | 16 | 6 | 2023-06-09T12:39:00Z | 2023-06-09T09:19:10Z | 47666 |
| 1051 | *https://api.tailscale.com/api/v2/* | .{0,1000}https\:\/\/api\.tailscale\.com\/api\/v2\/.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47668 |
| 1052 | *https://api.telegram.org/bot*/sendMessage* | .{0,1000}https\:\/\/api\.telegram\.org\/bot.{0,1000}\/sendMessage.{0,1000} | greyware_tool_keyword | TelegramRAT | Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions | T1071.001 - T1105 - T1027 | TA0011 - TA0005 - TA0002 | N/A | N/A | C2 | https://github.com/machine1337/TelegramRAT | 1 | 1 | N/A | N/A | 10 | 10 | 372 | 62 | 2024-01-23T12:05:59Z | 2023-06-30T10:59:55Z | 47669 |
| 1053 | *https://app.action1.com/agent/*/Windows/*.msi* | .{0,1000}https\:\/\/app\.action1\.com\/agent\/.{0,1000}\/Windows\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | action1 | Action1 remote administration tool abused buy attacker | T1021 - T1071 - T1090 | TA0008 - TA0011 | N/A | LockBit - MONTI | RMM | https://app.action1.com/ | 1 | 1 | N/A | https://app.action1.com/agent/{ID}/Windows/agent(My_Organization).msi | 10 | 10 | N/A | N/A | N/A | N/A | 47670 |
| 1054 | *https://app.level.io/devices* | .{0,1000}https\:\/\/app\.level\.io\/devices.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47671 |
| 1055 | *https://apps.apple.com/us/app/tailscale/id* | .{0,1000}https\:\/\/apps\.apple\.com\/us\/app\/tailscale\/id.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | #macos | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47672 |
| 1056 | *https://assist.zoho.com/assist-join?key=* | .{0,1000}https\:\/\/assist\.zoho\.com\/assist\-join\?key\=.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47673 |
| 1057 | *https://assist.zoho.com/customer-session-details?client_token=* | .{0,1000}https\:\/\/assist\.zoho\.com\/customer\-session\-details\?client_token\=.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47674 |
| 1058 | *https://assist.zoho.com/join?join_source=EMAIL_INVITE* | .{0,1000}https\:\/\/assist\.zoho\.com\/join\?join_source\=EMAIL_INVITE.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47675 |
| 1059 | *https://assist.zoho.com/join-session?key=* | .{0,1000}https\:\/\/assist\.zoho\.com\/join\-session\?key\=.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47676 |
| 1060 | *https://assist.zoho.com/org/* | .{0,1000}https\:\/\/assist\.zoho\.com\/org\/.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47677 |
| 1061 | *https://assist.zoho.com/viewer-assist* | .{0,1000}https\:\/\/assist\.zoho\.com\/viewer\-assist.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47678 |
| 1062 | *https://aur.archlinux.org/jprq.git* | .{0,1000}https\:\/\/aur\.archlinux\.org\/jprq\.git.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | #linux | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 47679 |
| 1063 | *https://bashupload.com* | .{0,1000}https\:\/\/bashupload\.com.{0,1000} | greyware_tool_keyword | bashupload.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47683 |
| 1064 | *https://bayfiles.com/* | .{0,1000}https\:\/\/bayfiles\.com\/.{0,1000} | greyware_tool_keyword | bayfiles | hosting site abused by attackers - blocked site in a lot of countries | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | CyClops | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47684 |
| 1065 | *https://bitbucket.org/*/downloads/*.bat* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47688 |
| 1066 | *https://bitbucket.org/*/downloads/*.dll* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47689 |
| 1067 | *https://bitbucket.org/*/downloads/*.dll* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47690 |
| 1068 | *https://bitbucket.org/*/downloads/*.exe* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47691 |
| 1069 | *https://bitbucket.org/*/downloads/*.ps1* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47692 |
| 1070 | *https://bitbucket.org/*/downloads/*.rar* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47693 |
| 1071 | *https://bitbucket.org/*/downloads/*.zip* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47694 |
| 1072 | *https://boringproxy.io/installation* | .{0,1000}https\:\/\/boringproxy\.io\/installation.{0,1000} | greyware_tool_keyword | boringproxy | Simple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/boringproxy/boringproxy | 1 | 1 | N/A | N/A | 10 | 10 | 1276 | 121 | 2024-07-06T10:13:37Z | 2020-09-26T21:58:07Z | 47702 |
| 1073 | *https://browser.lol/vnc?server=* | .{0,1000}https\:\/\/browser\.lol\/vnc\?server\=.{0,1000} | greyware_tool_keyword | browser.lol | Virtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environment | T1071 - T1090 - T1562 | TA0005 | N/A | N/A | Defense Evasion | https://browser.lol | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 47703 |
| 1074 | *https://burrow.io/tunnels* | .{0,1000}https\:\/\/burrow\.io\/tunnels.{0,1000} | greyware_tool_keyword | burrow | Expose localhost to the internet using a public URL | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://burrow.io | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 47707 |
| 1075 | *https://c3pool.com/#/* | .{0,1000}https\:\/\/c3pool\.com\/\#\/.{0,1000} | greyware_tool_keyword | xmrig | Auto setup scripts and pre-compiled xmr miner for c3pool.com pool | T1496 - T1057 | TA0004 - TA0007 | N/A | Pacha Group - APT4 | Cryptomining | https://github.com/C3Pool/xmrig_setup/ | 1 | 1 | N/A | N/A | 9 | 1 | 27 | 21 | 2024-11-05T05:34:20Z | 2020-05-16T13:01:30Z | 47709 |
| 1076 | *https://clbin.com/* | .{0,1000}https\:\/\/clbin\.com\/.{0,1000} | greyware_tool_keyword | clbin.com | clbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands. | T1567.002 | TA0010 - TA0009 | N/A | N/A | Data Exfiltration | https://clbin.com/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47711 |
| 1077 | *https://cloud.screenconnect.com/#/trialtoinstance?cookieValue=* | .{0,1000}https\:\/\/cloud\.screenconnect\.com\/\#\/trialtoinstance\?cookieValue\=.{0,1000} | greyware_tool_keyword | ScreenConnect | ConnectWise Control formerly known as Screenconnect is a remote desktop software application. | T1021.001 - T1133 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Black Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater | RMM | https://screenconnect.connectwise.com/download | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47712 |
| 1078 | *https://content.dropboxapi.com/2/files/upload* | .{0,1000}https\:\/\/content\.dropboxapi\.com\/2\/files\/upload.{0,1000} | greyware_tool_keyword | dropbox | uploading file to dropbox with the API | T1105 - T1071.001 - T1567.002 | TA0011 - TA0009 - TA0010 | N/A | BlackCat - Scattered Spider* - Operation BugDrop - COZY BEAR - Turla - LockBit - Pandora | Data Exfiltration | https://github.com/I-Am-Jakoby/PowerShell-for-Hackers/blob/main/Functions/DropBox-Upload.md | 1 | 1 | #filehostingservice | N/A | 7 | 10 | 1249 | 146 | 2024-06-16T04:10:39Z | 2022-05-10T04:12:53Z | 47719 |
| 1079 | *https://crates.io/crates/localtunnel-client* | .{0,1000}https\:\/\/crates\.io\/crates\/localtunnel\-client.{0,1000} | greyware_tool_keyword | Rust Localtunnels | Localtunnel implementation in Rust - exposes your localhost endpoint to the world | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/kaichaosun/rlt | 1 | 1 | N/A | N/A | 7 | 2 | 119 | 13 | 2024-12-16T09:09:34Z | 2022-06-27T05:57:34Z | 47723 |
| 1080 | *https://crates.io/crates/localtunnel-server* | .{0,1000}https\:\/\/crates\.io\/crates\/localtunnel\-server.{0,1000} | greyware_tool_keyword | Rust Localtunnels | Localtunnel implementation in Rust - exposes your localhost endpoint to the world | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/kaichaosun/rlt | 1 | 1 | N/A | N/A | 7 | 2 | 119 | 13 | 2024-12-16T09:09:34Z | 2022-06-27T05:57:34Z | 47724 |
| 1081 | *https://docs.level.io/1.0/admin-guides/level-watchdog-task* | .{0,1000}https\:\/\/docs\.level\.io\/1\.0\/admin\-guides\/level\-watchdog\-task.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47738 |
| 1082 | *https://download.advanced-ip-scanner.com/download/files/*.exe* | .{0,1000}https\:\/\/download\.advanced\-ip\-scanner\.com\/download\/files\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 47740 |
| 1083 | *https://downloads.level.io/install_linux.sh* | .{0,1000}https\:\/\/downloads\.level\.io\/install_linux\.sh.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47742 |
| 1084 | *https://downloads.level.io/install_mac_os.sh* | .{0,1000}https\:\/\/downloads\.level\.io\/install_mac_os\.sh.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47743 |
| 1085 | *https://downloads.level.io/install_windows.exe* | .{0,1000}https\:\/\/downloads\.level\.io\/install_windows\.exe.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47744 |
| 1086 | *https://downloads.level.io/stable/level-linux-amd64* | .{0,1000}https\:\/\/downloads\.level\.io\/stable\/level\-linux\-amd64.{0,1000} | greyware_tool_keyword | level.io | Level is reinventing remote monitoring and management | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* - Black Basta | RMM | https://level.io/ | 1 | 1 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47745 |
| 1087 | *https://downloads.solarwinds.com/solarwinds/Release/DameWare/* | .{0,1000}https\:\/\/downloads\.solarwinds\.com\/solarwinds\/Release\/DameWare\/.{0,1000} | greyware_tool_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 1 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 47746 |
| 1088 | *https://dropmefiles.com/* | .{0,1000}https\:\/\/dropmefiles\.com\/.{0,1000} | greyware_tool_keyword | dropmefiles.com | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Mallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice Society | Collection | https://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C48 | 1 | 1 | #filehostingservice | downloading files url | 8 | 6 | 504 | 51 | 2025-04-19T17:43:15Z | 2023-05-02T16:17:48Z | 47749 |
| 1089 | *https://dropmefiles.com/s3/upload/* | .{0,1000}https\:\/\/dropmefiles\.com\/s3\/upload\/.{0,1000} | greyware_tool_keyword | dropmefiles.com | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Mallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice Society | Data Exfiltration | https://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C48 | 1 | 1 | #filehostingservice | uploading files url | 10 | 6 | 504 | 51 | 2025-04-19T17:43:15Z | 2023-05-02T16:17:48Z | 47750 |
| 1090 | *https://easyupload.io/* | .{0,1000}https\:\/\/easyupload\.io\/.{0,1000} | greyware_tool_keyword | easyupload.io | file hosting platform abused by attackers to host malicious - url used when downloading a file on the site | T1567.002 - T1071.001 - T1041 - T1036.002 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47751 |
| 1091 | *https://easyupload.io/action.php* | .{0,1000}https\:\/\/easyupload\.io\/action\.php.{0,1000} | greyware_tool_keyword | easyupload.io | hosting platform abused by attackers | T1105 - T1071.001 - T1567.002 - T1041 | TA0010 - TA0005 | N/A | Akira | Data Exfiltration | N/A | 1 | 1 | #filehostingservice | uploading url | 8 | 6 | N/A | N/A | N/A | N/A | 47752 |
| 1092 | *https://easyupload.io/cdn-cgi/rum* | .{0,1000}https\:\/\/easyupload\.io\/cdn\-cgi\/rum.{0,1000} | greyware_tool_keyword | easyupload.io | hosting platform abused by attackers | T1105 - T1071.001 - T1567.002 - T1041 | TA0010 - TA0005 | N/A | Akira | Data Exfiltration | N/A | 1 | 1 | #filehostingservice | uploading url | 8 | 6 | N/A | N/A | N/A | N/A | 47753 |
| 1093 | *https://expose.dev/api/servers* | .{0,1000}https\:\/\/expose\.dev\/api\/servers.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 47757 |
| 1094 | *https://expose.dev/register* | .{0,1000}https\:\/\/expose\.dev\/register.{0,1000} | greyware_tool_keyword | expose | tunneling service - written in pure PHP | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/beyondcode/expose | 1 | 1 | N/A | N/A | 10 | 10 | 4367 | 280 | 2025-04-04T13:57:03Z | 2020-04-14T19:18:38Z | 47758 |
| 1095 | *https://file.io/* | .{0,1000}https\:\/\/file\.io\/.{0,1000} | greyware_tool_keyword | file.io | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - Conti | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47761 |
| 1096 | *https://file.io/?title=* | .{0,1000}https\:\/\/file\.io\/\?title\=.{0,1000} | greyware_tool_keyword | file.io | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - Conti | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47762 |
| 1097 | *https://filebin.net/* | .{0,1000}https\:\/\/filebin\.net\/.{0,1000} | greyware_tool_keyword | filebin.net | file hosting platform abused by attackers to host malicious file - raw access and api available | T1119 | TA0009 - TA0010 | N/A | N/A | Collection | https://filebin.net | 1 | 1 | #filehostingservice | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47763 |
| 1098 | *https://files.catbox.moe/* | https:\/\/files\.catbox\.moe\/[^\s\n]+ | greyware_tool_keyword | catbox.moe | The cutest free file host you've ever seen - abused by threat actors | T1560.001 - T1190 - T1102 - T1027.002 | TA0001 - TA0005 - TA0042 | N/A | N/A | Collection | https://files[.]catbox.moe | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47764 |
| 1099 | *https://fleetdm.com/resources/install-fleetctl.sh* | .{0,1000}https\:\/\/fleetdm\.com\/resources\/install\-fleetctl\.sh.{0,1000} | greyware_tool_keyword | fleetdm | Manage everything in one place | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://github.com/fleetdm/fleet | 1 | 1 | N/A | N/A | 10 | 10 | 4896 | 558 | 2025-04-22T21:05:02Z | 2020-11-03T22:17:18Z | 47765 |
| 1100 | *https://freefilesync.org/donate* | .{0,1000}https\:\/\/freefilesync\.org\/donate.{0,1000} | greyware_tool_keyword | freefilesync | freefilesync is a backup and file synchronization program abused by attacker for data exfiltration | T1567.002 - T1020 - T1039 | TA0010 | N/A | LockBit | Data Exfiltration | https://freefilesync.org/download.php | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47768 |
| 1101 | *https://get.telebit.io* | .{0,1000}https\:\/\/get\.telebit\.io.{0,1000} | greyware_tool_keyword | telebit.cloud | Access your devices - Share your stuff (shell from telebit.cloud) | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://telebit.cloud/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47769 |
| 1102 | *https://github.com/mandiant/SilkETW/releases/download/v0.8/SilkETW_SilkService_v8.zip* | .{0,1000}https\:\/\/github\.com\/mandiant\/SilkETW\/releases\/download\/v0\.8\/SilkETW_SilkService_v8\.zip.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 1 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 47778 |
| 1103 | *https://github-com.translate.goog/* | .{0,1000}https\:\/\/github\-com\.translate\.goog\/.{0,1000} | greyware_tool_keyword | translate.goog | accessing github through google translate (evasion) false positive risk | T1090.003 | TA0005 | N/A | N/A | Defense Evasion | https://*-com.translate.goog/* | 0 | 1 | N/A | N/A | 1 | 3 | N/A | N/A | N/A | N/A | 47782 |
| 1104 | *https://gofile.io/d/* | .{0,1000}https\:\/\/gofile\.io\/d\/.{0,1000} | greyware_tool_keyword | ransomware_notes | detection patterns retrieved in ransomware notes archives | T1486 | TA0040 | N/A | N/A | Ransomware | https://github.com/threatlabz/ransomware_notes | 1 | 1 | N/A | downloading files from gofile.io | 10 | 4 | 354 | 55 | 2025-04-04T19:06:04Z | 2022-08-01T15:14:59Z | 47785 |
| 1105 | *https://googleweblight.com/i?u=*ipfs.*.html* | .{0,1000}https\:\/\/googleweblight\.com\/i\?u\=.{0,1000}ipfs\..{0,1000}\.html.{0,1000} | greyware_tool_keyword | googleweblight.com | Open Redirect vulnerability being exploited by threat actors in Google Web Light | T1584.001 - T1534 | TA0008 | N/A | N/A | Phishing | https://x.com/1ZRR4H/status/1723062039680000255 | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47786 |
| 1106 | *https://gost.run/tutorials/* | .{0,1000}https\:\/\/gost\.run\/tutorials\/.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 47787 |
| 1107 | *https://gost.run/tutorials/api/config* | .{0,1000}https\:\/\/gost\.run\/tutorials\/api\/config.{0,1000} | greyware_tool_keyword | gost | GO Simple Tunnel - a simple tunnel written in golang | T1572 | TA0011 - TA0003 | N/A | Dispossessor - EMBER BEAR | C2 | https://github.com/go-gost/gost | 1 | 1 | N/A | N/A | 10 | 10 | 4986 | 573 | 2025-02-18T15:35:15Z | 2020-02-12T14:58:08Z | 47788 |
| 1108 | *https://homeway.io/install.sh* | .{0,1000}https\:\/\/homeway\.io\/install\.sh.{0,1000} | greyware_tool_keyword | homeway.io | Expose local servers to the internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://homeway.io/ | 1 | 1 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47795 |
| 1109 | *https://hunter.io/* | .{0,1000}https\:\/\/hunter\.io\/.{0,1000} | greyware_tool_keyword | Hunter.io | used by attacker and pentester while gathering information. Hunter lets you find email addresses in seconds and connect with the people that matter for your business | T1597 - T1526 - T1087 - T1078 - T1056 - T1018 - T1016 - T1583 - T1589 | TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Reconnaissance | https://hunter.io/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 47796 |
| 1110 | *https://hypertunnel.ga* | .{0,1000}https\:\/\/hypertunnel\.ga.{0,1000} | greyware_tool_keyword | hypertunnel | Expose any local TCP/IP service on the internet | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/berstend/hypertunnel | 1 | 1 | N/A | N/A | 10 | 10 | 248 | 47 | 2022-12-08T19:13:24Z | 2018-06-11T05:29:58Z | 47797 |
| 1111 | *https://ip138.com/iplookup.asp?ip=*&action=2* | .{0,1000}https\:\/\/ip138\.com\/iplookup\.asp\?ip\=.{0,1000}\&action\=2.{0,1000} | greyware_tool_keyword | anyviewer | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyviewer.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47799 |
| 1112 | *https://ipv4.myip.wtf/text* | .{0,1000}https\:\/\/ipv4\.myip\.wtf\/text.{0,1000} | greyware_tool_keyword | ipv4.myip.wtf | get public ip address. Used by disctopia-c2 | T1016 - T1071.001 | TA0005 - TA0002 | N/A | N/A | Reconnaissance | https://github.com/3ct0s/disctopia-c2/blob/main/libraries/disctopia.py | 1 | 1 | N/A | greyware_tools high risks of false positives | N/A | 10 | 609 | 139 | 2024-07-18T10:16:19Z | 2022-01-02T22:03:10Z | 47800 |
| 1113 | *https://jprq.io/auth* | .{0,1000}https\:\/\/jprq\.io\/auth.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 47803 |
| 1114 | *https://jprq.io/install.sh* | .{0,1000}https\:\/\/jprq\.io\/install\.sh.{0,1000} | greyware_tool_keyword | jprq | expose TCP protocols such as HTTP - SSH etc. Any server! | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/azimjohn/jprq | 1 | 1 | N/A | N/A | 10 | 10 | 1301 | 178 | 2025-03-24T21:45:09Z | 2020-04-18T10:12:42Z | 47804 |
| 1115 | *https://link.remote.it/support/rpi-linux-quick-install* | .{0,1000}https\:\/\/link\.remote\.it\/support\/rpi\-linux\-quick\-install.{0,1000} | greyware_tool_keyword | remoteit | Expose localhost to internet | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/remoteit/installer | 1 | 1 | #linux | N/A | 10 | 10 | 24 | 9 | 2024-04-17T00:45:45Z | 2019-01-29T21:06:02Z | 47807 |
| 1116 | *https://localtunnel.me* | .{0,1000}https\:\/\/localtunnel\.me.{0,1000} | greyware_tool_keyword | localtunnel | localtunnel exposes your localhost to the world | T1021 - T1090 - T1573 - T1219 - T1562.001 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/localtunnel/localtunnel | 1 | 1 | N/A | N/A | 10 | 10 | 20558 | 1428 | 2024-03-20T17:04:54Z | 2012-06-18T02:33:30Z | 47809 |
| 1117 | *https://localtunnel.me* | .{0,1000}https\:\/\/localtunnel\.me.{0,1000} | greyware_tool_keyword | localtunnels | server for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharing | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/localtunnel/server | 1 | 1 | N/A | N/A | 8 | 10 | 3163 | 1033 | 2024-03-20T09:14:46Z | 2013-06-16T22:30:48Z | 47810 |
| 1118 | *https://localxpose.io/download* | .{0,1000}https\:\/\/localxpose\.io\/download.{0,1000} | greyware_tool_keyword | localxpose | LocalXpose is a reverse proxy that enables you to expose your localhost to the internet | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://localxpose.io/ | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 47811 |
| 1119 | *https://login.remotepc.com/rpcnew* | .{0,1000}https\:\/\/login\.remotepc\.com\/rpcnew.{0,1000} | greyware_tool_keyword | RemotePC | RemotePC Remote administration tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotepc.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47812 |
| 1120 | *https://login.tailscale.com/admin/settings/keys* | .{0,1000}https\:\/\/login\.tailscale\.com\/admin\/settings\/keys.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47813 |
| 1121 | *https://maildrop.cc/inbox/?mailbox=* | .{0,1000}https\:\/\/maildrop\.cc\/inbox\/\?mailbox\=.{0,1000} | greyware_tool_keyword | maildrop | disposable email address to use anytime. | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | https://maildrop.cc/ | 1 | 1 | N/A | N/A | 4 | 5 | N/A | N/A | N/A | N/A | 47814 |
| 1122 | *https://media.discordapp.net/attachments/*.bat* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47821 |
| 1123 | *https://media.discordapp.net/attachments/*.exe* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47822 |
| 1124 | *https://media.discordapp.net/attachments/*.hta* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47823 |
| 1125 | *https://media.discordapp.net/attachments/*.iso* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47824 |
| 1126 | *https://media.discordapp.net/attachments/*.jar* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47825 |
| 1127 | *https://media.discordapp.net/attachments/*.msi* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47826 |
| 1128 | *https://media.discordapp.net/attachments/*.py* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47827 |
| 1129 | *https://media.discordapp.net/attachments/*.vbs* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47828 |
| 1130 | *https://media.discordapp.net/attachments/*.zip* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47829 |
| 1131 | *https://mega.io/cmd#download* | .{0,1000}https\:\/\/mega\.io\/cmd\#download.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47831 |
| 1132 | *https://mega.nz/file/* | .{0,1000}https\:\/\/mega\.nz\/file\/.{0,1000} | greyware_tool_keyword | mega.nz | Direct file download links on Mega.nz - file sharing activity often abused by attackers for Collection | T1105 - T1114 - T1083 | TA0009 | N/A | Akira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice #P2P | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47832 |
| 1133 | *https://mega.nz/folder/* | .{0,1000}https\:\/\/mega\.nz\/folder\/.{0,1000} | greyware_tool_keyword | mega.nz | Direct folder sharing links on Mega.nz for accessing multiple files - file sharing activity often abused by attackers for Collection | T1105 - T1114 - T1083 | TA0009 | N/A | Akira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice #P2P | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47833 |
| 1134 | *https://mega.nz/folder/8L80QKyL#glRTp6Zc0gppwp03IG03tA* | .{0,1000}https\:\/\/mega\.nz\/folder\/8L80QKyL\#glRTp6Zc0gppwp03IG03tA.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47834 |
| 1135 | *https://mega.nz/folder/bxomFKwL#3V1dUJFzL98t1GqXX29IXg* | .{0,1000}https\:\/\/mega\.nz\/folder\/bxomFKwL\#3V1dUJFzL98t1GqXX29IXg.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47835 |
| 1136 | *https://mega.nz/folder/D0w0nYiY#egvjqP5R-anbBdsJg8QRVg* | .{0,1000}https\:\/\/mega\.nz\/folder\/D0w0nYiY\#egvjqP5R\-anbBdsJg8QRVg.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47836 |
| 1137 | *https://mega.nz/folder/gflVFLhC#6neMkeJrt4dWboRTc1NLUg* | .{0,1000}https\:\/\/mega\.nz\/folder\/gflVFLhC\#6neMkeJrt4dWboRTc1NLUg.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | N/A | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47837 |
| 1138 | *https://mega.nz/linux/repo/* | .{0,1000}https\:\/\/mega\.nz\/linux\/repo\/.{0,1000} | greyware_tool_keyword | MEGAsync | synchronize or backup your computers to MEGA | T1567.002 - T1537 - T1020 - T1030 | TA0010 - TA0040 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://mega.io/en/desktop | 1 | 1 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47838 |
| 1139 | *https://mega.nz/linux/repo/*.deb* | .{0,1000}https\:\/\/mega\.nz\/linux\/repo\/.{0,1000}\.deb.{0,1000} | greyware_tool_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 1 | #linux | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 47839 |
| 1140 | *https://meshcentral.com/login* | .{0,1000}https\:\/\/meshcentral\.com\/login.{0,1000} | greyware_tool_keyword | meshcentral | MeshCentral is a full computer management web site - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | https://github.com/Ylianst/MeshAgent | 1 | 1 | N/A | N/A | 10 | 3 | 264 | 96 | 2025-03-19T18:43:56Z | 2017-10-12T21:26:52Z | 47840 |
| 1141 | *https://myexternalip.com/raw* | .{0,1000}https\:\/\/myexternalip\.com\/raw.{0,1000} | greyware_tool_keyword | myexternalip.com | return external ip address | T1046 - T1595 - T1595.001 | TA0007 - TA0040 | N/A | N/A | Reconnaissance | https://myexternalip.com/raw | 1 | 1 | N/A | False positives warning - used by some C2 projects but legitimate site | 1 | 6 | N/A | N/A | N/A | N/A | 47844 |
| 1142 | *https://new.express.adobe.com/publishedV2/urn:aaid:sc:* | .{0,1000}https\:\/\/new\.express\.adobe\.com\/publishedV2\/urn\:aaid\:sc\:.{0,1000} | greyware_tool_keyword | adobe.com | Attackers can use adobe.com to masquerade their domain for phishing purposes. | T1204.002 - T1036 - T1566.002 | TA0001 - TA0005 | N/A | N/A | Defense Evasion | N/A | 0 | 1 | N/A | N/A | 1 | 1 | N/A | N/A | N/A | N/A | 47846 |
| 1143 | *https://nopaste.net/* | .{0,1000}https\:\/\/nopaste\.net\/.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Data Exfiltration | https://www.shellhub.io/ | 1 | 1 | #Pastebinlike #filehostingservice | monitor PUT requests for data exfiltration | 8 | 10 | N/A | N/A | N/A | N/A | 47847 |
| 1144 | *https://nordvpn.com*/ovpn/*.ovpn* | .{0,1000}https\:\/\/nordvpn\.com.{0,1000}\/ovpn\/.{0,1000}\.ovpn.{0,1000} | greyware_tool_keyword | NordVPN | OVPN configuration for nordvpn accessed within corporate network | T1090.003 - T1133 - T1572 | TA0003 - TA0001 - TA0011 - TA0010 - TA0005 | N/A | N/A | Data Exfiltration | https://nordvpn.com | 0 | 1 | #VPN | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47848 |
| 1145 | *https://nsproducts.azureedge.net/nsm-*/NetSupport* | .{0,1000}https\:\/\/nsproducts\.azureedge\.net\/nsm\-.{0,1000}\/NetSupport.{0,1000} | greyware_tool_keyword | NetSupport | NetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillance | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Cuba - EvilCorp* - Black Basta - Moskalvzapoe | RMM | https://www.netsupportmanager.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47852 |
| 1146 | *https://oshi.at/* | .{0,1000}https\:\/\/oshi\.at\/.{0,1000} | greyware_tool_keyword | OshiUpload | Ephemeral file sharing engine | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | Black Basta | Data Exfiltration | https://github.com/somenonymous/OshiUpload | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 2 | 195 | 25 | 2025-04-02T12:44:45Z | 2019-05-11T02:08:51Z | 47855 |
| 1147 | *https://pagekite.net/downloads/* | .{0,1000}https\:\/\/pagekite\.net\/downloads\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 47856 |
| 1148 | *https://pagekite.net/pk/src/* | .{0,1000}https\:\/\/pagekite\.net\/pk\/src\/.{0,1000} | greyware_tool_keyword | PyPagekite | This is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet. | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/pagekite/PyPagekite | 1 | 1 | N/A | N/A | 10 | 10 | 730 | 123 | 2025-04-16T15:26:26Z | 2010-10-23T00:03:37Z | 47857 |
| 1149 | *https://portal.ehorus.com/#/agents/* | .{0,1000}https\:\/\/portal\.ehorus\.com\/\#\/agents\/.{0,1000} | greyware_tool_keyword | EHORUS RMM | Pandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC) | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Blacksuit - Royal | RMM | https://pandorafms.com/en/remote-control/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47870 |
| 1150 | *https://portal.xeox.com/* | .{0,1000}https\:\/\/portal\.xeox\.com\/.{0,1000} | greyware_tool_keyword | xeox | Easily access and manage Windows devices remotely within XEOX - RMM abused by threat actors | T1021 - T1078 - T1219 - T1105 - T1046 | TA0011 - TA0010 - TA0003 - TA0005 | N/A | Dispossessor | RMM | https://xeox.com/remote-access/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47871 |
| 1151 | *https://portr.dev/client/installation/* | .{0,1000}https\:\/\/portr\.dev\/client\/installation\/.{0,1000} | greyware_tool_keyword | Portr | Portr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internet | T1572 - T1090 | TA0011 - TA0005 | N/A | N/A | C2 | https://github.com/amalshaji/portr | 1 | 1 | N/A | N/A | 10 | 10 | 2409 | 72 | 2025-04-17T16:06:58Z | 2023-11-21T11:14:01Z | 47872 |
| 1152 | *https://privatebin.net/* | .{0,1000}https\:\/\/privatebin\.net\/.{0,1000} | greyware_tool_keyword | privatebin.net | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with Black Basta victims | T1071.001 - T1567.002 - T1005 | TA0010 - TA0009 | N/A | Black Basta | Data Exfiltration | N/A | 0 | 1 | #PastebinLike | N/A | 5 | 6 | N/A | N/A | N/A | N/A | 47873 |
| 1153 | *https://privatix-temp-mail-v1.p.rapidapi.com/request/domains/* | .{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/domains\/.{0,1000} | greyware_tool_keyword | temp-mail | using the API of a disposable email address to use anytime - could be abused by malicious actors | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | temp-mail.org | 1 | 1 | N/A | api doc https://rapidapi.com/Privatix/api/temp-mail | 9 | 10 | N/A | N/A | N/A | N/A | 47875 |
| 1154 | *https://privatix-temp-mail-v1.p.rapidapi.com/request/mail/id/null/* | .{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/mail\/id\/null\/.{0,1000} | greyware_tool_keyword | temp-mail | using the API of a disposable email address to use anytime - could be abused by malicious actors | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | temp-mail.org | 1 | 1 | N/A | api doc https://rapidapi.com/Privatix/api/temp-mail | 9 | 10 | N/A | N/A | N/A | N/A | 47877 |
| 1155 | *https://privnote.com/* | .{0,1000}https\:\/\/privnote\.com\/.{0,1000} | greyware_tool_keyword | privnote.com | temporary notes service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Akira - Black Basta | Collection | https://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Akira/20240620.json#L31C27-L31C48 | 1 | 1 | #PastebinLike | downloading files url | 5 | 6 | 504 | 51 | 2025-04-19T17:43:15Z | 2023-05-02T16:17:48Z | 47878 |
| 1156 | *https://pubsub.zoho.com/*_deskUserPresence/pubsub* | .{0,1000}https\:\/\/pubsub\.zoho\.com\/.{0,1000}_deskUserPresence\/pubsub.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47881 |
| 1157 | *https://put.io/?login* | .{0,1000}https\:\/\/put\.io\/\?login.{0,1000} | greyware_tool_keyword | put.io | A storage and torrenting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | Scattered Spider - RagnarLocker - Medusa | Data Exfiltration | https://put.i | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47882 |
| 1158 | *https://put.io/default/magnet?url=* | .{0,1000}https\:\/\/put\.io\/default\/magnet\?url\=.{0,1000} | greyware_tool_keyword | put.io | A storage and torrenting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | Scattered Spider - RagnarLocker - Medusa | Collection | https://put.i | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47883 |
| 1159 | *https://put.io/transfers* | .{0,1000}https\:\/\/put\.io\/transfers.{0,1000} | greyware_tool_keyword | put.io | A storage and torrenting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | Scattered Spider - RagnarLocker - Medusa | Data Exfiltration | https://put.i | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47884 |
| 1160 | *https://put.io/v2/oauth2/register* | .{0,1000}https\:\/\/put\.io\/v2\/oauth2\/register.{0,1000} | greyware_tool_keyword | put.io | A storage and torrenting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | Scattered Spider - RagnarLocker - Medusa | Data Exfiltration | https://put.i | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47885 |
| 1161 | *https://qaz.im/* | .{0,1000}https\:\/\/qaz\.im\/.{0,1000} | greyware_tool_keyword | qaz.im | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Data Exfiltration | https://qaz.im/ | 1 | 1 | #filehostingservice | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47889 |
| 1162 | *https://qaz.im/load/* | .{0,1000}https\:\/\/qaz\.im\/load\/.{0,1000} | greyware_tool_keyword | qaz.im | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.im/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47890 |
| 1163 | *https://qaz.im/zaq/* | .{0,1000}https\:\/\/qaz\.im\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.im | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.im/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47891 |
| 1164 | *https://qaz.is/* | .{0,1000}https\:\/\/qaz\.is\/.{0,1000} | greyware_tool_keyword | qaz.is | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Data Exfiltration | https://qaz.is/ | 1 | 1 | #filehostingservice | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47892 |
| 1165 | *https://qaz.is/load/* | .{0,1000}https\:\/\/qaz\.is\/load\/.{0,1000} | greyware_tool_keyword | qaz.is | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.is/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47893 |
| 1166 | *https://qaz.is/zaq/* | .{0,1000}https\:\/\/qaz\.is\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.is | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.is/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47894 |
| 1167 | *https://qaz.su* | .{0,1000}https\:\/\/qaz\.su.{0,1000} | greyware_tool_keyword | qaz.su | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Data Exfiltration | https://qaz.su/ | 1 | 1 | #filehostingservice | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47895 |
| 1168 | *https://qaz.su/load/* | .{0,1000}https\:\/\/qaz\.su\/load\/.{0,1000} | greyware_tool_keyword | qaz.su | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.su/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47896 |
| 1169 | *https://qaz.su/zaq/* | .{0,1000}https\:\/\/qaz\.su\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.su | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.su/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47897 |
| 1170 | *https://qu.ax/*.* | https\:\/\/qu\.ax\/[^\s\n]+ | greyware_tool_keyword | qu.ax | qu.ax is a quick and private file hosting service - abused by threat actors | T1560.001 - T1190 - T1102 - T1027.002 | TA0001 - TA0005 - TA0042 | N/A | N/A | Collection | https://qu[.]ax/ | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47898 |
| 1171 | *https://rclone.org/install.sh* | .{0,1000}https\:\/\/rclone\.org\/install\.sh.{0,1000} | greyware_tool_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 1 | N/A | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 47906 |
| 1172 | *https://rdprelay*.support.services.microsoft.com* | .{0,1000}https\:\/\/rdprelay.{0,1000}\.support\.services\.microsoft\.com.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 47907 |
| 1173 | *https://remoteassistance.support.services.microsoft.com/* | .{0,1000}https\:\/\/remoteassistance\.support\.services\.microsoft\.com\/.{0,1000} | greyware_tool_keyword | QuickAssist | Sharing remote desktop with Microsoft Quick assit | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | LokiBot | Black Basta | RMM | https://apps.microsoft.com/detail/9p7bp5vnwkx5 | 1 | 1 | N/A | Quick assist could be preinstalled in some Windows versions | 10 | 10 | N/A | N/A | N/A | N/A | 47909 |
| 1174 | *https://remotedesktop.google.com/_/oauthredirect* | .{0,1000}https\:\/\/remotedesktop\.google\.com\/_\/oauthredirect.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47910 |
| 1175 | *https://remotedesktop.google.com/headless* | .{0,1000}https\:\/\/remotedesktop\.google\.com\/headless.{0,1000} | greyware_tool_keyword | Google Remote Desktop | Google Chrome Remote Desktop to access remote computers - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://remotedesktop.google.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47911 |
| 1176 | *https://rentry.co/* | .{0,1000}https\:\/\/rentry\.co\/.{0,1000} | greyware_tool_keyword | rentry.co | accessing a pastebinlike site - often abused by malware | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 5 | 8 | N/A | N/A | N/A | N/A | 47912 |
| 1177 | *https://rentry.co/*/raw* | .{0,1000}https\:\/\/rentry\.co\/.{0,1000}\/raw.{0,1000} | greyware_tool_keyword | rentry.co | raw format paste access attempt - abused by attackers to store malicious payloads | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47913 |
| 1178 | *https://rentry.co/cdn-cgi/challenge-platform/* | .{0,1000}https\:\/\/rentry\.co\/cdn\-cgi\/challenge\-platform\/.{0,1000} | greyware_tool_keyword | rentry.co | raw format paste access attempt - abused by attackers to store malicious payloads | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47914 |
| 1179 | *https://requestbin.net/r/* | .{0,1000}https\:\/\/requestbin\.net\/r\/.{0,1000} | greyware_tool_keyword | requestbin.net | allows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloads | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | http://requestbin.net | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | N/A | N/A | N/A | N/A | 47915 |
| 1180 | *https://s3.amazonaws.com/sshx/sshx-* | .{0,1000}https\:\/\/s3\.amazonaws\.com\/sshx\/sshx\-.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 47916 |
| 1181 | *https://s3.filebin.net/filebin/* | .{0,1000}https\:\/\/s3\.filebin\.net\/filebin\/.{0,1000} | greyware_tool_keyword | filebin.net | file hosting platform abused by attackers to host malicious file - raw access and api available | T1119 | TA0009 | N/A | N/A | Collection | https://filebin.net | 1 | 1 | #filehostingservice | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47917 |
| 1182 | *https://secure.logmeinrescue.com/R?i=2&Code=* | .{0,1000}https\:\/\/secure\.logmeinrescue\.com\/R\?i\=2\&Code\=.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47919 |
| 1183 | *https://secure.logmeinrescue.com/TechnicianConsole/Launch* | .{0,1000}https\:\/\/secure\.logmeinrescue\.com\/TechnicianConsole\/Launch.{0,1000} | greyware_tool_keyword | LogMeIn | LogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | BlackSuit - Royal - Trigona - Yanluowang | RMM | https://www.logmein.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47920 |
| 1184 | *https://send.exploit.in/api/download* | .{0,1000}https\:\/\/send\.exploit\.in\/api\/download.{0,1000} | greyware_tool_keyword | send.exploit.in | downloading files - hosting service frequently exploited by attackers - should be blocked | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | LockBit - Hive - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47921 |
| 1185 | *https://send.exploit.in/api/info/* | .{0,1000}https\:\/\/send\.exploit\.in\/api\/info\/.{0,1000} | greyware_tool_keyword | send.exploit.in | uploading files - hosting service frequently exploited by attackers - should be blocked | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | LockBit - Hive - Black Basta | Data Exfiltration | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47922 |
| 1186 | *https://send.exploit.in/api/metadata/* | .{0,1000}https\:\/\/send\.exploit\.in\/api\/metadata\/.{0,1000} | greyware_tool_keyword | send.exploit.in | uploading files - hosting service frequently exploited by attackers - should be blocked | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | LockBit - Hive - Black Basta | Data Exfiltration | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47923 |
| 1187 | *https://senet-flets.v6.softether.co.jp/ddns/ddns.aspx* | .{0,1000}https\:\/\/senet\-flets\.v6\.softether\.co\.jp\/ddns\/ddns\.aspx.{0,1000} | greyware_tool_keyword | SoftEtherVPN | Cross-platform multi-protocol VPN software abused by attackers | T1133 - T1210 - T1573 - T1219 - T1571 | TA0001 - TA0002 - TA0003 - TA0005 - TA0010 | N/A | GALLIUM | Defense Evasion | https://github.com/SoftEtherVPN/SoftEtherVPN | 1 | 1 | #VPN | N/A | 8 | 10 | 12183 | 2647 | 2025-04-13T22:05:51Z | 2014-01-02T12:40:57Z | 47924 |
| 1188 | *https://share.riseup.net/2* | .{0,1000}https\:\/\/share\.riseup\.net\/2.{0,1000} | greyware_tool_keyword | share.riseup.net | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker | Collection | https://share.riseup.net | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47925 |
| 1189 | *https://share.riseup.net/up* | .{0,1000}https\:\/\/share\.riseup\.net\/up.{0,1000} | greyware_tool_keyword | share.riseup.net | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker | Data Exfiltration | https://share.riseup.net | 1 | 1 | #filehostingservice | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47926 |
| 1190 | *https://silentbreaksecurity.com/adaptive-dll-hijacking* | .{0,1000}https\:\/\/silentbreaksecurity\.com\/adaptive\-dll\-hijacking.{0,1000} | greyware_tool_keyword | IObitUnlocker | unlocking locked files on Windows systems | T1222 - T1070 - T1485 | TA0005 - TA0040 | N/A | PLAY | Defense Evasion | https://www.iobit.com/en/iobit-unlocker.php# | 1 | 1 | N/A | often used legitimatly - admin tool | 5 | 9 | N/A | N/A | N/A | N/A | 47929 |
| 1191 | *https://slack.com/api/channels.create* | .{0,1000}https\:\/\/slack\.com\/api\/channels\.create.{0,1000} | greyware_tool_keyword | slack | API usage of slack - creating channel - abused by multiple C2 | T1059.003 - T1071.004 - T1562.001 | TA0002 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/mthcht/Purpleteam/blob/main/Detection/Threat%20Hunting/generic/C2_abusing_API_services.md | 0 | 1 | N/A | /!\ very high risk of FP - hunting only | 1 | 2 | 184 | 19 | 2024-12-20T10:22:25Z | 2022-12-05T12:40:02Z | 47930 |
| 1192 | *https://spark.adobe.com/page/* | .{0,1000}https\:\/\/spark\.adobe\.com\/page\/.{0,1000} | greyware_tool_keyword | adobe.com | Attackers can use adobe.com to masquerade their domain for phishing purposes. | T1204.002 - T1036 - T1566.002 | TA0001 - TA0005 | N/A | N/A | Defense Evasion | https://www.joesandbox.com/analysis/515360/0/html | 0 | 1 | N/A | N/A | 1 | 1 | N/A | N/A | N/A | N/A | 47936 |
| 1193 | *https://sshx.io/get* | .{0,1000}https\:\/\/sshx\.io\/get.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 47939 |
| 1194 | *https://sshx.io/s/* | .{0,1000}https\:\/\/sshx\.io\/s\/.{0,1000} | greyware_tool_keyword | sshx | Fast collaborative live terminal sharing over the web | T1021.004 - T1041 - T1059 - T1071.001 | TA0002 - TA0009 - TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/ekzhang/sshx | 1 | 1 | N/A | N/A | 10 | 10 | 6379 | 220 | 2025-02-12T20:40:30Z | 2022-02-12T23:29:33Z | 47940 |
| 1195 | *https://steamcommunity.com/profiles/* | .{0,1000}https\:\/\/steamcommunity\.com\/profiles\/.{0,1000} | greyware_tool_keyword | steam | Steam profiles have been leveraged to host payload addresses for malware delivery - making them a potential threat vector in corporate environments. This tactic can serve as a valuable hunting tip for threat detection efforts | T1102 - T1091 - T1204 | TA0001 - TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | N/A | N/A | 1 | 1 | N/A | N/A | N/A | N/A | 47941 |
| 1196 | *https://store-*.ufile.io/v1/upload/* | .{0,1000}https\:\/\/store\-.{0,1000}\.ufile\.io\/v1\/upload\/.{0,1000} | greyware_tool_keyword | ufile.io | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Hive | Data Exfiltration | https://ufile.io | 1 | 1 | N/A | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47942 |
| 1197 | *https://sun.aweray.com/*/download* | .{0,1000}https\:\/\/sun\.aweray\.com\/.{0,1000}\/download.{0,1000} | greyware_tool_keyword | aweray | all-in-one secure remote access control and support solution | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | sun.aweray.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47943 |
| 1198 | *https://tailscale.com/s/resolvconf-overwrite* | .{0,1000}https\:\/\/tailscale\.com\/s\/resolvconf\-overwrite.{0,1000} | greyware_tool_keyword | tailscale | Tailscale connects your team's devices and development environments for easy access to remote resources. | T1021 - T1573 | TA0005 - TA0001 - TA0010 | N/A | Scattered Spider* | Defense Evasion | https://github.com/tailscale/tailscale | 1 | 1 | N/A | N/A | 9 | 10 | 22196 | 1771 | 2025-04-22T19:46:43Z | 2020-01-31T22:00:03Z | 47954 |
| 1199 | *https://temp.sh/*/* | .{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | temp.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47955 |
| 1200 | *https://temp.sh/upload* | .{0,1000}https\:\/\/temp\.sh\/upload.{0,1000} | greyware_tool_keyword | temp.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47956 |
| 1201 | *https://tempsend.com/* | .{0,1000}https\:\/\/tempsend\.com\/.{0,1000} | greyware_tool_keyword | tempsend.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47957 |
| 1202 | *https://tempsend.com/send* | .{0,1000}https\:\/\/tempsend\.com\/send.{0,1000} | greyware_tool_keyword | tempsend.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47958 |
| 1203 | *https://termbin.com/test* | .{0,1000}https\:\/\/termbin\.com\/test.{0,1000} | greyware_tool_keyword | termbin.com | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | termbin.com | 1 | 1 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47959 |
| 1204 | *https://textbin.net/raw/* | .{0,1000}https\:\/\/textbin\.net\/raw\/.{0,1000} | greyware_tool_keyword | textbin.net | textbin.net raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | textbin.net | 1 | 1 | #PastebinLike | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47960 |
| 1205 | *https://tmate.io/t/* | .{0,1000}https\:\/\/tmate\.io\/t\/.{0,1000} | greyware_tool_keyword | tmate | Instant terminal sharing | T1071 - T1105 - T1573 - T1021 | TA0010 - TA0011 - TA0008 - TA0002 | N/A | WatchDog | C2 | https://github.com/tmate-io/tmate | 1 | 1 | #linux | N/A | 10 | 10 | 5786 | 315 | 2023-10-16T11:59:37Z | 2013-06-12T20:29:22Z | 47962 |
| 1206 | *https://tmpfiles.org/dl/*.exe* | .{0,1000}https\:\/\/tmpfiles\.org\/dl\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | tmpfiles.org | download of an executable files from tmpfiles.org often used by ransomware groups | T1566.002 - T1192 - T1105 | TA0001 - TA0002 | N/A | N/A | Collection | N/A | 1 | 1 | #filehostingservice | greyware tool - risk of false positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47963 |
| 1207 | *https://tox.chat/download.html* | .{0,1000}https\:\/\/tox\.chat\/download\.html.{0,1000} | greyware_tool_keyword | ransomware_notes | detection patterns retrieved in ransomware notes archives | T1486 | TA0040 | N/A | N/A | Ransomware | https://github.com/threatlabz/ransomware_notes | 1 | 1 | N/A | N/A | 10 | 4 | 354 | 55 | 2025-04-04T19:06:04Z | 2022-08-01T15:14:59Z | 47965 |
| 1208 | *https://track.adform.net/C/?bn=*;cpdir=http* | .{0,1000}https\:\/\/track\.adform\.net\/C\/\?bn\=.{0,1000}\;cpdir\=http.{0,1000} | greyware_tool_keyword | track.adform.net | Attackers can use track.adform.net to masquerade their domain for phishing purposes. | T1204.002 - T1036 - T1566.002 | TA0001 - TA0005 | N/A | N/A | Defense Evasion | https://www.joesandbox.com/analysis/514456/0/html | 0 | 1 | N/A | N/A | 5 | 5 | N/A | N/A | N/A | N/A | 47966 |
| 1209 | *https://transfer.sh* | .{0,1000}https\:\/\/transfer\.sh.{0,1000} | greyware_tool_keyword | transfer.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47967 |
| 1210 | *https://transfert-my-files.com/files/* | .{0,1000}https\:\/\/transfert\-my\-files\.com\/files\/.{0,1000} | greyware_tool_keyword | transfert-my-files.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47970 |
| 1211 | *https://transfert-my-files.com/inc/upload.php* | .{0,1000}https\:\/\/transfert\-my\-files\.com\/inc\/upload\.php.{0,1000} | greyware_tool_keyword | transfert-my-files.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Data Exfiltration | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47971 |
| 1212 | *https://tunnel.pyjam.as/* | .{0,1000}https\:\/\/tunnel\.pyjam\.as\/.{0,1000} | greyware_tool_keyword | tunnel | SSL-terminated ephemeral HTTP tunnels to your local machine | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://gitlab.com/pyjam.as/tunnel | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47973 |
| 1213 | *https://tunnelmole.com/docs* | .{0,1000}https\:\/\/tunnelmole\.com\/docs.{0,1000} | greyware_tool_keyword | tunnelmole-client | tmole - Share your local server with a Public URL | T1572 | TA0011 - TA0003 | N/A | N/A | C2 | https://github.com/robbie-cahill/tunnelmole-client/ | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 86 | 2025-04-04T09:06:21Z | 2023-02-08T08:27:57Z | 47974 |
| 1214 | *https://tunwg.com* | .{0,1000}https\:\/\/tunwg\.com.{0,1000} | greyware_tool_keyword | tunwg | End to end encrypted secure tunnel to local servers | T1572 - T1048 | TA0011 - TA0010 - TA0005 | N/A | N/A | C2 | https://github.com/ntnj/tunwg | 1 | 1 | N/A | N/A | 10 | 10 | 236 | 8 | 2024-09-18T15:03:45Z | 2023-01-16T17:51:13Z | 47977 |
| 1215 | *https://ufile.io/* | .{0,1000}https\:\/\/ufile\.io\/.{0,1000} | greyware_tool_keyword | ufile.io | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Hive | Collection | https://ufile.io | 1 | 1 | N/A | downloading files url | 5 | 6 | N/A | N/A | N/A | N/A | 47978 |
| 1216 | *https://ufile.io/v1/upload/* | .{0,1000}https\:\/\/ufile\.io\/v1\/upload\/.{0,1000} | greyware_tool_keyword | ufile.io | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Hive | Data Exfiltration | https://ufile.io | 1 | 1 | #filehostingservice | uploading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47979 |
| 1217 | *https://update.lansweeper.com/installation.aspx* | .{0,1000}https\:\/\/update\.lansweeper\.com\/installation\.aspx.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 47981 |
| 1218 | *https://us4-wms6.zoho.com* | .{0,1000}https\:\/\/us4\-wms6\.zoho\.com.{0,1000} | greyware_tool_keyword | Zoho Assist | Zoho Assist Remote access software - abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | LockBit - Scattered Spider* | RMM | https://www.zoho.com/assist/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47982 |
| 1219 | *https://usaupload.com/account/ajax/load_files* | .{0,1000}https\:\/\/usaupload\.com\/account\/ajax\/load_files.{0,1000} | greyware_tool_keyword | usaupload | uploading files to usaupload | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | N/A | Data Exfiltration | https://usaupload.com/ | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47983 |
| 1220 | *https://usaupload.com/account/ajax/uploader* | .{0,1000}https\:\/\/usaupload\.com\/account\/ajax\/uploader.{0,1000} | greyware_tool_keyword | usaupload | uploading files to usaupload | T1030 - T1048 - T1078.004 - T1105 - T1567.001 | TA0010 | N/A | N/A | Data Exfiltration | https://usaupload.com/ | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47984 |
| 1221 | *https://we.tl/t-* | .{0,1000}https\:\/\/we\.tl\/t\-.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47987 |
| 1222 | *https://webhook.site/*-*-*-* | .{0,1000}https\:\/\/webhook\.site\/.{0,1000}\-.{0,1000}\-.{0,1000}\-.{0,1000} | greyware_tool_keyword | webhook.site | test HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmation | T1102 - T1071 - T1560.001 | TA0011 - TA0042 | N/A | N/A | C2 | https://github.com/webhooksite/webhook.site | 1 | 1 | N/A | Out of band interaction domains | 10 | 10 | 5806 | 457 | 2025-04-04T10:42:59Z | 2016-03-21T08:45:42Z | 47990 |
| 1223 | *https://wetransfer.com/api/v4/transfers/* | .{0,1000}https\:\/\/wetransfer\.com\/api\/v4\/transfers\/.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47991 |
| 1224 | *https://wetransfer.com/downloads/* | .{0,1000}https\:\/\/wetransfer\.com\/downloads\/.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47992 |
| 1225 | *https://www.4shared.com/get/* | .{0,1000}https\:\/\/www\.4shared\.com\/get\/.{0,1000} | greyware_tool_keyword | 4shared.com | Downloading a file from 4shared.com | T1105 - T1071 - T1125 | TA0009 | N/A | Turla | Collection | 4shared.com | 1 | 1 | #filehostingservice | N/A | 6 | 5 | N/A | N/A | N/A | N/A | 47998 |
| 1226 | *https://www.autohotkey.com/download/* | .{0,1000}https\:\/\/www\.autohotkey\.com\/download\/.{0,1000} | greyware_tool_keyword | Ahk2Exe | Official AutoHotkey script compiler - misused in scripting malicious executables | T1059 - T1204 - T1036 - T1027 | TA0002 - TA0005 | N/A | N/A | Defense Evasion | https://github.com/AutoHotkey/Ahk2Exe | 1 | 1 | N/A | N/A | 7 | 7 | 658 | 118 | 2025-03-09T02:27:33Z | 2011-08-01T10:28:19Z | 47999 |
| 1227 | *https://www.btunnel.in/downloads* | .{0,1000}https\:\/\/www\.btunnel\.in\/downloads.{0,1000} | greyware_tool_keyword | btunnel | Btunnel is a publicly accessible reverse proxy | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://www.btunnel.in | 1 | 1 | N/A | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 48003 |
| 1228 | *https://www.dataplicity.com/*.py* | .{0,1000}https\:\/\/www\.dataplicity\.com\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | Dataplicity | enables connecting local systems to dataplicity cloud for remotely accessing them over the internet. | T1090 - T1102 - T1043 - T1071 | TA0010 - TA0005 - TA0011 | N/A | N/A | Data Exfiltration | https://github.com/wildfoundry/dataplicity-agent | 1 | 1 | N/A | N/A | 9 | 2 | 167 | 32 | 2024-06-10T20:17:43Z | 2016-07-27T14:23:01Z | 48004 |
| 1229 | *https://www.duckdns.org/update?domains=* | .{0,1000}https\:\/\/www\.duckdns\.org\/update\?domains\=.{0,1000} | greyware_tool_keyword | duckdns.org | A simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2 | T1568.002 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Defense Evasion | https://www.duckdns.org/install.jsp | 1 | 1 | N/A | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 48005 |
| 1230 | *https://www.email-format.com/d/* | .{0,1000}https\:\/\/www\.email\-format\.com\/d\/.{0,1000} | greyware_tool_keyword | email-format | used by attackers to find informations about a company users | T1593 - T1596 - T1213 | TA0009 | N/A | N/A | Reconnaissance | https://www.email-format.com | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 48006 |
| 1231 | *https://www.guerrillamail.com/compose* | .{0,1000}https\:\/\/www\.guerrillamail\.com\/compose.{0,1000} | greyware_tool_keyword | guerrillamail | disposable email address to use anytime. | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | https://www.guerrillamail.com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 48008 |
| 1232 | *https://www.guerrillamail.com/inbox* | .{0,1000}https\:\/\/www\.guerrillamail\.com\/inbox.{0,1000} | greyware_tool_keyword | guerrillamail | disposable email address to use anytime. | T1071.003 | TA0005 - TA0001 | N/A | N/A | Defense Evasion | https://www.guerrillamail.com | 1 | 1 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 48009 |
| 1233 | *https://www.lansweeper.com/installation.aspx* | .{0,1000}https\:\/\/www\.lansweeper\.com\/installation\.aspx.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 48012 |
| 1234 | *https://www.majorgeeks.com/files/details/pc_hunter.html* | .{0,1000}https\:\/\/www\.majorgeeks\.com\/files\/details\/pc_hunter\.html.{0,1000} | greyware_tool_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 48013 |
| 1235 | *https://www.mediafire.com/api/*/folder/get_content.php* | .{0,1000}https\:\/\/www\.mediafire\.com\/api\/.{0,1000}\/folder\/get_content\.php.{0,1000} | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1114 - T1083 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 48014 |
| 1236 | *https://www.nirsoft.net/toolsdownload/* | .{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000} | greyware_tool_keyword | nirsoft tools | NirSoft is a legitimate software company that develops system utilities for Windows. Some of its tools can be used by malicious actors to recover passwords harvest sensitive information and conduct password attacks. | T1003 - T1003.001 - T1003.002 - T1110 - T1566 | TA0002 - TA0003 - TA0004 - TA0006 - TA0007 - TA0008 - TA0011 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48016 |
| 1237 | *https://www.nirsoft.net/toolsdownload/*.exe* | .{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | nirsoft tools | some of nirsoft tools can be abused by attackers to retrieve passwords | T1003 - T1021 - T1056 - T1110 - T1212 - T1552 | TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011 | N/A | N/A | Credential Access | nirsoft.net | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48017 |
| 1238 | *https://www.nirsoft.net/toolsdownload/*.zip* | .{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | nirsoft tools | some of nirsoft tools can be abused by attackers to retrieve passwords | T1003 - T1021 - T1056 - T1110 - T1212 - T1552 | TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011 | N/A | N/A | Credential Access | nirsoft.net | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48018 |
| 1239 | *https://www.nirsoft.net/utils/*.exe* | .{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | nirsoft tools | some of nirsoft tools can be abused by attackers to retrieve passwords | T1003 - T1021 - T1056 - T1110 - T1212 - T1552 | TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011 | N/A | N/A | Credential Access | nirsoft.net | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48019 |
| 1240 | *https://www.nirsoft.net/utils/*.zip* | .{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | nirsoft tools | some of nirsoft tools can be abused by attackers to retrieve passwords | T1003 - T1021 - T1056 - T1110 - T1212 - T1552 | TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011 | N/A | N/A | Credential Access | nirsoft.net | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48020 |
| 1241 | *https://www.premiumize.me/* | .{0,1000}https\:\/\/www\.premiumize\.me\/.{0,1000} | greyware_tool_keyword | premiumize.me | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Collection | www.premiumize.me | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 48022 |
| The file is too large to be shown. View Raw |