Files
mthcht-ThreatHunting-Keywords/greyware_tool_keyword_network_detection.csv
2025-08-04 02:33:52 +02:00

785 KiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2*&browser=tor&api=false*.{0,1000}\&browser\=tor\&api\=false.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A4049
3*./nmap*.{0,1000}\.\/nmap.{0,1000}greyware_tool_keywordnmapA very common tool. Network host vuln and port detector.T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap11#linuxgreyware tool - risks of False positive !8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z4173
4*._tcp.argotunnel.com*.{0,1000}\._tcp\.argotunnel\.com.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z4234
5*.a.pinggy.online*.{0,1000}\.a\.pinggy\.online.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A4237
6*.api.mega.co.nz*.{0,1000}\.api\.mega\.co\.nz.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4242
7*.api.splashtop.com*.{0,1000}\.api\.splashtop\.com.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c7211N/AN/A1010N/AN/AN/AN/A4243
8*.apitest.barracudamsp.com*.{0,1000}\.apitest\.barracudamsp\.com.{0,1000}greyware_tool_keywordBarracudaRMMDeliver remote support services - formely AVGT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.barracudamsp.com/products/rmm/barracuda-rmm11N/AN/A1010N/AN/AN/AN/A4244
9*.asse.devtunnels.ms*.{0,1000}\.asse\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A4249
10*.aweray.net*.{0,1000}\.aweray\.net.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A4252
11*.beyondtrustcloud.com/session_complete*.{0,1000}\.beyondtrustcloud\.com\/session_complete.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A4258
12*.comodo.com/static/frontend/static-pages/enroll-wizard/token*.{0,1000}\.comodo\.com\/static\/frontend\/static\-pages\/enroll\-wizard\/token.{0,1000}greyware_tool_keywordComodoRMM (Itarian RMM)Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://one.comodo.com/11N/AN/A1010N/AN/AN/AN/A4275
13*.console.gotoassist.com*.{0,1000}\.console\.gotoassist\.com.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A4279
14*.d.requestbin.net*.{0,1000}\.d\.requestbin\.net.{0,1000}greyware_tool_keywordrequestbin.netallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://requestbin.net11N/AOut of band interaction domains1010N/AN/AN/AN/A4282
15*.dev1.fleetdeck.io*.{0,1000}\.dev1\.fleetdeck\.io.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z4285
16*.dnslog.cn:*.{0,1000}\.dnslog\.cn\:.{0,1000}greyware_tool_keyworddnslog.cnallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://dnslog.cn11N/AOut of band interaction domains1010N/AN/AN/AN/A4289
17*.exec*.interact.sh*.{0,1000}\.exec.{0,1000}\.interact\.sh.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z4660
18*.free.pinggy.online*.{0,1000}\.free\.pinggy\.online.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A4665
19*.gofile.io/uploadFile*.{0,1000}\.gofile\.io\/uploadFile.{0,1000}greyware_tool_keywordgofile.iolegitimate service abused by lots of stealer to exfiltrate dataT1567.002TA0010N/AHive - Royal - LockBit - Vice Society - BlackSuit - ContiData Exfiltrationhttps://gofile.io11#filehostingserviceN/A810N/AN/AN/AN/A4670
20*.in.zrok.io*.{0,1000}\.in\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4677
21*.l.tunwg.com*.{0,1000}\.l\.tunwg\.com.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z4686
22*.localltunnel.me*.{0,1000}\.localltunnel\.me.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z4696
23*.loclx.io:*.{0,1000}\.loclx\.io\:.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A4697
24*.mspa.n-able.com*.{0,1000}\.mspa\.n\-able\.com.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A4703
25*.myftp.biz*.{0,1000}\.myftp\.biz.{0,1000}greyware_tool_keywordmyftp.bizdyndns - lots of subdomains associated with malwares - could be used in various ways for both legitimate and malicious activities (malicious mostly)T1071 - T1021 - T1095 - T1059TA0010 - TA0008 - TA0009 - TA0011N/AN/AData Exfiltrationhttps://github.com/hagezi/dns-blocklists/blob/9d6562bddc175b59241d5935531f648cd6b6d9c8/rpz/dyndns.txt#L10311#filehostingservice #P2PN/A1010107253402025-04-22T19:18:32Z2022-04-25T07:13:09Z4704
26*.myftp.org*.{0,1000}\.myftp\.org.{0,1000}greyware_tool_keywordmyftp.orgdyndns - lots of subdomains associated with malwares - myftp.org could be used in various ways for both legitimate and malicious activities (malicious mostly)T1071 - T1021 - T1095 - T1059TA0010 - TA0008 - TA0009 - TA0011N/AN/AData Exfiltrationhttps://github.com/pan-unit42/iocs/blob/master/rat_nest/iocs.csv11#filehostingservice #P2PN/A1087111522025-04-05T02:03:37Z2015-06-04T13:37:09Z4705
27*.ngrok.me*.{0,1000}\.ngrok\.me.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z4709
28*.realtime.services.box.net*.{0,1000}\.realtime\.services\.box\.net.{0,1000}greyware_tool_keywordBoxAttackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackersT1567.002 - T1071.001 - T1036 - T1048.002TA0005 - TA0010 - TA0009N/AN/AData Exfiltrationhttps://app.box.com/11#dnsqueryN/A67N/AN/AN/AN/A4861
29*.rel.tunnels.api.visualstudio.com*.{0,1000}\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keywordvscodebuilt-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices.T1090 - T1003 - T1571TA0010 - TA0002 - TA0009N/AN/AC2https://twitter.com/code/status/169986908707189966901N/AN/A1010N/AN/AN/AN/A4862
30*.relay.splashtop.com*.{0,1000}\.relay\.splashtop\.com.{0,1000}greyware_tool_keywordSplashtopcontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - LockBit - AvosLocker - BianLian - Scattered Spider* - Hive - Quantum - Conti - Trigona - RansomHub - CactusRMMhttps://hybrid-analysis.com/sample/18c10b0235bd341e065ac5c53ca04b68eaeacd98a120e043fb4883628baf644e/6267eb693836e7217b1a3c7211N/AN/A1010N/AN/AN/AN/A4863
31*.remotepc.com*.{0,1000}\.remotepc\.com.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A4864
32*.remotepc.com*.{0,1000}\.remotepc\.com.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/Anetwork1010N/AN/AN/AN/A4865
33*.remoteutilities.com*.{0,1000}\.remoteutilities\.com.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A4866
34*.remoteview.logmein.com*.{0,1000}\.remoteview\.logmein\.com.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A4867
35*.router.teamviewer.com*.{0,1000}\.router\.teamviewer\.com.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/11N/AFP risk - teamviewer usage1010N/AN/AN/AN/A4871
36*.servicedesk.atera.com/GetAgent*.{0,1000}\.servicedesk\.atera\.com\/GetAgent.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A4885
37*.share.zrok.io*.{0,1000}\.share\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4904
38*.srv.browser.lol*.{0,1000}\.srv\.browser\.lol.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A4910
39*.static.mega.co.nz*.{0,1000}\.static\.mega\.co\.nz.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4915
40*.trycloudfare.com*DavWWWRoot*.{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A4923
41*.tunnel.pyjam.as*.{0,1000}\.tunnel\.pyjam\.as.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel11N/AN/A1010N/AN/AN/AN/A4924
42*.tunnelto.dev*.{0,1000}\.tunnelto\.dev.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z4929
43*.userstorage.mega.co.nz/ul/*.{0,1000}\.userstorage\.mega\.co\.nz\/ul\/.{0,1000}greyware_tool_keywordmega.co.nzuploading data to mega cloudT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR - DispossessorData Exfiltrationhttps://mega.io/11#filehostingservice #P2PN/A1010N/AN/AN/AN/A4944
44*.v2.argotunnel.com*.{0,1000}\.v2\.argotunnel\.com.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z4945
45*.xeox.com*.{0,1000}\.xeox\.com.{0,1000}greyware_tool_keywordxeoxEasily access and manage Windows devices remotely within XEOX - RMM abused by threat actorsT1021 - T1078 - T1219 - T1105 - T1046TA0011 - TA0010 - TA0003 - TA0005N/ADispossessorRMMhttps://xeox.com/remote-access/11N/AN/A1010N/AN/AN/AN/A4956
46*.zohoassist.com.cn*.{0,1000}\.zohoassist\.com\.cn.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A4979
47*.zohoassist.jp*.{0,1000}\.zohoassist\.jp.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A4980
48*.zrok.quigley.com*.{0,1000}\.zrok\.quigley\.com.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z4981
49*/*.loclx.io*.{0,1000}\/.{0,1000}\.loclx\.io.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A4983
50*/3proxy-*.deb*.{0,1000}\/3proxy\-.{0,1000}\.deb.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5088
51*/3proxy-*.rpm*.{0,1000}\/3proxy\-.{0,1000}\.rpm.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5089
52*/3proxy-*.zip*.{0,1000}\/3proxy\-.{0,1000}\.zip.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5090
53*/3proxy.exe*.{0,1000}\/3proxy\.exe.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5091
54*/3proxy.git*.{0,1000}\/3proxy\.git.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5092
55*/3proxy.log*.{0,1000}\/3proxy\.log.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11#logfile #linuxN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z5093
56*/a.pinggy.io*.{0,1000}\/a\.pinggy\.io.{0,1000}greyware_tool_keywordpinggyCreate HTTP/TCP or TLS tunnels to your Mac/PC. Even if it is sitting behind firewalls and NATs.T1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://pinggy.io/11N/AN/A1010N/AN/AN/AN/A5100
57*/AADInternals.git*.{0,1000}\/AADInternals\.git.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z5102
58*/action1_agent(My_Organization).msi*.{0,1000}\/action1_agent\(My_Organization\)\.msi.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/Aproduct name1010N/AN/AN/AN/A5123
59*/AD_Miner.git*.{0,1000}\/AD_Miner\.git.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5127
60*/AD_Miner/releases/*.{0,1000}\/AD_Miner\/releases\/.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5128
61*/adaudit.git*.{0,1000}\/adaudit\.git.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5138
62*/adaudit.ps1*.{0,1000}\/adaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5140
63*/AD-common-queries.git*.{0,1000}\/AD\-common\-queries\.git.{0,1000}greyware_tool_keywordAD-common-queriesCollection of common ADSI queries for Domain Account enumerationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries11N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z5147
64*/AdFind.zip*.{0,1000}\/AdFind\.zip.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior11N/AN/A1010N/AN/AN/AN/A5186
65*/ADGet.exe*.{0,1000}\\ADGet\.exe.{0,1000}greyware_tool_keywordadgetgather valuable informations about the AD environmentT1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482TA0001 - TA0002 - TA0003 - TA0007 - TA0011N/AN/ADiscoveryhttps://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/11N/AN/A1010N/AN/AN/AN/A5198
66*/ADRecon*.{0,1000}\/ADRecon.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commandsT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/sense-of-security/ADRecon11N/AN/A101017862922020-06-15T05:23:14Z2017-11-29T23:01:53Z5212
67*/ADRecon.ps1*.{0,1000}\/ADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z5214
68*/Advanced_Port_Scanner_*.exe*.{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A5218
69*/Ahk2Exe.exe*.{0,1000}\/Ahk2Exe\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5255
70*/Ahk2Exe.git*.{0,1000}\/Ahk2Exe\.git.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5256
71*/Ahk2Exe.zip*.{0,1000}\/Ahk2Exe\.zip.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5257
72*/Ahk2Exe1.*.zip*.{0,1000}\/Ahk2Exe1\..{0,1000}\.zip.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5258
73*/ahk-install.exe*.{0,1000}\/ahk\-install\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5259
74*/ahk-v2.exe*.{0,1000}\/ahk\-v2\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5260
75*/Alpemix.zip*.{0,1000}\/Alpemix\.zip.{0,1000}greyware_tool_keywordAlpemixconnect to your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.alpemix.com/11N/AN/A1010N/AN/AN/AN/A5281
76*/amalshaji/portr-admin/*.{0,1000}\/amalshaji\/portr\-admin\/.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z5282
77*/amidaware/rmmagent/releases/download/*.{0,1000}\/amidaware\/rmmagent\/releases\/download\/.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z5288
78*/Amperage.exe*.{0,1000}\/Amperage\.exe.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5291
79*/AmperageKit.git*.{0,1000}\/AmperageKit\.git.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5292
80*/AmperageKit/releases/*.{0,1000}\/AmperageKit\/releases\/.{0,1000}greyware_tool_keywordAmperageKitenabling Recall in Windows 11 version 24H2 on unsupported devicesT1005 - T1113 - T1056.001 - T1003TA0009 - TA0010 - TA0006 - TA0007N/AN/ASniffing & Spoofinghttps://github.com/thebookisclosed/AmperageKit11N/AN/A85406262024-06-21T16:37:12Z2024-05-30T23:00:45Z5293
81*/Anydesk.exe.{0,1000}\/Anydesk\.exegreyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://anydesk.com/11N/Arisk of false positives - compliance detection1010N/AN/AN/AN/A5333
82*/anyplace-control/data2/*.exe*.{0,1000}\/anyplace\-control\/data2\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordAnyplaceControlaccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyplace-control[.]com11N/AN/A1010N/AN/AN/AN/A5334
83*/AnyViewerSetup.exe*.{0,1000}\/AnyViewerSetup\.exe.{0,1000}greyware_tool_keywordanyvieweraccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyviewer.com11N/AN/A1010N/AN/AN/AN/A5336
84*/Apemix.exe*.{0,1000}\/Apemix\.exe.{0,1000}greyware_tool_keywordAlpemixconnect to your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.alpemix.com/11N/AN/A1010N/AN/AN/AN/A5342
85*/api/latest/fleet/mdm/bootstrap?token=*.{0,1000}\/api\/latest\/fleet\/mdm\/bootstrap\?token\=.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z5350
86*/api/v1/fleet/mdm/sso/callback*.{0,1000}\/api\/v1\/fleet\/mdm\/sso\/callback.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z5365
87*/Assistance rapide Installer.exe*.{0,1000}\/Assistance\srapide\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A5428
88*/Assistenza rapida Installer.exe*.{0,1000}\/Assistenza\srapida\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A5429
89*/atnow.exe*.{0,1000}\/atnow\.exe.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5454
90*/atnow.zip*.{0,1000}\/atnow\.zip.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5455
91*/AttendedUDP.zip*.{0,1000}\/AttendedUDP\.zip.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A5466
92*/AutoHotkey.exe*.{0,1000}\/AutoHotkey\.exe.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5478
93*/AutoHotkey.git*.{0,1000}\/AutoHotkey\.git.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5479
94*/AutoHotkey/releases/download/*.{0,1000}\/AutoHotkey\/releases\/download\/.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5480
95*/AutoHotkey_*.zip*.{0,1000}\/AutoHotkey_.{0,1000}\.zip.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5481
96*/AutoHotkey_1*_setup.exe*.{0,1000}\/AutoHotkey_1.{0,1000}_setup\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5482
97*/AutoHotkey_2*_setup.exe*.{0,1000}\/AutoHotkey_2.{0,1000}_setup\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5483
98*/AutoHotkey64.exe*.{0,1000}\/AutoHotkey64\.exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z5484
99*/AutoHotkey64.exe*.{0,1000}\/AutoHotkey64\.exe.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z5485
100*/Aweray_Remote_*.exe*.{0,1000}\/Aweray_Remote_.{0,1000}\.exe.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A5505
101*/Aweray_Remote_*.zip*.{0,1000}\/Aweray_Remote_.{0,1000}\.zip.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A5506
102*/bin/x64/connectd.exe*.{0,1000}\/bin\/x64\/connectd\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11#linuxN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z5666
103*/BitLockerToGo.exe*.{0,1000}\/BitLockerToGo\.exe.{0,1000}greyware_tool_keywordBitLockerToGoBitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive dataT1218 - T1055 - T1112 - T1056 - T1555TA0005 - TA0007 - TA0009Lumma StealerN/ADefense Evasionhttps://securelist.com/fake-captcha-delivers-lumma-amadey/114312/01N/Ahigh FP - hunting only38N/AN/AN/AN/A5676
104*/bomgar-rep.exe*.{0,1000}\/bomgar\-rep\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5761
105*/bomgar-scc-*.exe*.{0,1000}\/bomgar\-scc\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5763
106*/bomgar-scc.exe*.{0,1000}\/bomgar\-scc\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A5764
107*/boringproxy.git*.{0,1000}\/boringproxy\.git.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5767
108*/boringproxy-client.service*.{0,1000}\/boringproxy\-client\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5768
109*/boringproxy-server.service*.{0,1000}\/boringproxy\-server\.service.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z5769
110*/BoxDrive.msi*.{0,1000}\/BoxDrive\.msi.{0,1000}greyware_tool_keywordBoxAttackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackersT1567.002 - T1071.001 - T1036 - T1048.002TA0005 - TA0010 - TA0009N/AN/AData Exfiltrationhttps://app.box.com/11N/AN/A67N/AN/AN/AN/A5770
111*/btunnel.exe*.{0,1000}\/btunnel\.exe.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A5847
112*/cloudflared.git*.{0,1000}\/cloudflared\.git.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6091
113*/cloudflared-linux-*.deb*.{0,1000}\/cloudflared\-linux\-.{0,1000}\.deb.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11#linuxN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6093
114*/cloudflared-linux-*.rpm*.{0,1000}\/cloudflared\-linux\-.{0,1000}\.rpm.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11#linuxN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z6094
115*/cmd/tailscaled*.{0,1000}\/cmd\/tailscaled.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z6105
116*/config/apps/http/servers/sirtunnel/routes*.{0,1000}\/config\/apps\/http\/servers\/sirtunnel\/routes.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z6181
117*/connectd.aarch64-win.exe*.{0,1000}\/connectd\.aarch64\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z6189
118*/connectd.x86_64-win.exe*.{0,1000}\/connectd\.x86_64\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z6190
119*/croc.exe*.{0,1000}\/croc\.exe.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6271
120*/croc/releases/download/v10*.{0,1000}\/croc\/releases\/download\/v10.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6273
121*/croc/releases/latest*.{0,1000}\/croc\/releases\/latest.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z6274
122*/crowbar.git*.{0,1000}\/crowbar\.git.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6285
123*/crowbar_1.0.0_darwin_386.zip*.{0,1000}\/crowbar_1\.0\.0_darwin_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6286
124*/crowbar_1.0.0_darwin_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_darwin_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6287
125*/crowbar_1.0.0_freebsd_386.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6288
126*/crowbar_1.0.0_freebsd_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6289
127*/crowbar_1.0.0_freebsd_arm.zip*.{0,1000}\/crowbar_1\.0\.0_freebsd_arm\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6290
128*/crowbar_1.0.0_linux_386.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_386\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6291
129*/crowbar_1.0.0_linux_amd64.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_amd64\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6292
130*/crowbar_1.0.0_linux_arm.tar.gz*.{0,1000}\/crowbar_1\.0\.0_linux_arm\.tar\.gz.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11#linuxN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6293
131*/crowbar_1.0.0_openbsd_386.zip*.{0,1000}\/crowbar_1\.0\.0_openbsd_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6294
132*/crowbar_1.0.0_openbsd_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_openbsd_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6295
133*/crowbar_1.0.0_windows_386.zip*.{0,1000}\/crowbar_1\.0\.0_windows_386\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6296
134*/crowbar_1.0.0_windows_amd64.zip*.{0,1000}\/crowbar_1\.0\.0_windows_amd64\.zip.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z6297
135*/damewareagent.exe*.{0,1000}\/damewareagent\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A6397
136*/dataplicity-agent.git*.{0,1000}\/dataplicity\-agent\.git.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6439
137*/dataplicity-agent/releases/download*.{0,1000}\/dataplicity\-agent\/releases\/download.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z6440
138*/download*mediafire.com/.{0,1000}\/download.{0,1000}mediafire\.com\/greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1083 - T1560TA0009 N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A6750
139*/download/fiddler/fiddler-everywhere-windows*.{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A6751
140*/download/pcunlocker*.{0,1000}\/download\/pcunlocker.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A6754
141*/downloads/ultravnc.html*.{0,1000}\/downloads\/ultravnc\.html.{0,1000}greyware_tool_keywordUltraVNCUltraVNC remote access software usageT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ADispossessor - Gamaredon Group - APT39RMMhttps://uvnc.com/downloads/ultravnc.html11N/AN/A1010N/AN/AN/AN/A6771
142*/dropbear.git*.{0,1000}\/dropbear\.git.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6792
143*/dropbear/releases/*.{0,1000}\/dropbear\/releases\/.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6795
144*/dropbear-sshj.git*.{0,1000}\/dropbear\-sshj\.git.{0,1000}greyware_tool_keywordSSH-J.comThis is Dropbear SSH server modified to be used as a public SSH jump & port forwarding serviceT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://bitbucket.org/ValdikSS/dropbear-sshj/src/master/11N/AN/A1010N/AN/AN/AN/A6798
145*/DuckDNS.7z*.{0,1000}\/DuckDNS\.7z.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6809
146*/DuckDNS.git*.{0,1000}\/DuckDNS\.git.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6810
147*/DuckDNS.zip"*.{0,1000}\/DuckDNS\.zip\".{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6811
148*/duckdns/duck.log*.{0,1000}\/duckdns\/duck\.log.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11#logfile #linuxN/A510N/AN/AN/AN/A6812
149*/duckdns/duck.sh*.{0,1000}\/duckdns\/duck\.sh.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6813
150*/duckdns-powershell.git*.{0,1000}\/duckdns\-powershell\.git.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A6814
151*/DWMRC_St_64.msi*.{0,1000}\/DWMRC_St_64\.msi.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6860
152*/DWRCC.exe*.{0,1000}\/DWRCC\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6861
153*/DWRCCMD.exe*.{0,1000}\/DWRCCMD\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6862
154*/DWRCS.exe*.{0,1000}\/DWRCS\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A6863
155*/ehorus_agent_installer-*.{0,1000}\/ehorus_agent_installer\-.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/11N/AN/A1010N/AN/AN/AN/A6906
156*/Eraser 6.0.10.2620.exe*.{0,1000}\/Eraser\s6\.0\.10\.2620\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6980
157*/Eraser 6.0.8.2273.exe*.{0,1000}\/Eraser\s6\.0\.8\.2273\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6981
158*/Eraser 6.0.9.2343.exe*.{0,1000}\/Eraser\s6\.0\.9\.2343\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6982
159*/Eraser 6.2.0.2994.exe*.{0,1000}\/Eraser\s6\.2\.0\.2994\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6983
160*/EraserSetup.exe*.{0,1000}\/EraserSetup\.exe.{0,1000}greyware_tool_keyworderaserIt completely removes sensitive data from your hard drive by overwriting it several times with carefully selected patterns - abusedby attackers for anti forensicT1070 - T1488 - T1561TA0005N/ABlackSuit - RoyalDefense Evasionhttps://sourceforge.net/projects/eraser11N/AN/A710N/AN/AN/AN/A6984
161*/expose/database/expose.db*.{0,1000}\/expose\/database\/expose\.db.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z7151
162*/expose/raw/master/builds/expose*.{0,1000}\/expose\/raw\/master\/builds\/expose.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z7152
163*/Fiddler Everywhere *.*.*.exe*.{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A7190
164*/FileZilla_*_sponsored-setup.exe*.{0,1000}\/FileZilla_.{0,1000}_sponsored\-setup\.exe.{0,1000}greyware_tool_keywordFileZillaFileZilla admintool used by threat actors for persistence and data exfiltrationT1505 - T1041TA0003 - TA0009 -TA0010N/ADispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155Data Exfiltrationhttps://filezilla-project.org/11N/APUA risk of legitimate usage57N/AN/AN/AN/A7199
165*/FileZilla_Server_*.deb*.{0,1000}\/FileZilla_Server_.{0,1000}\.deb.{0,1000}greyware_tool_keywordFileZillaFileZilla admintool used by threat actors for persistence and data exfiltrationT1505 - T1041TA0003 - TA0009 -TA0010N/ADispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155Data Exfiltrationhttps://filezilla-project.org/11N/APUA risk of legitimate usage57N/AN/AN/AN/A7200
166*/fleet_v*_linux.tar.gz*.{0,1000}\/fleet_v.{0,1000}_linux\.tar\.gz.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11#linuxN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7216
167*/fleetd.crx*.{0,1000}\/fleetd\.crx.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7217
168*/fleetdm/fleet/releases/download/*.{0,1000}\/fleetdm\/fleet\/releases\/download\/.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7218
169*/fleetdm/fleet/releases/latest*.{0,1000}\/fleetdm\/fleet\/releases\/latest.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z7219
170*/FreeFileSync.exe*.{0,1000}\/FreeFileSync\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7247
171*/FreeFileSync.tar.gz*.{0,1000}\/FreeFileSync\.tar\.gz.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7248
172*/FreeFileSync_*.tar.gz*.{0,1000}\/FreeFileSync_.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7249
173*/FreeFileSync_*_Windows_Setup.exe*.{0,1000}\/FreeFileSync_.{0,1000}_Windows_Setup\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7250
174*/FreeFileSync_x64.exe*.{0,1000}\/FreeFileSync_x64\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7251
175*/FreeFileSyncPortable_*.exe*.{0,1000}\/FreeFileSyncPortable_.{0,1000}\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A7252
176*/frp.git*.{0,1000}\/frp\.git.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7258
177*/frp_0.*.*_darwin_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7259
178*/frp_0.*.*_darwin_arm64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_darwin_arm64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7260
179*/frp_0.*.*_freebsd_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_freebsd_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7261
180*/frp_0.*.*_linux_amd64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_amd64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7262
181*/frp_0.*.*_linux_arm.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7263
182*/frp_0.*.*_linux_arm64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_arm64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7264
183*/frp_0.*.*_linux_mips.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7265
184*/frp_0.*.*_linux_mips64.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7266
185*/frp_0.*.*_linux_mips64le.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mips64le\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7267
186*/frp_0.*.*_linux_mipsle.tar.gz*.{0,1000}\/frp_0\..{0,1000}\..{0,1000}_linux_mipsle\.tar\.gz.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11#linuxN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7268
187*/frpc.exe*.{0,1000}\/frpc\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z7270
188*/github.com*.exe?raw=true*.{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7414
189*/github.com/*/archive/refs/tags/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7415
190*/github.com/*/raw/main/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7416
191*/github.com/*/raw/main/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7417
192*/github.com/*/raw/main/*.app*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7418
193*/github.com/*/raw/main/*.as*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7419
194*/github.com/*/raw/main/*.asc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7420
195*/github.com/*/raw/main/*.asp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7421
196*/github.com/*/raw/main/*.bash*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11#linuxgreyware tool - risks of False positive !910N/AN/AN/AN/A7422
197*/github.com/*/raw/main/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7423
198*/github.com/*/raw/main/*.beacon*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7424
199*/github.com/*/raw/main/*.bin*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7425
200*/github.com/*/raw/main/*.bpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7426
201*/github.com/*/raw/main/*.c*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7427
202*/github.com/*/raw/main/*.cer*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7428
203*/github.com/*/raw/main/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7429
204*/github.com/*/raw/main/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7430
205*/github.com/*/raw/main/*.cpp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7431
206*/github.com/*/raw/main/*.crt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7432
207*/github.com/*/raw/main/*.cs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7433
208*/github.com/*/raw/main/*.csh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7434
209*/github.com/*/raw/main/*.dat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7435
210*/github.com/*/raw/main/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7436
211*/github.com/*/raw/main/*.docm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7437
212*/github.com/*/raw/main/*.dos*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7438
213*/github.com/*/raw/main/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7439
214*/github.com/*/raw/main/*.go*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7440
215*/github.com/*/raw/main/*.gz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7441
216*/github.com/*/raw/main/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7442
217*/github.com/*/raw/main/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7443
218*/github.com/*/raw/main/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7444
219*/github.com/*/raw/main/*.js*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7445
220*/github.com/*/raw/main/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7446
221*/github.com/*/raw/main/*.log*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7447
222*/github.com/*/raw/main/*.mac*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7448
223*/github.com/*/raw/main/*.mam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7449
224*/github.com/*/raw/main/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7450
225*/github.com/*/raw/main/*.msp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7451
226*/github.com/*/raw/main/*.nexe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7452
227*/github.com/*/raw/main/*.nim*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7453
228*/github.com/*/raw/main/*.otm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7454
229*/github.com/*/raw/main/*.out*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7455
230*/github.com/*/raw/main/*.ova*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7456
231*/github.com/*/raw/main/*.pem*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7457
232*/github.com/*/raw/main/*.pfx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7458
233*/github.com/*/raw/main/*.pl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7459
234*/github.com/*/raw/main/*.plx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7460
235*/github.com/*/raw/main/*.pm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7461
236*/github.com/*/raw/main/*.ppk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7462
237*/github.com/*/raw/main/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7463
238*/github.com/*/raw/main/*.psm1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7464
239*/github.com/*/raw/main/*.pub*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7465
240*/github.com/*/raw/main/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7466
241*/github.com/*/raw/main/*.pyc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7467
242*/github.com/*/raw/main/*.pyo*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7468
243*/github.com/*/raw/main/*.rar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7469
244*/github.com/*/raw/main/*.raw*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7470
245*/github.com/*/raw/main/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7471
246*/github.com/*/raw/main/*.rgs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7472
247*/github.com/*/raw/main/*.RGS*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7473
248*/github.com/*/raw/main/*.run*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7474
249*/github.com/*/raw/main/*.scpt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7475
250*/github.com/*/raw/main/*.script*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7476
251*/github.com/*/raw/main/*.sct*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7477
252*/github.com/*/raw/main/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7478
253*/github.com/*/raw/main/*.ssh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7479
254*/github.com/*/raw/main/*.sys*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7480
255*/github.com/*/raw/main/*.teamserver*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7481
256*/github.com/*/raw/main/*.temp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7482
257*/github.com/*/raw/main/*.tgz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7483
258*/github.com/*/raw/main/*.tmp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7484
259*/github.com/*/raw/main/*.vb*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7485
260*/github.com/*/raw/main/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7486
261*/github.com/*/raw/main/*.vbscript*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7487
262*/github.com/*/raw/main/*.ws*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7488
263*/github.com/*/raw/main/*.wsf*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7489
264*/github.com/*/raw/main/*.wsh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7490
265*/github.com/*/raw/main/*.X86*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7491
266*/github.com/*/raw/main/*.X86_64*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7492
267*/github.com/*/raw/main/*.xlam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7493
268*/github.com/*/raw/main/*.xlm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7494
269*/github.com/*/raw/main/*.xlsm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7495
270*/github.com/*/raw/main/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7496
271*/github.com/*/raw/refs/heads/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7497
272*/github.com/*/raw/refs/heads/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7498
273*/github.com/*/raw/refs/heads/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7499
274*/github.com/*/raw/refs/heads/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7500
275*/github.com/*/raw/refs/heads/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7501
276*/github.com/*/raw/refs/heads/*.cpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7502
277*/github.com/*/raw/refs/heads/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7503
278*/github.com/*/raw/refs/heads/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7504
279*/github.com/*/raw/refs/heads/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7505
280*/github.com/*/raw/refs/heads/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7506
281*/github.com/*/raw/refs/heads/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7507
282*/github.com/*/raw/refs/heads/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7508
283*/github.com/*/raw/refs/heads/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7509
284*/github.com/*/raw/refs/heads/*.pif*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7510
285*/github.com/*/raw/refs/heads/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7511
286*/github.com/*/raw/refs/heads/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7512
287*/github.com/*/raw/refs/heads/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7513
288*/github.com/*/raw/refs/heads/*.scr*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7514
289*/github.com/*/raw/refs/heads/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7515
290*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7516
291*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7517
292*/github.com/*/raw/refs/heads/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7518
293*/go-gost/core/*.{0,1000}\/go\-gost\/core\/.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7563
294*/go-http-tunnel.git.git*.{0,1000}\/go\-http\-tunnel\.git\.git.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel11N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z7564
295*/go-http-tunnel/cmd/*.{0,1000}\/go\-http\-tunnel\/cmd\/.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel11N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z7565
296*/go-localtunnel.git*.{0,1000}\/go\-localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/NoahShen/gotunnelme11N/AN/A1010171452018-01-06T04:41:15Z2013-10-18T02:46:51Z7570
297*/GoodSync-vsub-Setup.exe*.{0,1000}\/GoodSync\-vsub\-Setup\.exe.{0,1000}greyware_tool_keywordGoodsyncGoodSync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/AN/AData Exfiltrationhttps://www.goodsync.com/11N/AN/A910N/AN/AN/AN/A7579
298*/gost.tar.gz*.{0,1000}\/gost\.tar\.gz.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7597
299*/gost/raw/master/install.sh*.{0,1000}\/gost\/raw\/master\/install\.sh.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7598
300*/gost/releases/download/*.tar.gz*.{0,1000}\/gost\/releases\/download\/.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z7599
301*/gotunnelme.git*.{0,1000}\/gotunnelme\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/NoahShen/gotunnelme11N/AN/A1010171452018-01-06T04:41:15Z2013-10-18T02:46:51Z7603
302*/gt-win-x86_64.exe*.{0,1000}\/gt\-win\-x86_64\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z7682
303*/host-7.2.2.0.msi*.{0,1000}\/host\-7\.2\.2\.0\.msi.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A7810
304*/hypertunnel.git*.{0,1000}\/hypertunnel\.git.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7992
305*/hypertunnel-tcp-relay*.tar.gz*.{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7993
306*/hypertunnel-tcp-relay*.zip*.{0,1000}\/hypertunnel\-tcp\-relay.{0,1000}\.zip.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z7994
307*/install-fleetctl.sh*.{0,1000}\/install\-fleetctl\.sh.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z8101
308*/interactsh/*.{0,1000}\/interactsh\/.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C5T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8106
309*/interactsh-client*.{0,1000}\/interactsh\-client.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C6T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8107
310*/interactsh-collaborator*.{0,1000}\/interactsh\-collaborator.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C15T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8108
311*/interactsh-server*.{0,1000}\/interactsh\-server.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C8T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z8109
312*/Invoke-Maldaptive.git*.{0,1000}\/Invoke\-Maldaptive\.git.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive11N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z8153
313*/IObitUnlocker.exe*.{0,1000}\/IObitUnlocker\.exe.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#11N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A8172
314*/ipscan.exe*.{0,1000}\/ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8199
315*/ipscan.git*.{0,1000}\/ipscan\.git.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8200
316*/jprq.git*.{0,1000}\/jprq\.git.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8251
317*/jprq-darwin-arm64*.{0,1000}\/jprq\-darwin\-arm64.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8255
318*/jprq-linux-386*.{0,1000}\/jprq\-linux\-386.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8256
319*/jprq-linux-arm64*.{0,1000}\/jprq\-linux\-arm64.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8257
320*/jprq-windows-386.exe*.{0,1000}\/jprq\-windows\-386\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8258
321*/jprq-windows-amd64.exe*.{0,1000}\/jprq\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z8259
322*/lansearch.exe*.{0,1000}\/lansearch\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A8435
323*/LansweeperSetup_*.exe*.{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/11N/AN/A67N/AN/AN/AN/A8436
324*/latest/download/tunwg*.{0,1000}\/latest\/download\/tunwg.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z8453
325*/level-windows-amd64.exe*.{0,1000}\/level\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A8492
326*/level-windows-arm64.exe*.{0,1000}\/level\-windows\-arm64\.exe.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A8493
327*/LMI_Rescue.exe*.{0,1000}\/LMI_Rescue\.exe.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A8558
328*/LMIRTechConsole.exe*.{0,1000}\/LMIRTechConsole\.exe.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A8559
329*/localtunnel.git*.{0,1000}\/localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8596
330*/localtunnel.git*.{0,1000}\/localtunnel\.git.{0,1000}greyware_tool_keywordlocaltunnelsclient for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/localtunnel11N/AN/A8102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8597
331*/localtunnel.js*.{0,1000}\/localtunnel\.js.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z8598
332*/localtunnel-server.git*.{0,1000}\/localtunnel\-server\.git.{0,1000}greyware_tool_keywordlocaltunnelsserver for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/server11N/AN/A810316310332024-03-20T09:14:46Z2013-06-16T22:30:48Z8600
333*/loclx.exe*.{0,1000}\/loclx\.exe.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A8606
334*/loclx-windows-amd64.zip*.{0,1000}\/loclx\-windows\-amd64\.zip.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A8607
335*/lsa-whisperer-*.zip*.{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8658
336*/lsa-whisperer.git*.{0,1000}\/lsa\-whisperer\.git.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8659
337*/LTProxy.git*.{0,1000}\/LTProxy\.git.{0,1000}greyware_tool_keywordLTProxyLinux Transparent Proxy (Similar to Proxifiter)T1090 - T1573.001 - T1571 - T1071.001TA0010 - TA0005N/AN/AData Exfiltrationhttps://github.com/L-codes/LTProxy11#linuxN/A1013152024-11-27T05:09:47Z2021-11-11T15:17:54Z8660
338*/MEGAclient.exe*.{0,1000}\/MEGAclient\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8734
339*/MEGAcmd.exe*.{0,1000}\/MEGAcmd\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8735
340*/MEGAcmd.sh*.{0,1000}\/MEGAcmd\.sh.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8736
341*/MEGAcmdServer.exe*.{0,1000}\/MEGAcmdServer\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8737
342*/MEGAcmdSetup.exe*.{0,1000}\/MEGAcmdSetup\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8738
343*/MEGAcmdSetup32.exe*.{0,1000}\/MEGAcmdSetup32\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8739
344*/MEGAcmdSetup64.exe*.{0,1000}\/MEGAcmdSetup64\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8740
345*/MEGAcmdSetup64.exe*.{0,1000}\/MEGAcmdSetup64\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8741
346*/MEGAcmdShell.exe*.{0,1000}\/MEGAcmdShell\.exe.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z8742
347*/megasync.exe*.{0,1000}\/megasync\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8744
348*/MEGAsyncSetup32.exe*.{0,1000}\/MEGAsyncSetup32\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8745
349*/MEGAsyncSetup64.exe*.{0,1000}\/MEGAsyncSetup64\.exe.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11N/AN/A1010N/AN/AN/AN/A8746
350*/MeshAgent.git*.{0,1000}\/MeshAgent\.git.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshAgent11N/AN/A103264962025-03-19T18:43:56Z2017-10-12T21:26:52Z8775
351*/MeshCentral.git*.{0,1000}\/MeshCentral\.git.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8776
352*/meshinstall.sh*.{0,1000}\/meshinstall\.sh.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8778
353*/meshinstall-bsd-rcd.sh*.{0,1000}\/meshinstall\-bsd\-rcd\.sh.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z8779
354*/Microsoft Azure Storage Explorer.app*.{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.app.{0,1000}greyware_tool_keywordAzure Storage Explorerlegitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data ExfiltrationT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ARhysidaData Exfiltrationhttps://azure.microsoft.com/en-us/products/storage/storage-explorer11N/AN/A810N/AN/AN/AN/A8812
355*/Microsoft Azure Storage Explorer.zip*.{0,1000}\/Microsoft\sAzure\sStorage\sExplorer\.zip.{0,1000}greyware_tool_keywordAzure Storage Explorerlegitimate microsoft software - threat actors have been abusing Azure Storage Explorer for Data ExfiltrationT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ARhysidaData Exfiltrationhttps://azure.microsoft.com/en-us/products/storage/storage-explorer11N/AN/A810N/AN/AN/AN/A8813
356*/MITMPluginLogViewer*.{0,1000}\/MITMPluginLogViewer.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z8865
357*/MITMServerHijacking*.{0,1000}\/MITMServerHijacking.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z8867
358*/mzcv-x64.zip*.{0,1000}\/mzcv\-x64\.zip.{0,1000}greyware_tool_keywordMozillaCookiesViewnirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actorsT1070 - T1552.001 - T1125 - T1005TA0009 - TA0005N/AMuddyWaterCredential Accesshttps://www.nirsoft.net/utils/mzcv.html11N/AN/A710N/AN/AN/AN/A8994
359*/nats-rmm.conf*.{0,1000}\/nats\-rmm\.conf.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z9019
360*/neoreg.py*.{0,1000}\/neoreg\.py.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9047
361*/Neo-reGeorg.git*.{0,1000}\/Neo\-reGeorg\.git.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9048
362*/NeoreGeorg.java*.{0,1000}\/NeoreGeorg\.java.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9049
363*/Neo-reGeorg/tarball*.{0,1000}\/Neo\-reGeorg\/tarball.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9050
364*/Neo-reGeorg/zipball*.{0,1000}\/Neo\-reGeorg\/zipball.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z9051
365*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/Anetwork exploitation tool610N/AN/AN/AN/A9108
366*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9109
367*/netscan_linux.tar.gz*.{0,1000}\/netscan_linux\.tar\.gz.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#linuxN/A810N/AN/AN/AN/A9110
368*/netscan_macos.dmg*.{0,1000}\/netscan_macos\.dmg.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#macosN/A810N/AN/AN/AN/A9111
369*/netscan_setup.exe*.{0,1000}\/netscan_setup\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9112
370*/netscan64.exe*.{0,1000}\/netscan64\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9113
371*/netshrun.c*.{0,1000}\/netshrun\.c.{0,1000}greyware_tool_keywordNetshRunNetsh.exe relies on extensions taken from Registry which means it may be used as a persistence and you go one step further extending netsh with a DLL allowing you to do whatever you wantT1546.008 - T1112 - T1037 - T1055 - T1218.001TA0003 - TA0002 - TA0008N/AN/AExploitation toolhttps://github.com/gtworek/PSBits/blob/master/NetShRun11N/AN/AN/A1033375422025-03-12T19:59:23Z2019-06-29T13:22:36Z9117
372*/ngrok.git*.{0,1000}\/ngrok\.git.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9137
373*/ngrok.go*.{0,1000}\/ngrok\.go.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9138
374*/ngrokd.go*.{0,1000}\/ngrokd\.go.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z9140
375*/NimScan.exe*.{0,1000}\/NimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9175
376*/NimScan.git*.{0,1000}\/NimScan\.git.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9176
377*/NimScan.nim*.{0,1000}\/NimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9177
378*/nircmd.exe*.{0,1000}\/nircmd\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9184
379*/nircmd.zip*.{0,1000}\/nircmd\.zip.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9185
380*/nircmdc.exe*.{0,1000}\/nircmdc\.exe.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9186
381*/nircmd-x64.zip*.{0,1000}\/nircmd\-x64\.zip.{0,1000}greyware_tool_keywordnircmdNirsoft tool - NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interfaceT1059 - T1036TA0005 - TA0002 - TA0003N/AN/ADefense Evasionhttps://www.nirsoft.net/utils/nircmd.html11N/AN/A1010N/AN/AN/AN/A9187
382*/Nmap/folder/check15*.{0,1000}\/Nmap\/folder\/check15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9198
383*/Nmap/folder/check16*.{0,1000}\/Nmap\/folder\/check16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9199
384*/Nmap/folder/check17*.{0,1000}\/Nmap\/folder\/check17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9200
385*/nmaplowercheck15*.{0,1000}\/nmaplowercheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://nmap.org/book/nse-usage.html11N/Awill appear on your server access logs if you are scanned by nmap810N/AN/AN/AN/A9204
386*/nmaplowercheck16*.{0,1000}\/nmaplowercheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9205
387*/nmaplowercheck17*.{0,1000}\/nmaplowercheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9206
388*/nmap-scada*.{0,1000}\/nmap\-scada.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9208
389*/NmapUpperCheck15*.{0,1000}\/NmapUpperCheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9209
390*/NmapUpperCheck16*.{0,1000}\/NmapUpperCheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9210
391*/NmapUpperCheck17*.{0,1000}\/NmapUpperCheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9211
392*/nmap-vulners*.{0,1000}\/nmap\-vulners.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9212
393*/nse-install.git*.{0,1000}\/nse\-install\.git.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z9260
394*/nspowershell.exe*.{0,1000}\/nspowershell\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A9264
395*/nssadmui.exe*.{0,1000}\/nssadmui\.exe.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A9265
396*/OfflineSamTool.exe*.{0,1000}\/OfflineSamTool\.exe.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9370
397*/openvpn.exe*.{0,1000}\/openvpn\.exe.{0,1000}greyware_tool_keywordOPENVPNOpenVPN is a legitimate tool that might be used by an adversary to maintain persistence or exfiltrate dataT1071 - T1573 - T1133TA0003 - TA0008 - TA0011N/AN/ADefense Evasionhttps://openvpn.net/11#VPNN/A68N/AN/AN/AN/A9396
398*/oset.exe*.{0,1000}\/oset\.exe.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9447
399*/oset.zip*.{0,1000}\/oset\.zip.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140611N/AN/A1010N/AN/AN/AN/A9448
400*/OshiUpload.git*.{0,1000}\/OshiUpload\.git.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload11#filehostingservice #P2PN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z9450
401*/PAExec.cpp*.{0,1000}\/PAExec\.cpp.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9480
402*/paexec.exe.{0,1000}\/paexec\.exegreyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9481
403*/PAExec.git*.{0,1000}\/PAExec\.git.{0,1000}greyware_tool_keywordPAExecPAExec is a freely-redistributable re-implementation of SysInternal/Microsoft's popular PsExec programT1047 - T1105 - T1204TA0003 - TA0008 - TA0040N/AN/ALateral Movementhttps://github.com/poweradminllc/PAExec11N/AN/A1065601772025-02-21T15:14:44Z2013-11-13T04:05:27Z9482
404*/pagekite.py*.{0,1000}\/pagekite\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9486
405*/pagekite-0.3.21.py*.{0,1000}\/pagekite\-0\.3\.21\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9487
406*/pagekite-0.4.6a.py*.{0,1000}\/pagekite\-0\.4\.6a\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9488
407*/pagekite-0.5.6d.py*.{0,1000}\/pagekite\-0\.5\.6d\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9489
408*/pagekite-0.5.8a.py*.{0,1000}\/pagekite\-0\.5\.8a\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9490
409*/pagekite-gtk.py*.{0,1000}\/pagekite\-gtk\.py.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z9491
410*/PCHunter.exe*.{0,1000}\/PCHunter\.exe.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A9569
411*/PCHunter_free.zip*.{0,1000}\/PCHunter_free\.zip.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A9570
412*/PCMonitorManager.exe*.{0,1000}\/PCMonitorManager\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9573
413*/PCMonitorSrv.exe*.{0,1000}\/PCMonitorSrv\.exe.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9574
414*/pcmontask.exe*.{0,1000}\/pcmontask\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A9575
415*/pcmrdp-client.dll*.{0,1000}\/pcmrdp\-client\.dll.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A9576
416*/pcunlocker.iso*.{0,1000}\/pcunlocker\.iso.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A9577
417*/pcunlocker_trial.zip*.{0,1000}\/pcunlocker_trial\.zip.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A9578
418*/pgrok.exe*.{0,1000}\/pgrok\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok11N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z9651
419*/pgrok.git*.{0,1000}\/pgrok\.git.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok11N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9652
420*/pgrokd.exe*.{0,1000}\/pgrokd\.exe.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/jerson/pgrok11N/AN/A1010283552022-05-30T14:53:46Z2019-07-31T13:23:51Z9654
421*/pgrokd_*.zip*.{0,1000}\/pgrokd_.{0,1000}\.zip.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok11N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z9656
422*/pingcastle.git*.{0,1000}\/pingcastle\.git.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9695
423*/PingCastle.zip*.{0,1000}\/PingCastle\.zip.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9696
424*/pingcastle/releases/download/*.{0,1000}\/pingcastle\/releases\/download\/.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scannerT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://github.com/netwrix/pingcastle11N/AN/A101024863032025-02-28T10:16:24Z2018-08-31T17:42:48Z9697
425*/PortQry.exe*.{0,1000}\/PortQry\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9748
426*/PortQryV2.exe*.{0,1000}\/PortQryV2\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9749
427*/portr.exe*.{0,1000}\/portr\.exe.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9750
428*/portr.git*.{0,1000}\/portr\.git.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9751
429*/portr/releases*.{0,1000}\/portr\/releases.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9752
430*/portr_*_Darwin_arm64.zip*.{0,1000}\/portr_.{0,1000}_Darwin_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9753
431*/portr_*_Darwin_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Darwin_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9754
432*/portr_*_Linux_arm64.zip*.{0,1000}\/portr_.{0,1000}_Linux_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9755
433*/portr_*_Linux_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Linux_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11#linuxN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9756
434*/portr_*_Windows_arm64.zip*.{0,1000}\/portr_.{0,1000}_Windows_arm64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9757
435*/portr_*_Windows_x86_64.zip*.{0,1000}\/portr_.{0,1000}_Windows_x86_64\.zip.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9758
436*/portr_admin/*.py*.{0,1000}\/portr_admin\/.{0,1000}\.py.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z9759
437*/privoxy.exe*.{0,1000}\/privoxy\.exe.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z9904
438*/Procdump.zip*.{0,1000}\/Procdump\.zip.{0,1000}greyware_tool_keywordProcdumpdump lsass process with procdumpT1003.001TA0006N/ALockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - DispossessorCredential Accesshttps://learn.microsoft.com/en-us/sysinternals/downloads/procdump11N/AN/A1010N/AN/AN/AN/A9907
439*/processhacker-*-bin.zip*.{0,1000}\/processhacker\-.{0,1000}\-bin\.zip.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9910
440*/processhacker/files/latest/download*.{0,1000}\/processhacker\/files\/latest\/download.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9911
441*/ProduKey.exe*.{0,1000}\/ProduKey\.exe.{0,1000}greyware_tool_keywordprodukeyProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.T1003.001 - T1003.002 - T1012 - T1057 - T1518TA0006 - TA0007 - TA0009N/AEvilnumCredential Accesshttps://www.nirsoft.net/utils/product_cd_key_viewer.html11N/AN/A610N/AN/AN/AN/A9915
442*/Proxifier.exe*.{0,1000}\/Proxifier\.exe.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9929
443*/ProxifierPE.zip*.{0,1000}\/ProxifierPE\.zip.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9931
444*/ProxifierSetup.exe*.{0,1000}\/ProxifierSetup\.exe.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A9932
445*/ps2exe.ps1*.{0,1000}\/ps2exe\.ps1.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill11N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z9952
446*/pslist.exe*.{0,1000}\/pslist\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9972
447*/pslist64.exe*.{0,1000}\/pslist64\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9973
448*/pulseway_x64.deb*.{0,1000}\/pulseway_x64\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10002
449*/Pulseway_x64.msi*.{0,1000}\/Pulseway_x64\.msi.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10003
450*/pulseway_x86.deb*.{0,1000}\/pulseway_x86\.deb.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A10004
451*/py2exe/*.{0,1000}\/py2exe\/.{0,1000}greyware_tool_keywordpy2exepy2exe allows you to convert Python scripts into standalone executable files for Windows othen used by attackerT1027.002 - T1045 - T1059.001 - T1587.001TA0005 - TA0042Operation WocaoN/AResource Developmenthttps://github.com/py2exe/py2exe11N/Agreyware_tools high risks of false positivesN/A109271022024-11-12T19:44:34Z2019-03-11T13:16:35Z10061
452*/pyjam.as/tunnel*.{0,1000}\/pyjam\.as\/tunnel.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel11N/AN/A1010N/AN/AN/AN/A10070
453*/PyPagekite.git*.{0,1000}\/PyPagekite\.git.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10083
454*/PyPagekite/tarball/*.{0,1000}\/PyPagekite\/tarball\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10084
455*/PyPagekite/zipball/*.{0,1000}\/PyPagekite\/zipball\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z10085
456*/pyshark.git*.{0,1000}\/pyshark\.git.{0,1000}greyware_tool_keywordpysharkPython wrapper for tshark allowing python packet parsing using wireshark dissectorsT1040 - T1213 - T1105 - T1572TA0009 - TA0007N/AN/ADiscoveryhttps://github.com/KimiNewt/pyshark11N/AN/A61023554392024-12-04T15:41:20Z2013-12-28T14:38:22Z10096
457*/QNAP_NAS/megacmdpkg*.{0,1000}\/QNAP_NAS\/megacmdpkg.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z10116
458*/Quasar.git*.{0,1000}\/Quasar\.git.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10125
459*/Quasar.v*.zip*.{0,1000}\/Quasar\.v.{0,1000}\.zip.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10126
460*/Quasar/releases*.{0,1000}\/Quasar\/releases.{0,1000}greyware_tool_keywordQuasarOpen-Source Remote Administration Tool for Windows. Quasar is a fast and light-weight remote administration tool coded in C#.T1548.002 - T1547.001 - T1059.003 - T1555 - T1005 - T1573.001 - T1564.001 - T1564.003 - T1105 - T1056.001 - T1112 - T1095 - T1571 - T1090 - T1021.001 - T1053.005 - T1553.002 - T1082 - T1614 - T1016 - T1033 - T1552.001 - T1125TA0002 - TA0003 - TA0005 - TA0006 - TA0008 - TA0009 - TA0011 - TA0040N/APatchwork - LazyScripter - Gorgon Group - menuPass - BackdoorDiplomacy - Earth Berberoka - APT33 - APT32 - Operation C-Major - QUILTED TIGER - MoleratsRMMhttps://github.com/quasar/Quasar11N/AN/AN/A10918725512024-02-29T06:37:37Z2014-07-08T12:27:59Z10127
461*/Quick Assist Installer.exe*.{0,1000}\/Quick\sAssist\sInstaller\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A10129
462*/Quick%20Assist%20Installer.exe*.{0,1000}\/Quick\%20Assist\%20Installer\.exe.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A10130
463*/Radmin.exe*.{0,1000}\/Radmin\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10142
464*/Radmin_Server_*.msi*.{0,1000}\/Radmin_Server_.{0,1000}\.msi.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10143
465*/Radmin_Viewer_*.msi*.{0,1000}\/Radmin_Viewer_.{0,1000}\.msi.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10144
466*/Radmin_VPN_1.*.exe*.{0,1000}\/Radmin_VPN_1\..{0,1000}\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10145
467*/rathole.exe.{0,1000}\/rathole\.exegreyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10168
468*/rathole.git*.{0,1000}\/rathole\.git.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10169
469*/rathole/src/*.{0,1000}\/rathole\/src\/.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10170
470*/rathole-aarch64-*.{0,1000}\/rathole\-aarch64\-.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10171
471*/rathole-arm*.{0,1000}\/rathole\-arm.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10172
472*/rathole-main/*.{0,1000}\/rathole\-main\/.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10173
473*/rathole-mipsel-*.{0,1000}\/rathole\-mipsel\-.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10174
474*/rathole-x86_64*.{0,1000}\/rathole\-x86_64.{0,1000}greyware_tool_keywordrathole expose the service on the device behind the NAT to the Internet, via a server with a public IP.T1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/rapiz1/rathole11N/AN/A1010105805492024-07-06T20:09:48Z2021-12-14T05:03:07Z10175
475*/raw/main/speedtest.exe*.{0,1000}\/raw\/main\/speedtest\.exe.{0,1000}greyware_tool_keywordspeedtestlegitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration effortsT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 Dispossessor - Dagon LockerData Exfiltrationhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A67N/AN/AN/AN/A10185
476*/raw/master/speedtest.exe*.{0,1000}\/raw\/master\/speedtest\.exe.{0,1000}greyware_tool_keywordspeedtestlegitimate tool from speedtest.net abused by threat actors to assess the network speed and determine the feasibility and duration of their exfiltration effortsT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 Dispossessor - Dagon LockerData Exfiltrationhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A67N/AN/AN/AN/A10188
477*/rclone.git*.{0,1000}\/rclone\.git.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10200
478*/rclone.rar*.{0,1000}\/rclone\.rar.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10201
479*/rclone.zip*.{0,1000}\/rclone\.zip.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10202
480*/rclone/releases/download/*.{0,1000}\/rclone\/releases\/download\/.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z10203
481*/rdpscan.git*.{0,1000}\/rdpscan\.git.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10223
482*/rdpscan-macos.zip*.{0,1000}\/rdpscan\-macos\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10224
483*/rdpscan-windows.zip*.{0,1000}\/rdpscan\-windows\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10225
484*/RDPWInst.exe*.{0,1000}\/RDPWInst\.exe.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10235
485*/RDPWInst-v*.msi*.{0,1000}\/RDPWInst\-v.{0,1000}\.msi.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10236
486*/rdpwrap.dll*.{0,1000}\/rdpwrap\.dll.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10237
487*/rdpwrap.git*.{0,1000}\/rdpwrap\.git.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10238
488*/RDPWrap-v*.zip*.{0,1000}\/RDPWrap\-v.{0,1000}\.zip.{0,1000}greyware_tool_keywordrdpwrapRDP Wrapper Library used by malwaresT1021TA0008N/AN/ALateral Movementhttps://github.com/stascorp/rdpwrap11N/AN/A10101533239112024-06-18T15:08:33Z2014-10-22T23:18:28Z10239
489*/RealTimeSync.exe*.{0,1000}\/RealTimeSync\.exe.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11N/AN/A910N/AN/AN/AN/A10246
490*/RedTeaming-Tactics-and-Techniques.git*.{0,1000}\/RedTeaming\-Tactics\-and\-Techniques\.git.{0,1000}greyware_tool_keywordired.teamRed Teaming Tactics and TechniquesT1593.003TA0043N/AN/AReconnaissancehttps://github.com/mantvydasb/RedTeaming-Tactics-and-Techniques11N/AN/A710423410712024-08-22T07:17:31Z2019-03-02T13:33:33Z10302
491*/release/gt-win-x86_64.exe*.{0,1000}\/release\/gt\-win\-x86_64\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z10336
492*/release/sshx-server*.{0,1000}\/release\/sshx\-server.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z10337
493*/releases/download/Ahk2Exe*.{0,1000}\/releases\/download\/Ahk2Exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z10339
494*/RemCom.exe*.{0,1000}\/RemCom\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10352
495*/RemCom.git*.{0,1000}\/RemCom\.git.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10353
496*/RemComSvc.exe*.{0,1000}\/RemComSvc\.exe.{0,1000}greyware_tool_keywordRemComRemote Command Executor: A OSS replacement for PsExec and RunAsT1077 - T1059 - T1021 - T1569.002TA0002 - TA0005 - TA0008N/AAPT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando Lateral Movementhttps://github.com/kavika13/RemCom11N/AN/A1043461002017-10-30T04:48:38Z2011-11-09T11:00:09Z10354
497*/Remote.It-Installer-*.{0,1000}\/Remote\.It\-Installer\-.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10356
498*/RemoteControlSetup.exe*.{0,1000}\/RemoteControlSetup\.exe.{0,1000}greyware_tool_keywordComodoRMM (Itarian RMM)Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://one.comodo.com/11N/AN/A1010N/AN/AN/AN/A10369
499*/RemoteDesktop.exe*.{0,1000}\/RemoteDesktop\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A10370
500*/remoteit.exe*.{0,1000}\/remoteit\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10373
501*/remoteit.x86-win.exe*.{0,1000}\/remoteit\.x86\-win\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10374
502*/remoteit/connectd/releases*.{0,1000}\/remoteit\/connectd\/releases.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z10375
503*/remoteit/desktop*.{0,1000}\/remoteit\/desktop.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10376
504*/remoteit-desktop.exe*.{0,1000}\/remoteit\-desktop\.exe.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/desktop11N/AN/A101046112025-04-11T23:19:29Z2019-01-12T00:59:20Z10377
505*/remotemoe.git*.{0,1000}\/remotemoe\.git.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z10382
506*/remotepc.deb*.{0,1000}\/remotepc\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10384
507*/remotepc.deb*.{0,1000}\/remotepc\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10385
508*/RemotePC.exe*.{0,1000}\/RemotePC\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10386
509*/RemotePC.exe*.{0,1000}\/RemotePC\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10387
510*/RemotePC.lnk*.{0,1000}\/RemotePC\.lnk.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10388
511*/RemotePC.tmp*.{0,1000}\/RemotePC\.tmp.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10389
512*/remotepc-attended.deb*.{0,1000}\/remotepc\-attended\.deb.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10390
513*/RemotePCAttended.dmg*.{0,1000}\/RemotePCAttended\.dmg.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11#macosN/A1010N/AN/AN/AN/A10391
514*/remotepclauncher.exe*.{0,1000}\/remotepclauncher\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10392
515*/RemotePCSuite.dmg*.{0,1000}\/RemotePCSuite\.dmg.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11#macosN/A1010N/AN/AN/AN/A10393
516*/remotepcuiu.exe*.{0,1000}\/remotepcuiu\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10394
517*/RemotePCViewer.msi*.{0,1000}\/RemotePCViewer\.msi.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A10395
518*/restic-*.tar.gz*.{0,1000}\/restic\-.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10424
519*/restic.exe*.{0,1000}\/restic\.exe.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10425
520*/restic/releases/download/*.{0,1000}\/restic\/releases\/download\/.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10426
521*/restic_*_windows_amd64.zip*.{0,1000}\/restic_.{0,1000}_windows_amd64\.zip.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10427
522*/restic-master/*.{0,1000}\/restic\-master\/.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z10428
523*/reverse-tunnel.git*.{0,1000}\/reverse\-tunnel\.git.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10451
524*/reverse-tunnel/agent/cmd*.{0,1000}\/reverse\-tunnel\/agent\/cmd.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10452
525*/reverse-tunnel/server/service*.{0,1000}\/reverse\-tunnel\/server\/service.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10453
526*/RevoUninProSetup.exe*.{0,1000}\/RevoUninProSetup\.exe.{0,1000}greyware_tool_keywordRevoUninstallerlegitimate tool abused by the Dispossessor ransomware groupT1562.001 - T1112 - T1059 - T1036TA0005 - TA0040N/ADispossessorDefense Evasionhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A1010N/AN/AN/AN/A10457
527*/rfusclient.exe*.{0,1000}\/rfusclient\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10472
528*/rmm/api/tacticalrmm/*.{0,1000}\/rmm\/api\/tacticalrmm\/.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z10487
529*/rmm-installer.ps1*.{0,1000}\/rmm\-installer\.ps1.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z10488
530*/RpcDND_Console.exe*.{0,1000}\/RpcDND_Console\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10540
531*/rpcdownloader.exe*.{0,1000}\/rpcdownloader\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10541
532*/RPCFireWallRule.exe*.{0,1000}\/RPCFireWallRule\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10545
533*/rpcperfviewer.exe*.{0,1000}\/rpcperfviewer\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10549
534*/RPCProxyLatency.exe*.{0,1000}\/RPCProxyLatency\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A10550
535*/rserver3.exe*.{0,1000}\/rserver3\.exe.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A10554
536*/rsocks.git*.{0,1000}\/rsocks\.git.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10556
537*/rsocks/releases/download/*.{0,1000}\/rsocks\/releases\/download\/.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10559
538*/rsocks_linux_amd64*.{0,1000}\/rsocks_linux_amd64.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11#linuxN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10560
539*/rsocks_windows_386.exe*.{0,1000}\/rsocks_windows_386\.exe.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z10561
540*/rtun-freebsd-amd64*.{0,1000}\/rtun\-freebsd\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10580
541*/rtun-linux-amd64*.{0,1000}\/rtun\-linux\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10581
542*/rtun-linux-arm64*.{0,1000}\/rtun\-linux\-arm64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10582
543*/rtun-mac-amd64*.{0,1000}\/rtun\-mac\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10583
544*/rtun-server-freebsd-amd64*.{0,1000}\/rtun\-server\-freebsd\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10584
545*/rtun-server-linux-amd64*.{0,1000}\/rtun\-server\-linux\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10585
546*/rtun-server-linux-arm64*.{0,1000}\/rtun\-server\-linux\-arm64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11#linuxN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10586
547*/rtun-server-mac-amd64*.{0,1000}\/rtun\-server\-mac\-amd64.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10587
548*/rtun-server-windows-amd64.exe*.{0,1000}\/rtun\-server\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10588
549*/rtun-windows-amd64.exe*.{0,1000}\/rtun\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordreverse-tunnelrtun is a tool for exposing TCP and UDP ports to the Internet via a public gateway server. You can expose ssh and mosh server on a machine behind firewall and NAT.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/snsinfu/reverse-tunnel11N/AN/A1010217422023-10-15T07:29:32Z2018-07-09T21:41:50Z10589
550*/RustDesk.exe*.{0,1000}\/RustDesk\.exe.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10639
551*/rustdesk.git*.{0,1000}\/rustdesk\.git.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10640
552*/rustdesk/rustdesk/releases/*.{0,1000}\/rustdesk\/rustdesk\/releases\/.{0,1000}greyware_tool_keywordRustDeskRustdesk open suorce remote control software abused by scammersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AAkira - Scattered Spider*RMMhttps://github.com/rustdesk/rustdesk11N/AN/A101087186123342025-04-22T15:18:36Z2020-09-28T15:36:08Z10641
553*/rutserv.exe*.{0,1000}\/rutserv\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10649
554*/rutview.exe*.{0,1000}\/rutview\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A10650
555*/sdelete.exe*.{0,1000}\/sdelete\.exe.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10747
556*/SDelete.zip*.{0,1000}\/SDelete\.zip.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10748
557*/sdelete64.exe*.{0,1000}\/sdelete64\.exe.{0,1000}greyware_tool_keywordsdeleteSDelete is an application that securely deletes data in a way that makes it unrecoverable.- abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10749
558*/sdelete64a.exe*.{0,1000}\/sdelete64a\.exe.{0,1000}greyware_tool_keywordsdeletedelete one or more files and/or directories, or to cleanse the free space on a logical disk - abused by attackersT1485 - T1070.004TA0005 - TA0040 N/AAPT29 - Sandworm - Cobalt Group - FIN5 - Silence - BOSS SPIDERDefense Evasionhttps://learn.microsoft.com/en-us/sysinternals/downloads/sdelete11N/AN/A610N/AN/AN/AN/A10750
559*/send.exploit.in/*.{0,1000}\/send\.exploit\.in\/.{0,1000}greyware_tool_keywordsend.exploit.infile-sharing platform used by ransomware groupsT1567TA0010N/ABlack BastaData Exfiltrationhttps://www.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf11#filehostingserviceN/A1010N/AN/AN/AN/A10784
560*/SetACL.exe*.{0,1000}\/SetACL\.exe.{0,1000}greyware_tool_keywordSetACLManage Windows permissions from the command lineT1069 - T1222TA0002 - TA0004 - TA0005N/AN/ADefense Evasionhttps://helgeklein.com/download/11N/AN/A610N/AN/AN/AN/A10810
561*/SetACL64..exe*.{0,1000}\/SetACL64\.\.exe.{0,1000}greyware_tool_keywordSetACLManage Windows permissions from the command lineT1069 - T1222TA0002 - TA0004 - TA0005N/AN/ADefense Evasionhttps://helgeklein.com/download/11N/AN/A610N/AN/AN/AN/A10811
562*/set-proxy.ps1*.{0,1000}\/set\-proxy\.ps1.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z10814
563*/Shadowsocks-*.zip*.{0,1000}\/Shadowsocks\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10839
564*/Shadowsocks.zip*.{0,1000}\/Shadowsocks\.zip.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10840
565*/shadowsocks-rust.default*.{0,1000}\/shadowsocks\-rust\.default.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10843
566*/shadowsocks-rust.git*.{0,1000}\/shadowsocks\-rust\.git.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10844
567*/shadowsocks-rust.init*.{0,1000}\/shadowsocks\-rust\.init.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10845
568*/shadowsocks-rust.service*.{0,1000}\/shadowsocks\-rust\.service.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10846
569*/shadowsocks-service*.{0,1000}\/shadowsocks\-service.{0,1000}greyware_tool_keywordshadowsocksRust port - shadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-rust11N/AN/A1010931212732025-04-21T14:29:22Z2014-10-15T11:02:36Z10847
570*/shadowsocks-windows.git*.{0,1000}\/shadowsocks\-windows\.git.{0,1000}greyware_tool_keywordshadowsocksshadowsocks is a fast tunnel proxy that helps you bypass firewallsT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/shadowsocks/shadowsocks-windows11N/AN/A101058770163682025-01-01T08:09:55Z2013-01-14T07:54:16Z10848
571*/simplehelper64.exe*.{0,1000}\/simplehelper64\.exe.{0,1000}greyware_tool_keywordSimpleHelpSimpleHelp is an RMM tool that has been exploited by attackers to gain unauthorized remote access T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackCatRMMsimple-help.com11N/AN/A1010N/AN/AN/AN/A11275
572*/SirTunnel.git*.{0,1000}\/SirTunnel\.git.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z11296
573*/sirtunnel.py*.{0,1000}\/sirtunnel\.py.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z11297
574*/sish.git*.{0,1000}\/sish\.git.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish11N/AN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z11299
575*/SoftEtherVPN-*.tar.xz*.{0,1000}\/SoftEtherVPN\-.{0,1000}\.tar\.xz.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11494
576*/SoftEtherVPN.git*.{0,1000}\/SoftEtherVPN\.git.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNabused https://asec.ahnlab.com/en/66843/8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11495
577*/SoftEtherVPN/releases/tag/*.{0,1000}\/SoftEtherVPN\/releases\/tag\/.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11496
578*/softether-vpnclient-*.exe*.{0,1000}\/softether\-vpnclient\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11497
579*/softether-vpnserver-*.deb*.{0,1000}\/softether\-vpnserver\-.{0,1000}\.deb.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11498
580*/softether-vpnserver_*.exe*.{0,1000}\/softether\-vpnserver_.{0,1000}\.exe.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z11500
581*/SolarWinds-Dameware-DRS-St.exe*.{0,1000}\/SolarWinds\-Dameware\-DRS\-St\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/ADameware Remote Support1010N/AN/AN/AN/A11502
582*/sources.list.d/tailscale.list*.{0,1000}\/sources\.list\.d\/tailscale\.list.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11506
583*/sshtunnel.git*.{0,1000}\/sshtunnel\.git.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11617
584*/sshtunnel.py*.{0,1000}\/sshtunnel\.py.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11618
585*/sshtunnel/tarball/*.{0,1000}\/sshtunnel\/tarball\/.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11619
586*/sshtunnel/zipball/*.{0,1000}\/sshtunnel\/zipball\/.{0,1000}greyware_tool_keywordsshtunnelSSH tunnels to remote serverT1572 - T1219TA0005 - TA0010 - TA0011N/AN/ADefense Evasionhttps://github.com/pahaz/sshtunnel11N/AN/A101012561862024-03-10T15:20:42Z2014-06-11T21:14:05Z11620
587*/sshuttle.git*.{0,1000}\/sshuttle\.git.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11621
588*/sshuttle.py*.{0,1000}\/sshuttle\.py.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11622
589*/sshuttle/tarball*.{0,1000}\/sshuttle\/tarball.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11623
590*/sshuttle/zipball*.{0,1000}\/sshuttle\/zipball.{0,1000}greyware_tool_keywordsshuttleTransparent proxy server that works as a poor man's VPN. Forwards over sshT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/sshuttle/sshuttle11#linuxN/A1010122007542025-04-04T20:48:27Z2014-09-15T04:51:13Z11624
591*/sshx-server/*.{0,1000}\/sshx\-server\/.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z11626
592*/stunnel-latest.tar.gz*.{0,1000}\/stunnel\-latest\.tar\.gz.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11692
593*/stunnel-latest-android.zip*.{0,1000}\/stunnel\-latest\-android\.zip.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11693
594*/stunnel-latest-win64-installer.exe*.{0,1000}\/stunnel\-latest\-win64\-installer\.exe.{0,1000}greyware_tool_keywordstunnelStunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the programsT1573 - T1071 - T1090TA0010 - TA0011 - TA0003N/AAPT37 - APT38 - KimsukyC2https://www.stunnel.org/index.html11N/AN/A78N/AN/AN/AN/A11694
595*/suo5.git*.{0,1000}\/suo5\.git.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11718
596*/suo5/releases/*.{0,1000}\/suo5\/releases\/.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11719
597*/suo5-darwin-amd64*.{0,1000}\/suo5\-darwin\-amd64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11720
598*/suo5-darwin-arm64*.{0,1000}\/suo5\-darwin\-arm64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11721
599*/suo5-gui-darwin.app.zip*.{0,1000}\/suo5\-gui\-darwin\.app\.zip.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11722
600*/suo5-gui-linux*.{0,1000}\/suo5\-gui\-linux.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11723
601*/suo5-gui-windows.exe*.{0,1000}\/suo5\-gui\-windows\.exe.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11724
602*/suo5-linux-amd64*.{0,1000}\/suo5\-linux\-amd64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11725
603*/suo5-linux-arm64*.{0,1000}\/suo5\-linux\-arm64.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511#linuxN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11726
604*/suo5-windows-amd64.exe*.{0,1000}\/suo5\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z11727
605*/Supremo.exe*.{0,1000}\/Supremo\.exe.{0,1000}greyware_tool_keywordSupremoSupremo - Remote access softwareT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/ABlack BastaRMMhttps://www.supremocontrol.com11N/AN/A1010N/AN/AN/AN/A11736
606*/syncthing.exe*.{0,1000}\/syncthing\.exe.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11N/Ahttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z11754
607*/syncthing/releases/latest*.{0,1000}\/syncthing\/releases\/latest.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11N/Ahttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z11755
608*/syncthing-linux-*.{0,1000}\/syncthing\-linux\-.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11#linuxhttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z11756
609*/tacticalagent-v*-*.exe*.{0,1000}\/tacticalagent\-v.{0,1000}\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11779
610*/tacticalagent-v*-linux-arm.exe*.{0,1000}\/tacticalagent\-v.{0,1000}\-linux\-arm\.exe.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11#linuxN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11780
611*/tacticalagent-v*-windows-amd64.exe*.{0,1000}\/tacticalagent\-v.{0,1000}\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11781
612*/tacticalrmm.exe*.{0,1000}\/tacticalrmm\.exe.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11782
613*/tacticalrmm.git*.{0,1000}\/tacticalrmm\.git.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11783
614*/tacticalrmm/master/install.sh*.{0,1000}\/tacticalrmm\/master\/install\.sh.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11784
615*/tacticalrmm/releases/latest*.{0,1000}\/tacticalrmm\/releases\/latest.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11785
616*/tacticalrmm-web.git*.{0,1000}\/tacticalrmm\-web\.git.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z11786
617*/tailscale.exe*.{0,1000}\/tailscale\.exe.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11789
618*/tailscale/client/*.{0,1000}\/tailscale\/client\/.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11791
619*/tailscale:unstable*.{0,1000}\/tailscale\:unstable.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11793
620*/tailscale_*_*.deb*.{0,1000}\/tailscale_.{0,1000}_.{0,1000}\.deb.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11794
621*/tailscale_*_*.tgz*.{0,1000}\/tailscale_.{0,1000}_.{0,1000}\.tgz.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11795
622*/tailscaled.defaults*.{0,1000}\/tailscaled\.defaults.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11796
623*/tailscaled.go*.{0,1000}\/tailscaled\.go.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11797
624*/tailscaled.sock*.{0,1000}\/tailscaled\.sock.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11798
625*/tailscale-setup-*-*.msi*.{0,1000}\/tailscale\-setup\-.{0,1000}\-.{0,1000}\.msi.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11799
626*/tailscale-setup-*.exe*.{0,1000}\/tailscale\-setup\-.{0,1000}\.exe.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11800
627*/TDSSKiller.exe*.{0,1000}\/TDSSKiller\.exe.{0,1000}greyware_tool_keywordTDSKillerTDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - AvaddonDefense Evasionhttps://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html11N/AN/A810N/AN/AN/AN/A11828
628*/tdsskiller.zip*.{0,1000}\/tdsskiller\.zip.{0,1000}greyware_tool_keywordTDSKillerTDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - AvaddonDefense Evasionhttps://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html11N/AN/A810N/AN/AN/AN/A11829
629*/test_tailscale.sh*.{0,1000}\/test_tailscale\.sh.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z11865
630*/tightvnc-*.msi*.{0,1000}\/tightvnc\-.{0,1000}\.msi.{0,1000}greyware_tool_keywordtightvncTightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.tightvnc.com11N/AN/A1010N/AN/AN/AN/A11919
631*/tkc_agent_dre.deb*.{0,1000}\/tkc_agent_dre\.deb.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A11931
632*/tmate-ssh-server.*.{0,1000}\/tmate\-ssh\-server\..{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate-ssh-server11#linuxN/A10106421482024-06-21T11:52:24Z2013-06-09T23:58:55Z11936
633*/tmate-ssh-server.git*.{0,1000}\/tmate\-ssh\-server\.git.{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate-ssh-server11#linuxN/A10106421482024-06-21T11:52:24Z2013-06-09T23:58:55Z11937
634*/tmate-ssh-server/releases/*.{0,1000}\/tmate\-ssh\-server\/releases\/.{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate-ssh-server11#linuxN/A10106421482024-06-21T11:52:24Z2013-06-09T23:58:55Z11938
635*/tunnel.nosocket.php*.{0,1000}\/tunnel\.nosocket\.php.{0,1000}greyware_tool_keywordNeo-reGeorgNeo-reGeorg is a project that seeks to aggressively refactor reGeorgT1090 - T1095 - T1572TA0003 - TA0011 - TA0005 - TA0010N/AIRIDIUMData Exfiltrationhttps://github.com/L-codes/Neo-reGeorg11N/AN/A101030494552025-02-18T07:26:54Z2019-07-08T14:25:42Z12129
636*/tunneld.service*.{0,1000}\/tunneld\.service.{0,1000}greyware_tool_keywordgo-http-tunnelFast and secure tunnels over HTTP/2T1572TA0011 - TA0003N/AN/AC2https://github.com/mmatczuk/go-http-tunnel11N/AN/A101032613082025-04-16T21:49:57Z2016-10-12T12:59:38Z12135
637*/tunneller.git*.{0,1000}\/tunneller\.git.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12136
638*/tunneller/releases/*.{0,1000}\/tunneller\/releases\/.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12137
639*/tunneller-darwin-amd64*.{0,1000}\/tunneller\-darwin\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12138
640*/tunneller-darwin-amd64*.{0,1000}\/tunneller\-darwin\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12139
641*/tunneller-darwin-amd64*.{0,1000}\/tunneller\-darwin\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12140
642*/tunneller-darwin-amd64*.{0,1000}\/tunneller\-darwin\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12141
643*/tunneller-darwin-i386*.{0,1000}\/tunneller\-darwin\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12142
644*/tunneller-darwin-i386*.{0,1000}\/tunneller\-darwin\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12143
645*/tunneller-darwin-i386*.{0,1000}\/tunneller\-darwin\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12144
646*/tunneller-darwin-i386*.{0,1000}\/tunneller\-darwin\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12145
647*/tunneller-freebsd-amd64*.{0,1000}\/tunneller\-freebsd\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12146
648*/tunneller-freebsd-amd64*.{0,1000}\/tunneller\-freebsd\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12147
649*/tunneller-freebsd-amd64*.{0,1000}\/tunneller\-freebsd\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12148
650*/tunneller-freebsd-amd64*.{0,1000}\/tunneller\-freebsd\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12149
651*/tunneller-freebsd-i386*.{0,1000}\/tunneller\-freebsd\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12150
652*/tunneller-freebsd-i386*.{0,1000}\/tunneller\-freebsd\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12151
653*/tunneller-freebsd-i386*.{0,1000}\/tunneller\-freebsd\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12152
654*/tunneller-freebsd-i386*.{0,1000}\/tunneller\-freebsd\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11N/AN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12153
655*/tunneller-linux-amd64*.{0,1000}\/tunneller\-linux\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12154
656*/tunneller-linux-amd64*.{0,1000}\/tunneller\-linux\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12155
657*/tunneller-linux-amd64*.{0,1000}\/tunneller\-linux\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12156
658*/tunneller-linux-amd64*.{0,1000}\/tunneller\-linux\-amd64.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12157
659*/tunneller-linux-i386*.{0,1000}\/tunneller\-linux\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12158
660*/tunneller-linux-i386*.{0,1000}\/tunneller\-linux\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12159
661*/tunneller-linux-i386*.{0,1000}\/tunneller\-linux\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12160
662*/tunneller-linux-i386*.{0,1000}\/tunneller\-linux\-i386.{0,1000}greyware_tool_keywordtunnellerTunneller allows you to expose services which are running on localhost or on your local network to the public internet.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/skx/tunneller11#linuxN/A1010487412024-08-13T07:36:22Z2019-04-21T11:05:11Z12161
663*/tunnelmole-client.git*.{0,1000}\/tunnelmole\-client\.git.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z12164
664*/tunnelmole-service*.{0,1000}\/tunnelmole\-service.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z12165
665*/tunnelmole-service.git*.{0,1000}\/tunnelmole\-service\.git.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z12166
666*/tunnelto.git*.{0,1000}\/tunnelto\.git.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z12168
667*/tunnelto/releases/latest*.{0,1000}\/tunnelto\/releases\/latest.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z12169
668*/tunnelto_server*.{0,1000}\/tunnelto_server.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z12170
669*/tunnelto_server/*.{0,1000}\/tunnelto_server\/.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z12171
670*/tunwg.exe*.{0,1000}\/tunwg\.exe.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z12175
671*/tunwg.git*.{0,1000}\/tunwg\.git.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z12176
672*/tunwg@latest*.{0,1000}\/tunwg\@latest.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z12177
673*/tunwg-arm64.exe*.{0,1000}\/tunwg\-arm64\.exe.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z12178
674*/unlocker-setup.exe*.{0,1000}\/unlocker\-setup\.exe.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#11N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A12231
675*/updog-*.tar.gz*.{0,1000}\/updog\-.{0,1000}\.tar\.gz.{0,1000}greyware_tool_keywordupdogUpdog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth.T1567 - T1074.001 - T1020TA0010 - TA0009N/AN/AData Exfiltrationhttps://github.com/sc0tfree/updog11N/AN/A91030523142024-03-13T15:52:39Z2020-02-18T15:29:21Z12243
676*/updog.git*.{0,1000}\/updog\.git.{0,1000}greyware_tool_keywordupdogUpdog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth.T1567 - T1074.001 - T1020TA0010 - TA0009N/AN/AData Exfiltrationhttps://github.com/sc0tfree/updog11N/AN/A91030523142024-03-13T15:52:39Z2020-02-18T15:29:21Z12244
677*/updog/archive/updog-*.{0,1000}\/updog\/archive\/updog\-.{0,1000}greyware_tool_keywordupdogUpdog is a replacement for SimpleHTTPServer. It allows uploading and downloading via HTTP/S can set ad hoc SSL certificates and use http basic auth.T1567 - T1074.001 - T1020TA0010 - TA0009N/AN/AData Exfiltrationhttps://github.com/sc0tfree/updog11N/AN/A91030523142024-03-13T15:52:39Z2020-02-18T15:29:21Z12245
678*/uvs_v415eng.zip*.{0,1000}\/uvs_v415eng\.zip.{0,1000}greyware_tool_keywordUniversal Virus SnifferUniversal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/APhobosDefense Evasionhttps://www.majorgeeks.com/files/details/universal_virus_sniffer.html11N/AN/A810N/AN/AN/AN/A12390
679*/vbs2exe.exe*.{0,1000}\/vbs2exe\.exe.{0,1000}greyware_tool_keywordredpillAssist reverse tcp shells in post-exploration tasksT1082 - T1016 - T1049 - T1057 - T1489 - T1070 - T1562 - T1563 - T1119 - T1518 - T1602 - T1530 - T1113 - T1125 - T1105 - T1133 - T1056 - T1114 - T1539 - T1552 - T1214 - T1110 - T1040 - T1436 - T1068 - T1088 - T1564 - T1112 - T1547 - T1574 - T1204 - T1215 - T1046 - T1557 - T1136 - T1059 - T1127 - T1555 - T1548 - T1115 - T1003TA0007 - TA0003 - TA0005 - TA0009 - TA0002 - TA0006 - TA0004 - TA0010 - TA0011N/AN/AExploitation toolhttps://github.com/r00t-3xp10it/redpill11N/AN/A103218522024-03-19T15:03:16Z2021-02-20T23:59:07Z12424
680*/viewerhostkeypopup.exe*.{0,1000}\/viewerhostkeypopup\.exe.{0,1000}greyware_tool_keywordRemotePCRemotePC RMM tool - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.remotedesktop.com/11N/AN/A1010N/AN/AN/AN/A12446
681*/VncSharp.exe*.{0,1000}\/VncSharp\.exe.{0,1000}greyware_tool_keywordVncSharpVncSharp is a GPL implementation of the VNC Remote Framebuffer (RFB) Protocol for the .NET FrameworkT1021.001 - T1219 - T1071.001TA0007 - TA0008CarbanakFIN7 - CarbanakLateral Movementhttps://github.com/humphd/VncSharp11N/AN/A832461792019-02-18T16:04:27Z2012-03-05T15:23:41Z12471
682*/VncSharp.git*.{0,1000}\/VncSharp\.git.{0,1000}greyware_tool_keywordVncSharpVncSharp is a GPL implementation of the VNC Remote Framebuffer (RFB) Protocol for the .NET FrameworkT1021.001 - T1219 - T1071.001TA0007 - TA0008CarbanakFIN7 - CarbanakLateral Movementhttps://github.com/humphd/VncSharp11N/AN/A832461792019-02-18T16:04:27Z2012-03-05T15:23:41Z12472
683*/VPDAgent.exe*.{0,1000}\/VPDAgent\.exe.{0,1000}greyware_tool_keywordRemoteUtilitiesRemoteUtilities Remote Access softwaresT1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090TA0003 - TA0008 - TA0011N/ARagnarLocker - MuddyWater - UAC-0050RMMhttps://www.remoteutilities.com/11N/AN/A1010N/AN/AN/AN/A12482
684*/VSAX_x64.msi*.{0,1000}\/VSAX_x64\.msi.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A12483
685*/vsxrc-clip.exe*.{0,1000}\/vsxrc\-clip\.exe.{0,1000}greyware_tool_keywordkaseya VSAKaseya VSA (Virtual System Administrator) is a cloud-based IT management and remote monitoring software designed for managed service providers (MSPs) and IT departments -it is abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.kaseya.com/products/vsa/11N/AN/A1010N/AN/AN/AN/A12486
686*/webhook.site.git*.{0,1000}\/webhook\.site\.git.{0,1000}greyware_tool_keywordwebhook.sitetest HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmationT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/webhooksite/webhook.site11N/AN/A101058064572025-04-04T10:42:59Z2016-03-21T08:45:42Z12535
687*/webvulnscan1*.exe*.{0,1000}\/webvulnscan1.{0,1000}\.exe.{0,1000}greyware_tool_keywordAcunetix Web Vulnerability ScannerVulnerability Scanner abused by threat actorsT1190 - T1046 - T1210 - T1213TA0001 - TA0008 - TA0009N/AClever Kitten - EMBER BEARVulnerability Scannerhttps://www.acunetix.com/vulnerability-scanner/11N/AN/A89N/AN/AN/AN/A12554
688*/webvulnscan2*.exe*.{0,1000}\/webvulnscan2.{0,1000}\.exe.{0,1000}greyware_tool_keywordAcunetix Web Vulnerability ScannerVulnerability Scanner abused by threat actorsT1190 - T1046 - T1210 - T1213TA0001 - TA0008 - TA0009N/AClever Kitten - EMBER BEARVulnerability Scannerhttps://www.acunetix.com/vulnerability-scanner/11N/AN/A89N/AN/AN/AN/A12555
689*/webvulnscan3*.exe*.{0,1000}\/webvulnscan3.{0,1000}\.exe.{0,1000}greyware_tool_keywordAcunetix Web Vulnerability ScannerVulnerability Scanner abused by threat actorsT1190 - T1046 - T1210 - T1213TA0001 - TA0008 - TA0009N/AClever Kitten - EMBER BEARVulnerability Scannerhttps://www.acunetix.com/vulnerability-scanner/11N/AN/A89N/AN/AN/AN/A12556
690*/Win7Taskbar.dll*.{0,1000}\/Win7Taskbar\.dll.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A12585
691*/Wireguard.zip*.{0,1000}\/Wireguard\.zip.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12654
692*/wireguard-amd64-*.msi*.{0,1000}\/wireguard\-amd64\-.{0,1000}\.msi.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12655
693*/wireguard-installer.exe*.{0,1000}\/wireguard\-installer\.exe.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12656
694*/wireguard-installer.rar*.{0,1000}\/wireguard\-installer\.rar.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12657
695*/wireproxy.conf*.{0,1000}\/wireproxy\.conf.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12659
696*/wireproxy.git*.{0,1000}\/wireproxy\.git.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11N/AN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12660
697*/wireproxy.service*.{0,1000}\/wireproxy\.service.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12661
698*/wireproxy/releases/*.{0,1000}\/wireproxy\/releases\/.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11N/AN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12662
699*/wireproxy_darwin*.{0,1000}\/wireproxy_darwin.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12663
700*/wireproxy_linux_*.{0,1000}\/wireproxy_linux_.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11#linuxN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12664
701*/wireproxy_windows*.{0,1000}\/wireproxy_windows.{0,1000}greyware_tool_keywordwireproxyWireguard client that exposes itself as a socks5 proxyT1572 - T1090 - T1071.004TA0011 - TA0005N/AN/AC2https://github.com/pufferffish/wireproxy11N/AN/A101048932992025-04-16T22:58:51Z2022-03-11T12:32:10Z12665
702*/wiretap.Dockerfile*.{0,1000}\/wiretap\.Dockerfile.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12672
703*/wiretap.exe*.{0,1000}\/wiretap\.exe.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12673
704*/wiretap.git*.{0,1000}\/wiretap\.git.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12674
705*/wiretap/releases/download/*.{0,1000}\/wiretap\/releases\/download\/.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12676
706*/wiretap_*_linux_386.tar.gz*.{0,1000}\/wiretap_.{0,1000}_linux_386\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11#linuxN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12677
707*/wiretap_*_linux_amd64.tar.gz*.{0,1000}\/wiretap_.{0,1000}_linux_amd64\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11#linuxN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12678
708*/wiretap_*_linux_arm64.tar.gz*.{0,1000}\/wiretap_.{0,1000}_linux_arm64\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11#linuxN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12679
709*/wiretap_*_linux_armv6.tar.gz*.{0,1000}\/wiretap_.{0,1000}_linux_armv6\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11#linuxN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12680
710*/wiretap_*_windows_386.tar.gz*.{0,1000}\/wiretap_.{0,1000}_windows_386\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12681
711*/wiretap_*_windows_amd64.tar.gz*.{0,1000}\/wiretap_.{0,1000}_windows_amd64\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12682
712*/wiretap_*_windows_arm64.tar.gz*.{0,1000}\/wiretap_.{0,1000}_windows_arm64\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12683
713*/wiretap_*_windows_armv6.tar.gz*.{0,1000}\/wiretap_.{0,1000}_windows_armv6\.tar\.gz.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/AC2https://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z12684
714*/x86_64-pc-windows-msvc/release/gt.exe*.{0,1000}\/x86_64\-pc\-windows\-msvc\/release\/gt\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z12757
715*/x86_64-pc-windows-msvc/release/gt.exe*.{0,1000}\/x86_64\-pc\-windows\-msvc\/release\/gt\.exe.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z12758
716*/xmrig-*-gcc-win64.zip*.{0,1000}\/xmrig\-.{0,1000}\-gcc\-win64\.zip.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/11N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z12772
717*/xmrig.exe*.{0,1000}\/xmrig\.exe.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/11N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z12773
718*/xmrig.git*.{0,1000}\/xmrig\.git.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/11N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z12774
719*/yak_darwin_amd64.zip*.{0,1000}\/yak_darwin_amd64\.zip.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11#linuxN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z12796
720*/yak_linux_amd64.zip*.{0,1000}\/yak_linux_amd64\.zip.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11#linuxN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z12797
721*/yak_windows_amd64.zip*.{0,1000}\/yak_windows_amd64\.zip.{0,1000}greyware_tool_keywordyakitsecurity platform with fuzzers - webshell and MITM (chinese burp)T1557 - T1557.003 - T1569.002TA0001 - TA0040N/AN/ASniffing & Spoofinghttps://github.com/Gerenios/AADInternals11N/AN/A71014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z12798
722*/ZA_Connect.exe*.{0,1000}\/ZA_Connect\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A12802
723*/ZAAudioClient.exe*.{0,1000}\/ZAAudioClient\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A12803
724*/ZAFileTransfer.exe*.{0,1000}\/ZAFileTransfer\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A12804
725*/ZAService.exe*.{0,1000}\/ZAService\.exe.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A12805
726*/zrok.exe*.{0,1000}\/zrok\.exe.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z12819
727*/zrok.git*.{0,1000}\/zrok\.git.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z12820
728*/zrok.zip*.{0,1000}\/zrok\.zip.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z12821
729*/zrok-amd64_darwin_amd64*.{0,1000}\/zrok\-amd64_darwin_amd64.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z12822
730*/zrok-arm64_darwin_arm64*.{0,1000}\/zrok\-arm64_darwin_arm64.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11#linuxN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z12823
731*:8040/SetupWizard.aspx*.{0,1000}\:8040\/SetupWizard\.aspx.{0,1000}greyware_tool_keywordScreenConnectConnectWise Control formerly known as Screenconnect is a remote desktop software application.T1021.001 - T1133TA0008 - TA0009 - TA0010 - TA0011N/ABlack Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater RMMhttps://screenconnect.connectwise.com/download11N/AN/A1010N/AN/AN/AN/A12861
732*:8070/tomcat/code/suo5.jsp*.{0,1000}\:8070\/tomcat\/code\/suo5\.jsp.{0,1000}greyware_tool_keywordsuo5http proxy tunneling toolT1071 - T1073 - T1075 - T1105 - T1571TA0008 - TA0011N/AN/AC2https://github.com/zema1/suo511N/AN/A101023322172025-04-14T03:33:51Z2022-11-22T11:45:26Z12863
733*:9001/proxy/mdmserver1/account*.{0,1000}\:9001\/proxy\/mdmserver1\/account.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z12866
734*@email.webhook.site*.{0,1000}\@email\.webhook\.site.{0,1000}greyware_tool_keywordwebhook.sitetest HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmationT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/webhooksite/webhook.site11N/AN/A101058064572025-04-04T10:42:59Z2016-03-21T08:45:42Z12877
735*159.69.126.209*.{0,1000}159\.69\.126\.209.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z22267
736*3proxy/3proxy*.{0,1000}3proxy\/3proxy.{0,1000}greyware_tool_keyword3proxy3proxy - tiny free proxy serverT1090 - T1583 - T1001 - T1132TA0040 - TA0001 - TA0005 - TA0006N/ALazarus GroupDefense Evasionhttps://github.com/3proxy/3proxy11N/AN/A81042128172025-04-16T18:29:51Z2014-04-08T08:59:11Z25293
737*-443.devtunnels.ms*.{0,1000}\-443\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A25624
738*4shared.com/*upload*.{0,1000}4shared\.com\/.{0,1000}upload.{0,1000}greyware_tool_keyword4shared.comUploading on 4shared.comT1105 - T1567 - T1071TA0010 N/ATurlaData Exfiltration4shared.com11#filehostingserviceN/A98N/AN/AN/AN/A26469
739*5ety7tpkim5me6eszuwcje7bmy25pbtrjtue7zkqqgziljwqy3rrikqd.onion*.{0,1000}5ety7tpkim5me6eszuwcje7bmy25pbtrjtue7zkqqgziljwqy3rrikqd\.onion.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload11#filehostingservice #P2PN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z27610
740*625ae9460120.ngrok.io*.{0,1000}625ae9460120\.ngrok\.io.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z27826
741*7k3j6g3h67l23j345wennkoc4a2223rhjkba22o77ihzdj3achwa.remote.moe*.{0,1000}7k3j6g3h67l23j345wennkoc4a2223rhjkba22o77ihzdj3achwa\.remote\.moe.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z29864
742*a.aomeisoftware.com*.{0,1000}a\.aomeisoftware\.com.{0,1000}greyware_tool_keywordanyvieweraccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyviewer.com11N/AN/A1010N/AN/AN/AN/A32143
743*AADInternals.exe*.{0,1000}AADInternals\.exe.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z32935
744*AADInternals.pdb*.{0,1000}AADInternals\.pdb.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z32936
745*AADInternals.psd1*.{0,1000}AADInternals\.psd1.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z32937
746*AADInternals.psm1*.{0,1000}AADInternals\.psm1.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z32938
747*Ab4y98/VerySimpleAnyDeskBackdoor*.{0,1000}Ab4y98\/VerySimpleAnyDeskBackdoor.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps111N/Asimple backdoor with anydesk101102025-04-17T19:04:37Z2023-12-05T22:08:51Z32983
748*ACLScanner.exe*.{0,1000}ACLScanner\.exe.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commandsT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/vletoux/pingcastle11N/AN/A1010N/AN/AN/AN/A33142
749*acontrol.atera.com*.{0,1000}acontrol\.atera\.com.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A33147
750*action1_agent.exe*.{0,1000}action1_agent\.exe.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/AN/A1010N/AN/AN/AN/A33161
751*action1_remote.exe*.{0,1000}action1_remote\.exe.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/AN/A1010N/AN/AN/AN/A33163
752*action1_update.exe*.{0,1000}action1_update\.exe.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/AN/A1010N/AN/AN/AN/A33164
753*activate.netsupportsoftware.com*.{0,1000}activate\.netsupportsoftware\.com.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A33166
754*adexplorer.exe*.{0,1000}adexplorer\.exe.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer11N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A33396
755*adexplorer.zip*.{0,1000}adexplorer\.zip.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer11N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A33398
756*adexplorer64.exe*.{0,1000}adexplorer64\.exe.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer11N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A33399
757*adexplorer64a.exe*.{0,1000}adexplorer64a\.exe.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer11N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A33400
758*adfind.bat*.{0,1000}adfind\.bat.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A33417
759*adfind.exe*.{0,1000}adfind\.exe.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A33427
760*adiskreader.disks.raw*.{0,1000}adiskreader\.disks\.raw.{0,1000}greyware_tool_keywordadiskreaderAsync Python library to parse local and remote disk imagesT1020 - T1048 - T1074 - T1560.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://github.com/skelsec/adiskreader11N/AN/A417672025-03-15T19:48:39Z2023-12-18T11:54:31Z33447
761*adiskreader.disks.vhdx*.{0,1000}adiskreader\.disks\.vhdx.{0,1000}greyware_tool_keywordadiskreaderAsync Python library to parse local and remote disk imagesT1020 - T1048 - T1074 - T1560.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://github.com/skelsec/adiskreader11N/AN/A417672025-03-15T19:48:39Z2023-12-18T11:54:31Z33448
762*admin.*.swi-dre.com*.{0,1000}admin\..{0,1000}\.swi\-dre\.com.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A33456
763*ADRecon.ps1*.{0,1000}ADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AN/ADiscoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z33475
764*adrecon/ADRecon*.{0,1000}adrecon\/ADRecon.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z33476
765*ADRecon-master.zip*.{0,1000}ADRecon\-master\.zip.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z33478
766*Advanced Monitoring Agent HTTP Retriever 1.1*.{0,1000}Advanced\sMonitoring\sAgent\sHTTP\sRetriever\s1\.1.{0,1000}greyware_tool_keywordNsight RMMNsight RMM usageT1021 - T1219 - T1563 - T1608TA0002 - TA0008 - TA0011 - TA0040N/AScattered Spider*RMMhttps://www.n-able.com/products/n-sight-rmm11#useragentuser-agent1010N/AN/AN/AN/A33497
767*Advanced_IP_Scanner*.exe*.{0,1000}Advanced_IP_Scanner.{0,1000}\.exe.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox11N/AN/A710N/AN/AN/AN/A33500
768*advanced_ip_scanner_console.exe*.{0,1000}advanced_ip_scanner_console\.exe.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox11N/AN/A710N/AN/AN/AN/A33501
769*advanced_port_scanner.exe*.{0,1000}advanced_port_scanner\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A33502
770*advanced_port_scanner_console.exe*.{0,1000}advanced_port_scanner_console\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A33503
771*AeroAdmin_2.exe*.{0,1000}AeroAdmin_2\.exe.{0,1000}greyware_tool_keywordaeroadminRMM software - full remote control / file transferT1021.001 - T1048.003TA0008 - TA0011 - TA0009 - TA0010N/AN/ARMMhttps://ulm.aeroadmin.com/AeroAdmin.exe11N/AN/A1010N/AN/AN/AN/A33600
772*agent.fleetdeck.io/*?win*.{0,1000}agent\.fleetdeck\.io\/.{0,1000}\?win.{0,1000}greyware_tool_keywordfleetdeckFleetDeck is a Remote Desktop & Virtual Terminal solution tailored for techs to manage large fleets of computersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://fleetdeck.io/11N/AN/A1010N/AN/AN/AN/A33681
773*agent01.xeox.com*.{0,1000}agent01\.xeox\.com.{0,1000}greyware_tool_keywordxeoxEasily access and manage Windows devices remotely within XEOX - RMM abused by threat actorsT1021 - T1078 - T1219 - T1105 - T1046TA0011 - TA0010 - TA0003 - TA0005N/ADispossessorRMMhttps://xeox.com/remote-access/11N/AN/A1010N/AN/AN/AN/A33709
774*agent-api.atera.com*.{0,1000}agent\-api\.atera\.com.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A33710
775*agents.level.io*.{0,1000}agents\.level\.io.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A33714
776*agrinman/tap/tunnelto*.{0,1000}agrinman\/tap\/tunnelto.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z33728
777*agrinman/tunnelto*.{0,1000}agrinman\/tunnelto.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z33729
778*alt.meshcentral.com*.{0,1000}alt\.meshcentral\.com.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshCentral11N/AN/A101048746402025-04-21T16:50:06Z2017-08-28T16:21:11Z33821
779*amalshaji/portr*.{0,1000}amalshaji\/portr.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z33828
780*amalshaji/taps/portr*.{0,1000}amalshaji\/taps\/portr.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z33829
781*amidaware/tacticalrmm*.{0,1000}amidaware\/tacticalrmm.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z33835
782*anderspitman/SirTunnel*.{0,1000}anderspitman\/SirTunnel.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z33869
783*angryip/ipscan*.{0,1000}angryip\/ipscan.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z33884
784*AnydeskBackdoor.ps1*.{0,1000}AnydeskBackdoor\.ps1.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://github.com/Ab4y98/VerySimpleAnyDeskBackdoor/blob/main/AnydeskBackdoor.ps111N/Asimple backdoor with anydesk101102025-04-17T19:04:37Z2023-12-05T22:08:51Z33914
785*AnyplaceControlInstall.exe*.{0,1000}AnyplaceControlInstall\.exe.{0,1000}greyware_tool_keywordAnyplaceControlaccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyplace-control[.]com11N/AN/A1010N/AN/AN/AN/A33915
786*api.btunnel.in*.{0,1000}api\.btunnel\.in.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A33938
787*api.cyberghostvpn.com*.{0,1000}api\.cyberghostvpn\.com.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A33939
788*api.dataplicity.com*.{0,1000}api\.dataplicity\.com.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z33940
789*api.freefilesync.org*.{0,1000}api\.freefilesync\.org.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11#filehostingserviceN/A910N/AN/AN/AN/A33941
790*api.gofile.io/getServer*.{0,1000}api\.gofile\.io\/getServer.{0,1000}greyware_tool_keywordgofile.iolegitimate service abused by lots of stealer to exfiltrate dataT1567.002TA0010N/AHive - Royal - LockBit - Vice Society - BlackSuit - ContiData Exfiltrationhttps://gofile.io11#filehostingserviceN/A810N/AN/AN/AN/A33942
791*api.localxpose.io*.{0,1000}api\.localxpose\.io.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A33943
792*api.remot3.it*.{0,1000}api\.remot3\.it.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z33944
793*api.surfshark.com/*.{0,1000}api\.surfshark\.com\/.{0,1000}greyware_tool_keywordsurfshark VPNusage of surfsharkVPN clientT1090 - T1573TA0005 - TA010N/AN/ADefense Evasion11N/AN/A78N/AN/AN/AN/A33945
794*api.telegram.org*.{0,1000}api\.telegram\.org.{0,1000}greyware_tool_keywordtelegramtelegram API usage -given the increasing adoption of Telegram by malware for command and control (C2) operations. it's essential to monitor and restrict its usage within corporate networks and on company devicesT1071.004 - T1102 - T1047TA0011 - TA0002 - TA0005N/AGamaredonC2api.telegram.org01N/AHigh False positive Risk !19N/AN/AN/AN/A33946
795*api/v1/fleet/sso/callback*.{0,1000}api\/v1\/fleet\/sso\/callback.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z33948
796*api01.remot3.it*.{0,1000}api01\.remot3\.it.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z33952
797*api-telemetry.servers.getgo.com*.{0,1000}api\-telemetry\.servers\.getgo\.com.{0,1000}greyware_tool_keywordGoToMyPCGoToMyPC is remote desktop software that allows users to access computers remotely using a web browserT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AN/ARMMhttps://www.gotomypc.com/11N/AN/A1010N/AN/AN/AN/A33957
798*asapi.aweray.net*.{0,1000}asapi\.aweray\.net.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A34112
799*asse.rel.tunnels.api.visualstudio.com*.{0,1000}asse\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A34140
800*assist.zoho.com*.{0,1000}assist\.zoho\.com.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A34148
801*as-tk.aweray.com*.{0,1000}as\-tk\.aweray\.com.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A34161
802*as-tk.aweray.com/track*.{0,1000}as\-tk\.aweray\.com\/track.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A34162
803*ataylor32/duckdns-powershell*.{0,1000}ataylor32\/duckdns\-powershell.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A34171
804*atera_del.bat*.{0,1000}atera_del\.bat.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A34172
805*atera_del2.bat*.{0,1000}atera_del2\.bat.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A34173
806*auc1.rel.tunnels.api.visualstudio.com*.{0,1000}auc1\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A34250
807*aue.rel.tunnels.api.visualstudio.com*.{0,1000}aue\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A34254
808*aue.rel.tunnels.api.visualstudio.com*.{0,1000}aue\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keywordvscodebuilt-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices.T1090 - T1003 - T1571TA0010 - TA0002 - TA0009N/AN/AC2https://twitter.com/code/status/169986908707189966901N/AN/A1010N/AN/AN/AN/A34255
809*aue-data.rel.tunnels.api.visualstudio.com*.{0,1000}aue\-data\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keywordvscodebuilt-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices.T1090 - T1003 - T1571TA0010 - TA0002 - TA0009N/AN/AC2https://twitter.com/code/status/169986908707189966901N/AN/A1010N/AN/AN/AN/A34256
810*auth11.aeroadmin.com*.{0,1000}auth11\.aeroadmin\.com.{0,1000}greyware_tool_keywordaeroadminRMM software - full remote control / file transferT1021.001 - T1048.003TA0008 - TA0011 - TA0009 - TA0010N/AN/ARMMhttps://ulm.aeroadmin.com/AeroAdmin.exe11N/AN/A1010N/AN/AN/AN/A34262
811*AutoHotkey/Ahk2Exe*.{0,1000}AutoHotkey\/Ahk2Exe.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z34297
812*AutoHotkey/AutoHotkey*.{0,1000}AutoHotkey\/AutoHotkey.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z34298
813*AutoHotkeySC.bin*.{0,1000}AutoHotkeySC\.bin.{0,1000}greyware_tool_keywordAutoHotkeyAutoHotkey - macro-creation and automation-oriented scripting utility for WindowsT1056.001 - T1027 - T1059.001 - T1140TA0005 - TA0002N/AN/ADefense Evasionhttps://github.com/AutoHotkey/AutoHotkey11N/Aabused by multiple threat actors https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html - False positives expected6101018810012025-03-29T02:12:26Z2009-11-25T11:08:21Z34299
814*auvik.agent.exe*.{0,1000}auvik\.agent\.exe.{0,1000}greyware_tool_keywordauvikcloud-based network management softwareT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.auvik.com/11N/AN/A1010N/AN/AN/AN/A34326
815*AuvikService.exe*.{0,1000}AuvikService\.exe.{0,1000}greyware_tool_keywordauvikcloud-based network management softwareT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.auvik.com/11N/AN/A1010N/AN/AN/AN/A34327
816*Aweray_Remote.exe*.{0,1000}Aweray_Remote\.exe.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A34370
817*awerayimg.com*.{0,1000}awerayimg\.com.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A34371
818*AzureADConnectAuthenticationAgentService.exe*.{0,1000}AzureADConnectAuthenticationAgentService\.exe.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z34400
819*b4ldr/nse-scripts*.{0,1000}b4ldr\/nse\-scripts.{0,1000}greyware_tool_keywordnmapInstall and update external NSE script for nmapT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaVulnerability Scannerhttps://github.com/shadawck/nse-install11N/AN/A71712020-08-28T11:27:08Z2020-08-24T16:55:55Z34746
820*berstend/hypertunnel*.{0,1000}berstend\/hypertunnel.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z35818
821*beyondcode/expose*.{0,1000}beyondcode\/expose.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z35839
822*bfleegjcoffelppfmadimianphbcdjkb*.{0,1000}bfleegjcoffelppfmadimianphbcdjkb.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11#browser_extensionidN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z35900
823*bit.ly/2alyerp*.{0,1000}bit\.ly\/2alyerp.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z35962
824*bluekeepscanner.exe*.{0,1000}bluekeepscanner\.exe.{0,1000}greyware_tool_keywordpingcastleactive directory weakness scan Vulnerability scanner and Earth Lusca Operations Tools and commandsT1016 - T1069.002 - T1087.002 - T1485TA0007 - TA0008N/AMAZE - BianLian - Scattered Spider* - DragonForceVulnerability Scannerhttps://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf https://github.com/vletoux/pingcastle11N/AN/A10N/A36096
825*bomgar-rdp.exe*.{0,1000}bomgar\-rdp\.exe.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A36187
826*boot.net.anydesk.com*.{0,1000}boot\.net\.anydesk\.com.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - Karakurt - DispossessorRMMhttps://anydesk.com/11N/Arisk of false positives - compliance detection1010N/AN/AN/AN/A36191
827*bored-tunnel-client_Windows_x86_64.*.{0,1000}bored\-tunnel\-client_Windows_x86_64\..{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A36197
828*boringproxy/boringproxy*.{0,1000}boringproxy\/boringproxy.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z36199
829*boringproxy_db.json*.{0,1000}boringproxy_db\.json.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z36200
830*brimstone/rsocks*.{0,1000}brimstone\/rsocks.{0,1000}greyware_tool_keywordrsocksreverse socks5 client & serverT1090 - T1571 - T1071 - T1095TA0011 - TA0001 - TA0008N/AScattered Spider*C2https://github.com/brimstone/rsocks11N/AN/A101085292020-01-09T20:45:32Z2018-01-05T03:09:07Z36233
831*browser.lol/create*.{0,1000}browser\.lol\/create.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A36238
832*brs.rel.tunnels.api.visualstudio.com*.{0,1000}brs\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A36270
833*builds.level.io*.{0,1000}builds\.level\.io.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A36389
834*c3pool_miner.bat*.{0,1000}c3pool_miner\.bat.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z36968
835*c3pool_miner.service*.{0,1000}c3pool_miner\.service.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z36969
836*c3pool_miner.sh*.{0,1000}c3pool_miner\.sh.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z36970
837*cdn*.boxcdn.net*.{0,1000}cdn.{0,1000}\.boxcdn\.net.{0,1000}greyware_tool_keywordBoxAttackers have used box to store malicious files and then share them with targets - box can also be used for data exfiltration by attackersT1567.002 - T1071.001 - T1036 - T1048.002TA0005 - TA0010 - TA0009N/AN/AData Exfiltrationhttps://app.box.com/11#dnsqueryN/A67N/AN/AN/AN/A37922
838*chat.us.n-able.com*.{0,1000}chat\.us\.n\-able\.com.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A38135
839*ChromeCookiesView.exe*.{0,1000}ChromeCookiesView\.exe.{0,1000}greyware_tool_keywordChromeCookiesViewdisplays the list of all cookies stored by Google Chrome Web browser - abused by attackersT1539 - T1005 - T1070.004 - T1552.001TA0006 - TA0008 - TA0009N/AEvilnum - MuddyWaterCredential Accesshttps://www.nirsoft.net/utils/chrome_cookies_view.html11N/Ahttps://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf810N/AN/AN/AN/A38236
840*chromecookiesview.zip*.{0,1000}chromecookiesview\.zip.{0,1000}greyware_tool_keywordChromeCookiesViewdisplays the list of all cookies stored by Google Chrome Web browser - abused by attackersT1539 - T1005 - T1070.004 - T1552.001TA0006 - TA0008 - TA0009N/AEvilnum - MuddyWaterCredential Accesshttps://www.nirsoft.net/utils/chrome_cookies_view.html11N/Ahttps://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf810N/AN/AN/AN/A38237
841*chromecookiesview-x64.zip*.{0,1000}chromecookiesview\-x64\.zip.{0,1000}greyware_tool_keywordChromeCookiesViewdisplays the list of all cookies stored by Google Chrome Web browser - abused by attackersT1539 - T1005 - T1070.004 - T1552.001TA0006 - TA0008 - TA0009N/AEvilnum - MuddyWaterCredential Accesshttps://www.nirsoft.net/utils/chrome_cookies_view.html11N/Ahttps://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf810N/AN/AN/AN/A38238
842*chrome-remote-desktop_current_amd64.deb*.{0,1000}chrome\-remote\-desktop_current_amd64\.deb.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com11N/AN/A1010N/AN/AN/AN/A38253
843*chromeremotedesktophost.msi*.{0,1000}chromeremotedesktophost\.msi.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com11N/AN/A1010N/AN/AN/AN/A38254
844*client.teamviewer.com*.{0,1000}client\.teamviewer\.com.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/11N/AFP risk - teamviewer usage1010N/AN/AN/AN/A38332
845*client-api.aweray.com*.{0,1000}client\-api\.aweray\.com.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A38333
846*cloud.telebit.remot*.{0,1000}cloud\.telebit\.remot.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/11N/AN/A1010N/AN/AN/AN/A38351
847*cloudflared-amd64.pkg*.{0,1000}cloudflared\-amd64\.pkg.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z38367
848*cloudflared-windows-386.exe*.{0,1000}cloudflared\-windows\-386\.exe.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z38368
849*cloudflared-windows-amd64.exe*.{0,1000}cloudflared\-windows\-amd64\.exe.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z38369
850*cloudflared-windows-amd64.msi*.{0,1000}cloudflared\-windows\-amd64\.msi.{0,1000}greyware_tool_keywordcloudflaredcloudfared Contains the command-line client for Cloudflare Tunnel - a tunneling daemon that proxies traffic from the Cloudflare network to your originsT1572 - T1090 - T1071TA0001 - TA0011N/ABlackSuit - Royal - Akira - Scattered Spider* - Gamaredon - TA4557 - FIN6C2https://github.com/cloudflare/cloudflared11N/AN/A1010103839272025-04-10T16:59:49Z2017-10-13T19:54:47Z38370
851*cmd/boringproxy*.{0,1000}cmd\/boringproxy.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z38469
852*cmd/crowbard/*.{0,1000}cmd\/crowbard\/.{0,1000}greyware_tool_keywordcrowbarTunnel TCP over a plain HTTP sessionT1572 - T1048TA0011 - TA0010 - TA0005N/ADispossessorC2https://github.com/q3k/crowbar11N/AN/A1010476412021-01-24T08:21:05Z2015-02-03T18:40:00Z38472
853*code.onedev.io/SoftEther/VPN.git*.{0,1000}code\.onedev\.io\/SoftEther\/VPN\.git.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z38566
854*codeload.github.com/*.{0,1000}codeload\.github\.com\/.{0,1000}greyware_tool_keywordgithubGithub executables download initiated - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A38576
855*commanderupdate.fleetdeck.io*.{0,1000}commanderupdate\.fleetdeck\.io.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z38680
856*comserver.corporate.beanywhere.com*.{0,1000}comserver\.corporate\.beanywhere\.com.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A38737
857*control.*.logmeinrescue.com*.{0,1000}control\..{0,1000}\.logmeinrescue\.com.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A38804
858*control.rsc-app*.logmeinrescue.com.{0,1000}control\.rsc\-app.{0,1000}\.logmeinrescue\.comgreyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A38805
859*controlserver.anyviewer.com*.{0,1000}controlserver\.anyviewer\.com.{0,1000}greyware_tool_keywordanyvieweraccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyviewer.com11N/AN/A1010N/AN/AN/AN/A38806
860*crash.syncthing.net*.{0,1000}crash\.syncthing\.net.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11N/Ahttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z38968
861*curl*.interact.sh*.{0,1000}curl.{0,1000}\.interact\.sh.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C3T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z39219
862*cwn-log-collector-production-clone.*.elasticbeanstalk.com*.{0,1000}cwn\-log\-collector\-production\-clone\..{0,1000}\.elasticbeanstalk\.com.{0,1000}greyware_tool_keywordComodoRMM (Itarian RMM)Comodo offers IT Remote Management tools includes RMM Software - Remote Access - Service Desk - Patch Management and Network Assessment (Itarian RMM)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://one.comodo.com/11N/AN/A1010N/AN/AN/AN/A39290
863*CyberGhost.exe*.{0,1000}CyberGhost\.exe.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A39304
864*CyberGhost.Service.exe*.{0,1000}CyberGhost\.Service\.exe.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A39306
865*CyberGhostVPNSetup.exe*.{0,1000}CyberGhostVPNSetup\.exe.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A39314
866*damewareagent.msi*.{0,1000}damewareagent\.msi.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A40119
867*damewareremoteeverywhereagent.exe*.{0,1000}damewareremoteeverywhereagent\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A40120
868*damewareremoteeverywhereconsole.exe*.{0,1000}damewareremoteeverywhereconsole\.exe.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A40121
869*daps94/SirTunnel*.{0,1000}daps94\/SirTunnel.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z40135
870*dashboard.tunnelmole.com*.{0,1000}dashboard\.tunnelmole\.com.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z40158
871*-data.rel.tunnels.api.visualstudio.com*.{0,1000}\-data\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keywordvscodebuilt-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices.T1090 - T1003 - T1571TA0010 - TA0002 - TA0009N/AN/AC2https://twitter.com/code/status/169986908707189966901N/AN/A1010N/AN/AN/AN/A40164
872*data.syncthing.net*.{0,1000}data\.syncthing\.net.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11N/Ahttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z40165
873*device.remote.it*.{0,1000}device\.remote\.it.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z40778
874*d-h.st/users/powertool*.{0,1000}d\-h\.st\/users\/powertool.{0,1000}greyware_tool_keywordPowertooltool abused by threat actors to desactive AntivirusT1562.001 - T1089 - T1562.009TA0005N/APlay - DispossessorDefense Evasionhttps://www.softpedia.com/get/Antivirus/Removal-Tools/ithurricane-PowerTool.shtml11N/AN/A1010N/AN/AN/AN/A40866
875*disk2vhd.exe*.{0,1000}disk2vhd\.exe.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41032
876*Disk2vhd.zip*.{0,1000}Disk2vhd\.zip.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41033
877*disk2vhd64.exe*.{0,1000}disk2vhd64\.exe.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41034
878*dl.wireshark.org*.{0,1000}dl\.wireshark\.org.{0,1000}greyware_tool_keywordwiresharkWireshark is a network protocol analyzer.T1040 - T1052.001 - T1046TA0001 - TA0002 - TA0007N/ABlack BastaSniffing & Spoofinghttps://www.wireshark.org/11N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A41089
879*donate.ssl.xmrig.com*.{0,1000}donate\.ssl\.xmrig\.com.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z41401
880*donate.v2.xmrig.com:3333*.{0,1000}donate\.v2\.xmrig\.com\:3333.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/11N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z41402
881*donate.xmrig.com*.{0,1000}donate\.xmrig\.com.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z41403
882*download.anydesk.com*.{0,1000}download\.anydesk\.com.{0,1000}greyware_tool_keywordanydeskAnydesk RMM usageT1021 - T1071 - T1090TA0008 - TA0011N/ABlackSuit - Royal - Akira - BlackCat - Karakurt - LockBit - Rhysida - AvosLocker - Conti - Dagon Locker - Nokoyawa - Quantum - Diavol - Trigona - BlackByte - Cactus - Lapsus$ - Black Basta - MONTI - KarakurtRMMhttps://anydesk.com/11N/AN/A1010N/AN/AN/AN/A41455
883*download.cyberghostvpn.com*.{0,1000}download\.cyberghostvpn\.com.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A41456
884*download.filezilla-project.org*.{0,1000}download\.filezilla\-project\.org.{0,1000}greyware_tool_keywordFileZillaFileZilla admintool used by threat actors for persistence and data exfiltrationT1505 - T1041TA0003 - TA0009 -TA0010N/ADispossessor - Akira - Karakurt - AvosLocker - LockBit - Nokoyawa - Diavol - Scattered Spider* - Unit 29155Data Exfiltrationhttps://filezilla-project.org/11N/APUA risk of legitimate usage57N/AN/AN/AN/A41457
885*download.global.mspa.n-able.com/*.{0,1000}download\.global\.mspa\.n\-able\.com\/.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Remote Control utilitiesT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/fr/remote-support-software11N/AN/A1010N/AN/AN/AN/A41458
886*download.radmin.com*.{0,1000}download\.radmin\.com.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A41460
887*download.radmin-vpn.com*.{0,1000}download\.radmin\-vpn\.com.{0,1000}greyware_tool_keywordRadminRadmin is a remote control program that lets you work on another computer through your ownT1021 - T1076 - T1563TA0008 - TA0009 - TA0002N/AAkiraRMMhttps://www.radmin.com/download/11N/AN/A1010N/AN/AN/AN/A41461
888*download.remotepc.com*.{0,1000}download\.remotepc\.com.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A41462
889*download.teamviewer.com.cdn.cloudflare.net*.{0,1000}download\.teamviewer\.com\.cdn\.cloudflare\.net.{0,1000}greyware_tool_keywordteamviewerTeamViewer Remote is software for remote assistance - control and access to computers and other terminals - abused by attackersT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/ALockBit - BERSERK BEAR - MUSTANG PANDA - TeamSpy Crew - BianLian - Scattered Spider* - Trigona - Yanluowang - FIN7 - LOTUS PANDARMMhttps://www.teamviewer.com/11N/AFP risk - teamviewer usage1010N/AN/AN/AN/A41463
890*download.wireguard.com/windows-client/*.{0,1000}download\.wireguard\.com\/windows\-client\/.{0,1000}greyware_tool_keywordwiretapWiretap is a transparent - VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.T1572TA0011 - TA0003N/AN/ADefense Evasionhttps://github.com/sandialabs/wiretap11N/AN/A1010939412025-04-16T21:54:13Z2022-11-19T00:19:05Z41465
891*downloads.nordcdn.com/apps/vpn-extension/*.{0,1000}downloads\.nordcdn\.com\/apps\/vpn\-extension\/.{0,1000}greyware_tool_keywordNordVPNOVPN configuration for nordvpn accessed within corporate networkT1090.003 - T1133 - T1572TA0003 - TA0001 - TA0011 - TA0010 - TA0005N/AN/AData Exfiltrationhttps://nordvpn.com11#VPNN/A810N/AN/AN/AN/A41486
892*downloads.remote.it/remoteit/install_agent.sh*.{0,1000}downloads\.remote\.it\/remoteit\/install_agent\.sh.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11N/AN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z41487
893*downloads.surfshark.com*.{0,1000}downloads\.surfshark\.com.{0,1000}greyware_tool_keywordsurfshark VPNusage of surfsharkVPN clientT1090 - T1573TA0005 - TA010N/AN/ADefense Evasion11N/AN/A78N/AN/AN/AN/A41488
894*downloads.zohocdn.com*.{0,1000}downloads\.zohocdn\.com.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A41489
895*downloads.zohodl.com.cn*.{0,1000}downloads\.zohodl\.com\.cn.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A41490
896*downloads2.surfshark.com*.{0,1000}downloads2\.surfshark\.com.{0,1000}greyware_tool_keywordsurfshark VPNusage of surfsharkVPN clientT1090 - T1573TA0005 - TA010N/AN/ADefense Evasion11N/AN/A78N/AN/AN/AN/A41492
897*ekzhang/bore*.{0,1000}ekzhang\/bore.{0,1000}greyware_tool_keywordborebore is a simple CLI tool for making tunnels to localhostT1090 - T1090.003 - T1572 - T1572.001TA0042 - TA0011N/AN/AData Exfiltrationhttps://github.com/ekzhang/bore11N/AN/A101096344102025-04-14T21:52:18Z2022-04-04T02:47:54Z43040
898*ekzhang/sshx*.{0,1000}ekzhang\/sshx.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z43041
899*elddy/NimScan*.{0,1000}elddy\/NimScan.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z43046
900*eun1.rel.tunnels.api.visualstudio.com*.{0,1000}eun1\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A43295
901*euw.rel.tunnels.api.visualstudio.com*.{0,1000}euw\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A43297
902*eval-*.beyondtrustcloud.com*.{0,1000}eval\-.{0,1000}\.beyondtrustcloud\.com.{0,1000}greyware_tool_keywordBomgarBomgar beyoundtrust Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.beyondtrust.com/11N/AN/A1010N/AN/AN/AN/A43299
903*EvanMcBroom/lsa-whisperer*.{0,1000}EvanMcBroom\/lsa\-whisperer.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z43301
904*f38fg.tunnelmole.net*.{0,1000}f38fg\.tunnelmole\.net.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z43896
905*fasmide/remotemoe*.{0,1000}fasmide\/remotemoe.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z44459
906*fatedier/frp*.{0,1000}fatedier\/frp.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z44465
907*fee.xmrig.com*.{0,1000}fee\.xmrig\.com.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z44773
908*feedback.cyberghostvpn.com*.{0,1000}feedback\.cyberghostvpn\.com.{0,1000}greyware_tool_keywordCyberGhost VPNExternal VPN usage within coporate networkT1567 - T1090TA0003 - TA0005 - TA0009 - TA0010 - TA0011N/AN/ADefense Evasionhttps://www.cyberghostvpn.com/11#VPNN/A98N/AN/AN/AN/A44778
909*File Shredder setup.exe*.{0,1000}File\sShredder\ssetup\.exe.{0,1000}greyware_tool_keywordShredderFile Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recoveryT1070 - T1485 - T1565.001TA0005 - TA0040N/AN/ADefense Evasionhttps://www.fileshredder.org/11N/AN/A78N/AN/AN/AN/A44891
910*File Shredder.exe*.{0,1000}File\sShredder\.exe.{0,1000}greyware_tool_keywordShredderFile Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recoveryT1070 - T1485 - T1565.001TA0005 - TA0040N/AN/ADefense Evasionhttps://www.fileshredder.org/11N/AN/A78N/AN/AN/AN/A44892
911*file_shredder_setup.exe*.{0,1000}file_shredder_setup\.exe.{0,1000}greyware_tool_keywordShredderFile Shredder is FREE and powerfull aplication to shred and permanently remove unwanted files from your computer beyond recoveryT1070 - T1485 - T1565.001TA0005 - TA0040N/AN/ADefense Evasionhttps://www.fileshredder.org/11N/AN/A78N/AN/AN/AN/A44895
912*filetransfer.io/upload/*.{0,1000}filetransfer\.io\/upload\/.{0,1000}greyware_tool_keywordfiletransfer.iouploading to filetransfer.ioT1105 - T1021 - T1560.003 - T1071.001 - T1071.002TA0010 - TA0009N/AN/AData Exfiltrationhttps://filetransfer.io11#filehostingserviceN/A1010N/AN/AN/AN/A44920
913*fleetdeck.io/prototype3/commander_svc*.{0,1000}fleetdeck\.io\/prototype3\/commander_svc.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45170
914*fleetdeck_agent.exe*.{0,1000}fleetdeck_agent\.exe.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45171
915*fleetdeck_agent_svc.exe*.{0,1000}fleetdeck_agent_svc\.exe.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45172
916*fleetdeck_commander_launcher.exe*.{0,1000}fleetdeck_commander_launcher\.exe.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45173
917*fleetdeck_commander_svc.exe*.{0,1000}fleetdeck_commander_svc\.exe.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45174
918*fleetdeck_installer.exe*.{0,1000}fleetdeck_installer\.exe.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z45175
919*frpc_windows_amd64.exe*.{0,1000}frpc_windows_amd64\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z45361
920*frpc_windows_arm64.exe*.{0,1000}frpc_windows_arm64\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z45362
921*frps_windows_amd64.exe*.{0,1000}frps_windows_amd64\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z45364
922*frps_windows_arm64.exe*.{0,1000}frps_windows_arm64\.exe.{0,1000}greyware_tool_keywordfrpA fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.T1572 - T1090 - T1599TA0010 - TA0040N/AN/AData Exfiltrationhttps://github.com/fatedier/frp11N/AN/A101092956139292025-04-16T17:34:14Z2015-12-21T15:24:59Z45365
923*gateway.zohoassist.com*.{0,1000}gateway\.zohoassist\.com.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A45482
924*geo.netsupportsoftware.com*.{0,1000}geo\.netsupportsoftware\.com.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A45608
925*Gerenios/AADInternals*.{0,1000}Gerenios\/AADInternals.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z45614
926*getcroc.schollz.com*.{0,1000}getcroc\.schollz\.com.{0,1000}greyware_tool_keywordcroccroc is a tool that allows any two computers to simply and securely transfer files and foldersT1567.002 - T1090.002 - T1573.002 - T1102.003TA0010 - TA0005 - TA0008 - TA0011N/AN/AData Exfiltrationhttps://github.com/schollz/croc11N/AN/A8102998911972025-04-16T23:30:54Z2017-10-17T15:20:18Z45947
927*ghcr.io/agrinman/tunnelto*.{0,1000}ghcr\.io\/agrinman\/tunnelto.{0,1000}greyware_tool_keywordtunnelto.devExpose your local web server to the internet with a public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/agrinman/tunnelto11N/AN/A101021671182022-09-24T21:28:44Z2020-03-22T05:39:49Z46378
928*ghcr.io/ao-space/gt:client-dev*.{0,1000}ghcr\.io\/ao\-space\/gt\:client\-dev.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z46379
929*ghcr.io/ao-space/gt:server-dev*.{0,1000}ghcr\.io\/ao\-space\/gt\:server\-dev.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z46380
930*github*/xmrig/xmrig*.{0,1000}github.{0,1000}\/xmrig\/xmrig.{0,1000}greyware_tool_keywordxmrigCPU/GPU cryptominer often used by attackers on compromised machinesT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/xmrig/xmrig/11N/AN/A910917336022025-04-17T09:12:31Z2017-04-15T05:57:53Z46427
931*github*ao-space/gt*.{0,1000}github.{0,1000}ao\-space\/gt.{0,1000}greyware_tool_keywordgtFast WebSocket(s)/HTTP(s)/TCP relay proxy for making tunnels to localhost.T1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ao-space/gt11N/AN/A1010132362024-10-30T00:37:47Z2021-11-29T03:09:56Z46428
932*github*koding/tunnel*.{0,1000}github.{0,1000}koding\/tunnel.{0,1000}greyware_tool_keywordtunnelTunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outsideT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/koding/tunnel11N/AN/A1010328722023-10-20T13:43:58Z2015-05-28T07:26:42Z46429
933*github.com*/jprq/releases/download/*.{0,1000}github\.com.{0,1000}\/jprq\/releases\/download\/.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z46430
934*github.com/tailscale*.{0,1000}github\.com\/tailscale.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z46441
935*gitlab.com/SoftEther/VPN.git*.{0,1000}gitlab\.com\/SoftEther\/VPN\.git.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z46445
936*global.rel.tunnels.api.visualstudio.com*.{0,1000}global\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A46468
937*global.rel.tunnels.api.visualstudio.com*.{0,1000}global\.rel\.tunnels\.api\.visualstudio\.com.{0,1000}greyware_tool_keywordvscodeStarts a reverse connection over global.rel.tunnels.api.visualstudio.com via websocketsT1090.003 - T1059.001 - T1071.001TA0011 - TA0002N/AN/AC2https://badoption.eu/blog/2023/01/31/code_c2.html01N/Arisk of False positive1010N/AN/AN/AN/A46469
938*go-gost/gost*.{0,1000}go\-gost\/gost.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z46573
939*GoodSync-vsub-2Go-Setup.exe*.{0,1000}GoodSync\-vsub\-2Go\-Setup\.exe.{0,1000}greyware_tool_keywordGoodsyncGoodSync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/AN/AData Exfiltrationhttps://www.goodsync.com/11N/Aportable version910N/AN/AN/AN/A46587
940*google-chrome-stable_current_amd64.deb*.{0,1000}google\-chrome\-stable_current_amd64\.deb.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com11N/AN/A1010N/AN/AN/AN/A46600
941*GoTo MyPC Installer.exe*.{0,1000}GoTo\sMyPC\sInstaller\.exe.{0,1000}greyware_tool_keywordGoToMyPCGoToMyPC is remote desktop software that allows users to access computers remotely using a web browserT1021.001 - T1059 - T1078 - T1133 - T1563TA0001 - TA0002 - TA0005 - TA0008 - TA0011 - TA0010N/AN/ARMMhttps://www.gotomypc.com/11N/AN/A1010N/AN/AN/AN/A46641
942*gtfobins*.{0,1000}gtfobins.{0,1000}greyware_tool_keywordgtfobinsGTFOBins is a curated list of Unix binaries that can used to bypass local security restrictions in misconfigured systems malicious use of legitimate binariesT1059 - T1068 - T1136TA0002 - TA0005N/AN/ADefense Evasionhttps://gtfobins.github.io/11#linuxhigh false positive risks - low signal25N/AN/AN/AN/A46793
943*hackforums.net/*.{0,1000}hackforums\.net\/.{0,1000}greyware_tool_keywordhackforums.netHack Forums - a well-known online community frequently referenced in various pieces of malicious codeT1588.003TA0011N/AN/AExploitation toolhackforums.net11N/AN/A610N/AN/AN/AN/A46848
944*homeassistant.local:8123*.{0,1000}homeassistant\.local\:8123.{0,1000}greyware_tool_keywordhomeway.ioExpose local servers to the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://homeway.io/11N/AN/A1010N/AN/AN/AN/A47262
945*http*.sslip.io*.{0,1000}http.{0,1000}\.sslip\.io.{0,1000}greyware_tool_keywordsslip.iosslip.io is a DNS server that maps specially-crafted DNS A records to IP addresses e.g. 127-0-0-1.sslip.io maps to 127.0.0.1T1568.002 - T1048.003TA0003 - TA0004N/AN/AC2https://github.com/cunnie/sslip.io11N/Aletigimate tool abused by threat actor to bypass IP blockage and encrypt traffic610737792025-04-04T14:05:21Z2015-08-26T18:43:35Z47332
946*http*/agent-api-*.atera.com*.{0,1000}http.{0,1000}\/agent\-api\-.{0,1000}\.atera\.com.{0,1000}greyware_tool_keywordAteracontrol remote machines- abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlackSuit - Royal - AvosLocker - BianLian - Conti - Hive - Quantum - RansomHub - Black Basta - DispossessorRMMhttps://www.atera.com/11N/AN/A1010N/AN/AN/AN/A47334
947*http://*.interact.sh*.{0,1000}http\:\/\/.{0,1000}\.interact\.sh.{0,1000}greyware_tool_keywordinteractshInteractsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions but abused by attackers as C4T1566.002 - T1566.001 - T1071 - T1102TA0011 - TA0001N/AN/AC2https://github.com/projectdiscovery/interactsh11N/AFP risk - legitimate service abused by attackers101037183882025-04-22T12:41:45Z2021-01-29T14:31:51Z47373
948*http://*.localhost.run*.{0,1000}http\:\/\/.{0,1000}\.localhost\.run.{0,1000}greyware_tool_keywordlocalhost.runPut a locally running HTTP HTTPS or TLS app on the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://localhost.run/11#filehostingserviceN/A1010N/AN/AN/AN/A47374
949*http://*.pagekite.me*.{0,1000}http\:\/\/.{0,1000}\.pagekite\.me.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z47384
950*http://*.remote.moe/*.{0,1000}http\:\/\/.{0,1000}\.remote\.moe\/.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z47385
951*http://*.serveo.net*.{0,1000}http\:\/\/.{0,1000}\.serveo\.net.{0,1000}greyware_tool_keywordserveo.netExpose local servers to the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://serveo.net11N/AN/A1010N/AN/AN/AN/A47386
952*http://*.ssi.sh*.{0,1000}http\:\/\/.{0,1000}\.ssi\.sh.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish11N/AN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z47387
953*http://*.trycloudfare.com*.{0,1000}http\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A47390
954*http://*.tunnelmole.net*.{0,1000}http\:\/\/.{0,1000}\.tunnelmole\.net.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z47391
955*http://*.zrok.io*.{0,1000}http\:\/\/.{0,1000}\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z47392
956*http://*:9000/restic*.{0,1000}http\:\/\/.{0,1000}\:9000\/restic.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z47398
957*http://127.0.0.1:18080*.{0,1000}http\:\/\/127\.0\.0\.1\:18080.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z47414
958*http://127.0.0.1:2019/id/*.{0,1000}http\:\/\/127\.0\.0\.1\:2019\/id\/.{0,1000}greyware_tool_keywordSirTunnelSirTunnel enables you to securely expose a webserver running on your computer to a public URL using HTTPS.T1572TA0011 - TA0003N/AN/AC2https://github.com/anderspitman/SirTunnel11N/AN/A101014361192024-03-24T20:15:50Z2020-09-23T00:15:26Z47415
959*http://127.0.0.1:3320/-/healthcheck*.{0,1000}http\:\/\/127\.0\.0\.1\:3320\/\-\/healthcheck.{0,1000}greyware_tool_keywordpgrokPoor man's ngrok - a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwardingT1572TA0011 - TA0003N/AN/AC2https://github.com/pgrok/pgrok11N/AN/A101033251172025-04-19T18:37:55Z2023-03-08T12:43:55Z47417
960*http://127.0.0.1:4000*.{0,1000}http\:\/\/127\.0\.0\.1\:4000.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47419
961*http://127.0.0.1:4040/api/logs/*.{0,1000}http\:\/\/127\.0\.0\.1\:4040\/api\/logs\/.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z47420
962*http://127.0.0.1:4040/api/tunnels*.{0,1000}http\:\/\/127\.0\.0\.1\:4040\/api\/tunnels.{0,1000}greyware_tool_keywordngrokngrok - abused by attackers for C2 usageT1090 - T1095 - T1008 - T1102 - T1572 - T1567 - T1568.002TA0011 - TA0010 - TA0005N/AAkira - BlackCat - Karakurt - Scattered Spider* - LockBit - Fox Kitten - LazyScripter - Unit 29155 - Common Raven - FoxKitten - Gamaredon - DispossessorC2https://github.com/inconshreveable/ngrok11N/AN/A10102431642872024-04-26T18:11:18Z2013-03-20T09:37:43Z47421
963*http://127.0.0.1:8000/gate.html*.{0,1000}http\:\/\/127\.0\.0\.1\:8000\/gate\.html.{0,1000}greyware_tool_keywordgolang_c2C2 written in Go for red teams aka gorfice2kT1071 - T1021 - T1090TA0011 - TA0008 - TA0010N/AN/AC2https://github.com/m00zh33/golang_c211N/AN/A1010682019-03-18T00:46:41Z2019-03-19T02:39:59Z47429
964*http://127.0.0.1:8384*.{0,1000}http\:\/\/127\.0\.0\.1\:8384.{0,1000}greyware_tool_keywordsyncthingOpen Source Continuous File Synchronization - abused by attackers for data exfiltrationT1046 - T1041 - T1020 - T1567TA0043 - TA0007 - TA0010 N/ADispossessor - UAC-0020Data Exfiltrationhttps://github.com/syncthing/syncthing11N/Ahttps://cert.gov.ua/article/62796009106957944862025-04-22T01:30:11Z2013-11-26T09:48:21Z47435
965*http://127.0.0.1:9191*.{0,1000}http\:\/\/127\.0\.0\.1\:9191.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z47437
966*http://antibody-software.com/files/wiztreeversion.php*.{0,1000}http\:\/\/antibody\-software\.com\/files\/wiztreeversion\.php.{0,1000}greyware_tool_keywordwiztreelegitimate tool abused by threat actors to obtain network files and directory listingsT1083TA0007N/AFox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - RoyalDiscoveryN/A11N/AN/A36N/AN/AN/AN/A47445
967*http://api.guerrillamail.com/ajax.php?*.{0,1000}http\:\/\/api\.guerrillamail\.com\/ajax\.php\?.{0,1000}greyware_tool_keywordguerrillamailusing the API of a disposable email address to use anytime - could be abused by malicious actorsT1071.003TA0005 - TA0001N/AN/ADefense Evasionhttps://www.guerrillamail.com11N/AN/A1010N/AN/AN/AN/A47446
968*http://arslan.koding.io/*.{0,1000}http\:\/\/arslan\.koding\.io\/.{0,1000}greyware_tool_keywordtunnelTunnel is a server/client package that enables to proxy public connections to your local machine over a tunnel connection from the local machine to the public server. What this means is, you can share your localhost even if it doesn't have a Public IP or if it's not reachable from outsideT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/koding/tunnel11N/AN/A1010328722023-10-20T13:43:58Z2015-05-28T07:26:42Z47447
969*http://bore.pub/*.{0,1000}http\:\/\/bore\.pub\/.{0,1000}greyware_tool_keywordborebore is a simple CLI tool for making tunnels to localhostT1090 - T1090.003 - T1572 - T1572.001TA0042 - TA0011N/AN/AData Exfiltrationhttps://github.com/ekzhang/bore11N/AN/A101096344102025-04-14T21:52:18Z2022-04-04T02:47:54Z47453
970*http://canarytokens.com/*/*.{0,1000}http\:\/\/canarytokens\.com\/.{0,1000}\/.{0,1000}greyware_tool_keywordcanarytokens.comfree honeypot detection tokens but also abused by attacker for payload callback confirmationT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://canarytokens.com11N/AOut of band interaction domains1010N/AN/AN/AN/A47455
971*http://dnslog.cn/*.{0,1000}http\:\/\/dnslog\.cn\/.{0,1000}greyware_tool_keyworddnslog.cnallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://dnslog.cn11N/AOut of band interaction domains1010N/AN/AN/AN/A47456
972*http://dsrt.dyndns.org:8888/uvs_freeupdate_en.htm*.{0,1000}http\:\/\/dsrt\.dyndns\.org\:8888\/uvs_freeupdate_en\.htm.{0,1000}greyware_tool_keywordUniversal Virus SnifferUniversal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/APhobosDefense Evasionhttps://www.majorgeeks.com/files/details/universal_virus_sniffer.html11N/AN/A810N/AN/AN/AN/A47457
973*http://dsrt.dyndns.org:8888/uvs_register_en.htm*.{0,1000}http\:\/\/dsrt\.dyndns\.org\:8888\/uvs_register_en\.htm.{0,1000}greyware_tool_keywordUniversal Virus SnifferUniversal Virus Sniffer detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/APhobosDefense Evasionhttps://www.majorgeeks.com/files/details/universal_virus_sniffer.html11N/AN/A810N/AN/AN/AN/A47458
974*http://get-my-ip.ddns.softether-network.net/ddns/getmyip.ashx*.{0,1000}http\:\/\/get\-my\-ip\.ddns\.softether\-network\.net\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47460
975*http://get-my-ip.ddns.uxcom.jp/ddns/getmyip.ashx*.{0,1000}http\:\/\/get\-my\-ip\.ddns\.uxcom\.jp\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47461
976*http://get-my-ip-v6.ddns.softether-network.net/ddns/getmyip.ashx*.{0,1000}http\:\/\/get\-my\-ip\-v6\.ddns\.softether\-network\.net\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47462
977*http://get-my-ip-v6.ddns.uxcom.jp/ddns/getmyip.ashx*.{0,1000}http\:\/\/get\-my\-ip\-v6\.ddns\.uxcom\.jp\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47463
978*http://localhost:1337*.{0,1000}http\:\/\/localhost\:1337.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z47472
979*http://localhost:1337/previewlogin*.{0,1000}http\:\/\/localhost\:1337\/previewlogin.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z47473
980*http://localhost:7681*.{0,1000}http\:\/\/localhost\:7681.{0,1000}greyware_tool_keywordsupershellSupershell is a C2 remote control platform accessed through WEB services. By establishing a reverse SSH tunnel it obtains a fully interactive Shell and supports multi-platform architecture PayloadT1090 - T1059 - T1021TA0011 - TA0005 - TA0002N/AN/AC2https://github.com/tdragon6/Supershell11N/AN/A101015611962023-09-26T13:53:55Z2023-03-25T15:02:43Z47480
981*http://local-tailscaled.sock*.{0,1000}http\:\/\/local\-tailscaled\.sock.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47487
982*http://pastie.org/p/*/raw*.{0,1000}http\:\/\/pastie\.org\/p\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordpastie.orgaccessing paste raw contentT1119TA0009N/AN/ACollectionhttp://pastie.org/11#PastebinLikeN/A88N/AN/AN/AN/A47503
983*http://pastie.org/pastes/create*.{0,1000}http\:\/\/pastie\.org\/pastes\/create.{0,1000}greyware_tool_keywordpastie.orgsending data to a pastebinT1567.002TA0010N/AN/AData Exfiltrationhttp://pastie.org/11#PastebinLikeN/A88N/AN/AN/AN/A47504
984*http://requestbin.net/r/*.{0,1000}http\:\/\/requestbin\.net\/r\/.{0,1000}greyware_tool_keywordrequestbin.netallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://requestbin.net11N/AOut of band interaction domains1010N/AN/AN/AN/A47507
985*http://senet.aoi.flets-east.jp/ddns/getmyip.ashx*.{0,1000}http\:\/\/senet\.aoi\.flets\-east\.jp\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47508
986*http://senet.p-ns.flets-west.jp/ddns/getmyip.ashx*.{0,1000}http\:\/\/senet\.p\-ns\.flets\-west\.jp\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47509
987*http://senet-flets.v6.softether.co.jp/ddns/getmyip.ashx*.{0,1000}http\:\/\/senet\-flets\.v6\.softether\.co\.jp\/ddns\/getmyip\.ashx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47510
988*http://support.kaspersky.com/viruses/tdsskiller.xmlt*.{0,1000}http\:\/\/support\.kaspersky\.com\/viruses\/tdsskiller\.xmlt.{0,1000}greyware_tool_keywordTDSKillerTDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - AvaddonDefense Evasionhttps://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html11N/AN/A810N/AN/AN/AN/A47515
989*http://tcp.btunnel.in*.{0,1000}http\:\/\/tcp\.btunnel\.in.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A47518
990*http://temp.sh/*/*.{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000}greyware_tool_keywordtemp.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47519
991*http://up.pagekite.net/*.{0,1000}http\:\/\/up\.pagekite\.net\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z47522
992*http://update.iobit.com/infofiles/iobitunlocker.upt*.{0,1000}http\:\/\/update\.iobit\.com\/infofiles\/iobitunlocker\.upt.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#11N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A47523
993*http://www.advanced-port-scanner.com/checkupdate.php*.{0,1000}http\:\/\/www\.advanced\-port\-scanner\.com\/checkupdate\.php.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A47527
994*http://www.epoolsoft.com/pchunter/pchunter_free*.{0,1000}http\:\/\/www\.epoolsoft\.com\/pchunter\/pchunter_free.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A47531
995*http://www.epoolsoft.com/PCHunter_Standard*.{0,1000}http\:\/\/www\.epoolsoft\.com\/PCHunter_Standard.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A47532
996*http://www.proxifier.com/distr/last_versions/ProxifierMac*.{0,1000}http\:\/\/www\.proxifier\.com\/distr\/last_versions\/ProxifierMac.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A47538
997*http://www.proxifier.com/distr/last_versions/ProxifierPortable*.{0,1000}http\:\/\/www\.proxifier\.com\/distr\/last_versions\/ProxifierPortable.{0,1000}greyware_tool_keywordProxifierallows to proxy connections for programsT1090 - T1071 - T1078.003TA0005N/AScattered Spider* - ProxifierDefense Evasionhttps://www.proxifier.com/download/11N/AN/A89N/AN/AN/AN/A47539
998*http://zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd.onion*.{0,1000}http\:\/\/zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd\.onion.{0,1000}greyware_tool_keywordzerobin.netaccessing paste raw contentT1119TA0009N/AN/ACollectionhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A47545
999*https://*.*.devtunnels.ms*.{0,1000}https\:\/\/.{0,1000}\..{0,1000}\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A47585
1000*https://*.*.devtunnels.ms*.{0,1000}https\:\/\/.{0,1000}\..{0,1000}\.devtunnels\.ms.{0,1000}greyware_tool_keywordvscodebuilt-in port forwarding. This feature allows you to share locally running services over the internet to other people and devices.T1090 - T1003 - T1571TA0010 - TA0002 - TA0009N/AN/AC2https://twitter.com/code/status/169986908707189966901N/AN/A1010N/AN/AN/AN/A47586
1001*https://*.app.github.dev/*.{0,1000}https\:\/\/.{0,1000}\.app\.github\.dev\/.{0,1000}greyware_tool_keywordgithubaccess to a GitHub Codespace environment - Github Codespaces have a public port forwarding option allowing you to make your server available for the public.T1071 - T1572TA0001 - TA0005N/AN/ACollectionhttps://detect.fyi/how-threat-actors-use-github-bd991c11ed3701N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A47587
1002*https://*.brs.devtunnels.ms/*.{0,1000}https\:\/\/.{0,1000}\.brs\.devtunnels\.ms\/.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview01N/AN/A810N/AN/AN/AN/A47588
1003*https://*.btunnel.co.in*.{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A47589
1004*https://*.btunnel.co.in*.{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A47590
1005*https://*.btunnel.co.in*.{0,1000}https\:\/\/.{0,1000}\.btunnel\.co\.in.{0,1000}greyware_tool_keywordbtunnel.inExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://www.btunnel.in/11N/AN/A1010N/AN/AN/AN/A47591
1006*https://*.dev.servers.ddns.softether-network.net/ddns/ddns.aspx*.{0,1000}https\:\/\/.{0,1000}\.dev\.servers\.ddns\.softether\-network\.net\/ddns\/ddns\.aspx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47592
1007*https://*.dev.servers-v6.ddns.softether-network.net/ddns/ddns.aspx*.{0,1000}https\:\/\/.{0,1000}\.dev\.servers\-v6\.ddns\.softether\-network\.net\/ddns\/ddns\.aspx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47593
1008*https://*.euw.devtunnels.ms*.{0,1000}https\:\/\/.{0,1000}\.euw\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview01N/AN/A810N/AN/AN/AN/A47594
1009*https://*.fex.net/download/*.{0,1000}https\:\/\/.{0,1000}\.fex\.net\/download\/.{0,1000}greyware_tool_keywordfex.nethosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/ACollectionhttps://fex.net11#filehostingservicedownloading a file1010N/AN/AN/AN/A47595
1010*https://*.fex.net/upload/*.{0,1000}https\:\/\/.{0,1000}\.fex\.net\/upload\/.{0,1000}greyware_tool_keywordfex.nethosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/AData Exfiltrationhttps://fex.net11#filehostingserviceuploading a file1010N/AN/AN/AN/A47596
1011*https://*.free.beeceptor.com*.{0,1000}https\:\/\/.{0,1000}\.free\.beeceptor\.com.{0,1000}greyware_tool_keywordbeeceptor.comtemporary public URL for your localhost + port combination - ideal for real-time testing - can be abused for payload callback confirmationT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://beeceptor.com/local-tunnel11N/AN/A1010N/AN/AN/AN/A47597
1012*https://*.localhost.run*.{0,1000}https\:\/\/.{0,1000}\.localhost\.run.{0,1000}greyware_tool_keywordlocalhost.runPut a locally running HTTP HTTPS or TLS app on the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://localhost.run/11N/AN/A1010N/AN/AN/AN/A47599
1013*https://*.localtunnel.me*.{0,1000}https\:\/\/.{0,1000}\.localtunnel\.me.{0,1000}greyware_tool_keywordlocaltunnelsclient for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/localtunnel11N/AN/A8102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z47600
1014*https://*.my.auvik.com/*.{0,1000}https\:\/\/.{0,1000}\.my\.auvik\.com\/.{0,1000}greyware_tool_keywordauvikcloud-based network management softwareT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://www.auvik.com/11N/AN/A1010N/AN/AN/AN/A47601
1015*https://*.pagekite.me*.{0,1000}https\:\/\/.{0,1000}\.pagekite\.me.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z47604
1016*https://*.pulseway.com/app/main/*.{0,1000}https\:\/\/.{0,1000}\.pulseway\.com\/app\/main\/.{0,1000}greyware_tool_keywordPulsewayPulseway - remote monitoring and management tool designed for IT administrators to monitor and manage their IT systems and infrastructure remotely - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Back BastaRMMhttps://www.pulseway.com/11N/AN/A1010N/AN/AN/AN/A47605
1017*https://*.remote.moe/*.{0,1000}https\:\/\/.{0,1000}\.remote\.moe\/.{0,1000}greyware_tool_keywordremotemoeremotemoe is a software daemon for exposing ad-hoc services to the internet without having to deal with the regular network stuff such as configuring VPNs - changing firewalls - or adding port forwardsT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/fasmide/remotemoe11N/AN/A1010288322024-06-03T14:00:47Z2020-06-11T07:41:03Z47606
1018*https://*.screenconnect.com/Bin/*.exe*.{0,1000}https\:\/\/.{0,1000}\.screenconnect\.com\/Bin\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordScreenConnectcontrol remote servers - abused by threat actorsT1021.001 - T1078 - T1133 - T1112TA0008 - TA0003 - TA0004 - TA0005 - TA0011 - TA0010N/ABlack Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater RMMscreenconnect.com11N/AN/A1010N/AN/AN/AN/A47607
1019*https://*.screenconnect.com/Host*.{0,1000}https\:\/\/.{0,1000}\.screenconnect\.com\/Host.{0,1000}greyware_tool_keywordScreenConnectConnectWise Control formerly known as Screenconnect is a remote desktop software application.T1021.001 - T1133TA0008 - TA0009 - TA0010 - TA0011N/ABlack Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater RMMhttps://screenconnect.connectwise.com/download11N/AN/A1010N/AN/AN/AN/A47608
1020*https://*.sendspace.com/upload*.{0,1000}https\:\/\/.{0,1000}\.sendspace\.com\/upload.{0,1000}greyware_tool_keywordsendspace.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ADispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice SocietyData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A47609
1021*https://*.serveo.net*.{0,1000}https\:\/\/.{0,1000}\.serveo\.net.{0,1000}greyware_tool_keywordserveo.netExpose local servers to the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://serveo.net11N/AN/A1010N/AN/AN/AN/A47610
1022*https://*.ssi.sh*.{0,1000}https\:\/\/.{0,1000}\.ssi\.sh.{0,1000}greyware_tool_keywordsishHTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.T1572TA0011 - TA0003N/AN/AC2https://github.com/antoniomika/sish11N/AN/A101042033252025-04-10T20:04:08Z2019-02-15T15:36:23Z47611
1023*https://*.tacticalrmm.com/*.{0,1000}https\:\/\/.{0,1000}\.tacticalrmm\.com\/.{0,1000}greyware_tool_keywordtacticalrmmA remote monitoring & management toolT1021.001 - T1219 - T1076 - T1563.002TA0008 - TA0009 - TA0010 - TA0011N/AAvosLocker - Scattered Spider* - Black BastaRMMhttps://github.com/amidaware/tacticalrmm11N/AN/A101035384842025-04-22T19:24:13Z2019-10-22T22:19:12Z47612
1024*https://*.telebit.io*.{0,1000}https\:\/\/.{0,1000}\.telebit\.io.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/11N/AN/A1010N/AN/AN/AN/A47613
1025*https://*.trycloudfare.com*.{0,1000}https\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comThe subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activitiesT1071.001 - T1090 - T1583.003 - T1102TA0001 - TA0005 - TA0008 - TA0011N/AN/APhishinghttps://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware11N/AN/A1010N/AN/AN/AN/A47616
1026*https://*.trycloudflare.com*.{0,1000}https\:\/\/.{0,1000}\.trycloudflare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comAttackers abuse this service to expose malicious servers on a *.trycloudflare.com subdomainT1567.002 - T1102 - T1071.001 - T1036TA0001 - TA0005 - TA0009N/AN/ACollectionhttps://lots-project.com/site/2a2e747279636c6f7564666c6172652e636f6d01N/AN/A88N/AN/AN/AN/A47617
1027*https://*.tunnelmole.net*.{0,1000}https\:\/\/.{0,1000}\.tunnelmole\.net.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z47618
1028*https://*.use.devtunnels.ms*.{0,1000}https\:\/\/.{0,1000}\.use\.devtunnels\.ms.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview01N/AN/A810N/AN/AN/AN/A47620
1029*https://*.zoho.com/pconnect*.{0,1000}https\:\/\/.{0,1000}\.zoho\.com\/pconnect.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47621
1030*https://*.zohoassist.com/w_socket*.{0,1000}https\:\/\/.{0,1000}\.zohoassist\.com\/w_socket.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47622
1031*https://*.zrok.io*.{0,1000}https\:\/\/.{0,1000}\.zrok\.io.{0,1000}greyware_tool_keywordzrokzrok allows users to share tunnels for HTTP TCP and UDP network resources. zrok additionally allows users to easily and rapidly share files - web content and custom resources in a peer-to-peer manner.T1572TA0011 - TA0003N/AN/AC2https://github.com/openziti/zrok11N/AN/A101031321252025-04-22T18:36:51Z2022-07-18T19:14:51Z47623
1032*https://*:9000/restic*.{0,1000}https\:\/\/.{0,1000}\:9000\/restic.{0,1000}greyware_tool_keywordresticbackup program used by threat actors for data exfiltrationT1567TA0009 - TA0010N/AINC Ransom - LynxData Exfiltrationhttps://github.com/restic/restic11N/AN/A8102834215992025-04-14T18:02:41Z2014-04-27T14:07:58Z47627
1033*https://0bin.net/paste/*+*.{0,1000}https\:\/\/0bin\.net\/paste\/.{0,1000}\+.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net11#PastebinLikeN/A510N/AN/AN/AN/A47631
1034*https://0bin.net/paste/create*.{0,1000}https\:\/\/0bin\.net\/paste\/create.{0,1000}greyware_tool_keyword0bin.netCreating a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://0bin.net11#PastebinLikeN/A910N/AN/AN/AN/A47632
1035*https://12ft.io/api/proxy?q=http*.{0,1000}https\:\/\/12ft\.io\/api\/proxy\?q\=http.{0,1000}greyware_tool_keyword12ft.ioAttackers can use 12ft.io to masquerade their domain for phishing purposes.T1204.002 - T1036 - T1566.002TA0001 - TA0005N/AN/ADefense Evasionhttps://12ft.io/01N/AN/A55N/AN/AN/AN/A47643
1036*https://12ft.io/proxy?q=*.{0,1000}https\:\/\/12ft\.io\/proxy\?q\=.{0,1000}greyware_tool_keyword12ft.ioAttackers can use 12ft.io to masquerade their domain for phishing purposes.T1204.002 - T1036 - T1566.002TA0001 - TA0005N/AN/ADefense Evasionhttps://12ft.io/01N/AN/A55N/AN/AN/AN/A47644
1037*https://1ty.me/*.{0,1000}https\:\/\/1ty\.me\/.{0,1000}greyware_tool_keyword1ty.metemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AN/ACollectionhttps://1ty.me11#PastebinLikedownloading or uploading data1010N/AN/AN/AN/A47645
1038*https://1ty.me/?mode=ajax&cmd=create_note*.{0,1000}https\:\/\/1ty\.me\/\?mode\=ajax\&cmd\=create_note.{0,1000}greyware_tool_keyword1ty.metemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AN/AData Exfiltrationhttps://1ty.me11#PastebinLikecreating note1010N/AN/AN/AN/A47646
1039*https://aadinternals.com/aadinternals/*.{0,1000}https\:\/\/aadinternals\.com\/aadinternals\/.{0,1000}greyware_tool_keywordAADInternalsAADInternals PowerShell module for administering Azure AD and Office 365T1583 - T1558 - T1078 - T1136 - T1087 - T1114 - T1566 - T1056 - T1199 - T1098 - T1649 - T1621 - T1649TA0006 - TA0003 - TA0004 - TA0005 - TA0007 - TA0009 - TA0011N/AAPT29 - COZY BEARExploitation toolhttps://github.com/Gerenios/AADInternals11N/AN/A91014042312025-04-18T11:41:23Z2018-10-25T17:35:16Z47648
1040*https://aka.ms/DevTunnelCliInstall*.{0,1000}https\:\/\/aka\.ms\/DevTunnelCliInstall.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview01N/AN/A810N/AN/AN/AN/A47650
1041*https://aka.ms/TunnelsCliDownload/*.{0,1000}https\:\/\/aka\.ms\/TunnelsCliDownload\/.{0,1000}greyware_tool_keyworddev-tunnelsDev tunnels allow developers to securely share local web services across the internet. Enabling you to connect your local development environment with cloud services and share work in progress with colleagues or aid in building webhooksT1021.003 - T1105 - T1090TA0002 - TA0005 - TA0011N/AN/AC2https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/overview11N/AN/A810N/AN/AN/AN/A47651
1042*https://anonfiles.com/*/*.{0,1000}https\:\/\/anonfiles\.com\/.{0,1000}\/.{0,1000}greyware_tool_keywordanonfiles.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHubCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A47653
1043*https://anymailfinder.com/search/*.{0,1000}https\:\/\/anymailfinder\.com\/search\/.{0,1000}greyware_tool_keywordanymailfinderused by attackers to find informations about a company usersT1593 - T1596 - T1213TA0009N/AN/AReconnaissancehttps://anymailfinder.com11N/AN/AN/AN/AN/AN/AN/AN/A47654
1044*https://apaste.info/p/new*.{0,1000}https\:\/\/apaste\.info\/p\/new.{0,1000}greyware_tool_keywordapaste.infoCreating a paste on apaste.info/T1213 - T1190TA0001 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://apaste.info/11#PastebinLikeN/A910N/AN/AN/AN/A47655
1045*https://api.anonfiles.com/upload*.{0,1000}https\:\/\/api\.anonfiles\.com\/upload.{0,1000}greyware_tool_keywordanonfiles.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHubData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A47656
1046*https://api.dropboxapi.com/*.{0,1000}https\:\/\/api\.dropboxapi\.com\/.{0,1000}greyware_tool_keywordDBC2DBC2 (DropboxC2) is a modular post-exploitation tool composed of an agent running on the victim's machine - a controler running on any machine - powershell modules and Dropbox servers as a means of communication.T1105 - T1071.004 - T1102TA0003 - TA0002 - TA0008N/ABlackCat - Scattered Spider*C2https://github.com/Arno0x/DBC211N/ADropbox API calls - Understanding your environment with the applications used and allowed will enhances the effectiveness of your hunt here1010295862017-10-27T07:39:02Z2016-12-14T10:35:56Z47657
1047*https://api.fex.net/api/v1/anonymous/file*.{0,1000}https\:\/\/api\.fex\.net\/api\/v1\/anonymous\/file.{0,1000}greyware_tool_keywordfex.nethosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/AData Exfiltrationhttps://fex.net11#filehostingserviceuploading a file1010N/AN/AN/AN/A47659
1048*https://api.freefilesync.org/new_installation*.{0,1000}https\:\/\/api\.freefilesync\.org\/new_installation.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11#filehostingserviceN/A910N/AN/AN/AN/A47660
1049*https://api.hunter.io/*.{0,1000}https\:\/\/api\.hunter\.io\/.{0,1000}greyware_tool_keywordHunter.ioused by attacker and pentester while gathering information. Hunter lets you find email addresses in seconds and connect with the people that matter for your businessT1597 - T1526 - T1087 - T1078 - T1056 - T1018 - T1016 - T1583 - T1589TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011N/AN/AReconnaissancehttps://hunter.io/11N/AN/AN/A10N/AN/AN/AN/A47662
1050*https://api.openai.com/v1/files*.{0,1000}https\:\/\/api\.openai\.com\/v1\/files.{0,1000}greyware_tool_keywordratchatptC2 using openAI APIT1094 - T1071.001TA0011 - TA0002N/AN/AC2https://github.com/spartan-conseil/ratchatpt01N/Arisk of False positive10101662023-06-09T12:39:00Z2023-06-09T09:19:10Z47666
1051*https://api.tailscale.com/api/v2/*.{0,1000}https\:\/\/api\.tailscale\.com\/api\/v2\/.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47668
1052*https://api.telegram.org/bot*/sendMessage*.{0,1000}https\:\/\/api\.telegram\.org\/bot.{0,1000}\/sendMessage.{0,1000}greyware_tool_keywordTelegramRATCross Platform Telegram based RAT that communicates via telegram to evade network restrictionsT1071.001 - T1105 - T1027TA0011 - TA0005 - TA0002N/AN/AC2https://github.com/machine1337/TelegramRAT11N/AN/A1010372622024-01-23T12:05:59Z2023-06-30T10:59:55Z47669
1053*https://app.action1.com/agent/*/Windows/*.msi*.{0,1000}https\:\/\/app\.action1\.com\/agent\/.{0,1000}\/Windows\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordaction1Action1 remote administration tool abused buy attackerT1021 - T1071 - T1090TA0008 - TA0011N/ALockBit - MONTIRMMhttps://app.action1.com/11N/Ahttps://app.action1.com/agent/{ID}/Windows/agent(My_Organization).msi1010N/AN/AN/AN/A47670
1054*https://app.level.io/devices*.{0,1000}https\:\/\/app\.level\.io\/devices.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A47671
1055*https://apps.apple.com/us/app/tailscale/id*.{0,1000}https\:\/\/apps\.apple\.com\/us\/app\/tailscale\/id.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11#macosN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47672
1056*https://assist.zoho.com/assist-join?key=*.{0,1000}https\:\/\/assist\.zoho\.com\/assist\-join\?key\=.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47673
1057*https://assist.zoho.com/customer-session-details?client_token=*.{0,1000}https\:\/\/assist\.zoho\.com\/customer\-session\-details\?client_token\=.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47674
1058*https://assist.zoho.com/join?join_source=EMAIL_INVITE*.{0,1000}https\:\/\/assist\.zoho\.com\/join\?join_source\=EMAIL_INVITE.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47675
1059*https://assist.zoho.com/join-session?key=*.{0,1000}https\:\/\/assist\.zoho\.com\/join\-session\?key\=.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47676
1060*https://assist.zoho.com/org/*.{0,1000}https\:\/\/assist\.zoho\.com\/org\/.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47677
1061*https://assist.zoho.com/viewer-assist*.{0,1000}https\:\/\/assist\.zoho\.com\/viewer\-assist.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47678
1062*https://aur.archlinux.org/jprq.git*.{0,1000}https\:\/\/aur\.archlinux\.org\/jprq\.git.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11#linuxN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z47679
1063*https://bashupload.com*.{0,1000}https\:\/\/bashupload\.com.{0,1000}greyware_tool_keywordbashupload.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/AData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47683
1064*https://bayfiles.com/*.{0,1000}https\:\/\/bayfiles\.com\/.{0,1000}greyware_tool_keywordbayfileshosting site abused by attackers - blocked site in a lot of countriesT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ACyClopsCollectionN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47684
1065*https://bitbucket.org/*/downloads/*.bat*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47688
1066*https://bitbucket.org/*/downloads/*.dll*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47689
1067*https://bitbucket.org/*/downloads/*.dll*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47690
1068*https://bitbucket.org/*/downloads/*.exe*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47691
1069*https://bitbucket.org/*/downloads/*.ps1*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47692
1070*https://bitbucket.org/*/downloads/*.rar*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.rar.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47693
1071*https://bitbucket.org/*/downloads/*.zip*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47694
1072*https://boringproxy.io/installation*.{0,1000}https\:\/\/boringproxy\.io\/installation.{0,1000}greyware_tool_keywordboringproxySimple tunneling reverse proxy with a fast web UI and auto HTTPS. Designed for self-hosters.T1572TA0011 - TA0003N/AN/AC2https://github.com/boringproxy/boringproxy11N/AN/A101012761212024-07-06T10:13:37Z2020-09-26T21:58:07Z47702
1073*https://browser.lol/vnc?server=*.{0,1000}https\:\/\/browser\.lol\/vnc\?server\=.{0,1000}greyware_tool_keywordbrowser.lolVirtual Browser - Safely visit blocked or risky websites - can be used to bypass network restrictions within a corporate environmentT1071 - T1090 - T1562TA0005N/AN/ADefense Evasionhttps://browser.lol11N/AN/A89N/AN/AN/AN/A47703
1074*https://burrow.io/tunnels*.{0,1000}https\:\/\/burrow\.io\/tunnels.{0,1000}greyware_tool_keywordburrowExpose localhost to the internet using a public URLT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://burrow.io11N/AN/A98N/AN/AN/AN/A47707
1075*https://c3pool.com/#/*.{0,1000}https\:\/\/c3pool\.com\/\#\/.{0,1000}greyware_tool_keywordxmrigAuto setup scripts and pre-compiled xmr miner for c3pool.com poolT1496 - T1057TA0004 - TA0007N/APacha Group - APT4Cryptomininghttps://github.com/C3Pool/xmrig_setup/11N/AN/A9127212024-11-05T05:34:20Z2020-05-16T13:01:30Z47709
1076*https://clbin.com/*.{0,1000}https\:\/\/clbin\.com\/.{0,1000}greyware_tool_keywordclbin.comclbin.com be used for C&C purposes. The attacker will place commands on a textbin paste and have the malware fetch the commands.T1567.002TA0010 - TA0009N/AN/AData Exfiltrationhttps://clbin.com/11#PastebinLikeN/A88N/AN/AN/AN/A47711
1077*https://cloud.screenconnect.com/#/trialtoinstance?cookieValue=*.{0,1000}https\:\/\/cloud\.screenconnect\.com\/\#\/trialtoinstance\?cookieValue\=.{0,1000}greyware_tool_keywordScreenConnectConnectWise Control formerly known as Screenconnect is a remote desktop software application.T1021.001 - T1133TA0008 - TA0009 - TA0010 - TA0011N/ABlack Basta - BlackCat - LockBit - Scattered Spider* - Hive - Trigona - Medusa - Yanluowang - GOLD SOUTHFIELD - MuddyWater RMMhttps://screenconnect.connectwise.com/download11N/AN/A1010N/AN/AN/AN/A47712
1078*https://content.dropboxapi.com/2/files/upload*.{0,1000}https\:\/\/content\.dropboxapi\.com\/2\/files\/upload.{0,1000}greyware_tool_keyworddropboxuploading file to dropbox with the APIT1105 - T1071.001 - T1567.002TA0011 - TA0009 - TA0010N/ABlackCat - Scattered Spider* - Operation BugDrop - COZY BEAR - Turla - LockBit - PandoraData Exfiltrationhttps://github.com/I-Am-Jakoby/PowerShell-for-Hackers/blob/main/Functions/DropBox-Upload.md11#filehostingserviceN/A71012491462024-06-16T04:10:39Z2022-05-10T04:12:53Z47719
1079*https://crates.io/crates/localtunnel-client*.{0,1000}https\:\/\/crates\.io\/crates\/localtunnel\-client.{0,1000}greyware_tool_keywordRust LocaltunnelsLocaltunnel implementation in Rust - exposes your localhost endpoint to the worldT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/kaichaosun/rlt11N/AN/A72119132024-12-16T09:09:34Z2022-06-27T05:57:34Z47723
1080*https://crates.io/crates/localtunnel-server*.{0,1000}https\:\/\/crates\.io\/crates\/localtunnel\-server.{0,1000}greyware_tool_keywordRust LocaltunnelsLocaltunnel implementation in Rust - exposes your localhost endpoint to the worldT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/kaichaosun/rlt11N/AN/A72119132024-12-16T09:09:34Z2022-06-27T05:57:34Z47724
1081*https://docs.level.io/1.0/admin-guides/level-watchdog-task*.{0,1000}https\:\/\/docs\.level\.io\/1\.0\/admin\-guides\/level\-watchdog\-task.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A47738
1082*https://download.advanced-ip-scanner.com/download/files/*.exe*.{0,1000}https\:\/\/download\.advanced\-ip\-scanner\.com\/download\/files\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox11N/AN/A710N/AN/AN/AN/A47740
1083*https://downloads.level.io/install_linux.sh*.{0,1000}https\:\/\/downloads\.level\.io\/install_linux\.sh.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11#linuxN/A1010N/AN/AN/AN/A47742
1084*https://downloads.level.io/install_mac_os.sh*.{0,1000}https\:\/\/downloads\.level\.io\/install_mac_os\.sh.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A47743
1085*https://downloads.level.io/install_windows.exe*.{0,1000}https\:\/\/downloads\.level\.io\/install_windows\.exe.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11N/AN/A1010N/AN/AN/AN/A47744
1086*https://downloads.level.io/stable/level-linux-amd64*.{0,1000}https\:\/\/downloads\.level\.io\/stable\/level\-linux\-amd64.{0,1000}greyware_tool_keywordlevel.ioLevel is reinventing remote monitoring and managementT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider* - Black BastaRMMhttps://level.io/11#linuxN/A1010N/AN/AN/AN/A47745
1087*https://downloads.solarwinds.com/solarwinds/Release/DameWare/*.{0,1000}https\:\/\/downloads\.solarwinds\.com\/solarwinds\/Release\/DameWare\/.{0,1000}greyware_tool_keywordDamewareSolarwind Dameware Mini Remote Control tool T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://www.solarwinds.com/dameware-mini-remote-control11N/ADameware Mini Remote Control1010N/AN/AN/AN/A47746
1088*https://dropmefiles.com/*.{0,1000}https\:\/\/dropmefiles\.com\/.{0,1000}greyware_tool_keyworddropmefiles.comtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AMallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice SocietyCollectionhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C4811#filehostingservicedownloading files url86504512025-04-19T17:43:15Z2023-05-02T16:17:48Z47749
1089*https://dropmefiles.com/s3/upload/*.{0,1000}https\:\/\/dropmefiles\.com\/s3\/upload\/.{0,1000}greyware_tool_keyworddropmefiles.comtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AMallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice SocietyData Exfiltrationhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C4811#filehostingserviceuploading files url106504512025-04-19T17:43:15Z2023-05-02T16:17:48Z47750
1090*https://easyupload.io/*.{0,1000}https\:\/\/easyupload\.io\/.{0,1000}greyware_tool_keywordeasyupload.iofile hosting platform abused by attackers to host malicious - url used when downloading a file on the siteT1567.002 - T1071.001 - T1041 - T1036.002TA0009N/ABlack BastaCollectionN/A11#filehostingserviceN/A810N/AN/AN/AN/A47751
1091*https://easyupload.io/action.php*.{0,1000}https\:\/\/easyupload\.io\/action\.php.{0,1000}greyware_tool_keywordeasyupload.iohosting platform abused by attackersT1105 - T1071.001 - T1567.002 - T1041TA0010 - TA0005N/AAkiraData ExfiltrationN/A11#filehostingserviceuploading url86N/AN/AN/AN/A47752
1092*https://easyupload.io/cdn-cgi/rum*.{0,1000}https\:\/\/easyupload\.io\/cdn\-cgi\/rum.{0,1000}greyware_tool_keywordeasyupload.iohosting platform abused by attackersT1105 - T1071.001 - T1567.002 - T1041TA0010 - TA0005N/AAkiraData ExfiltrationN/A11#filehostingserviceuploading url86N/AN/AN/AN/A47753
1093*https://expose.dev/api/servers*.{0,1000}https\:\/\/expose\.dev\/api\/servers.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z47757
1094*https://expose.dev/register*.{0,1000}https\:\/\/expose\.dev\/register.{0,1000}greyware_tool_keywordexposetunneling service - written in pure PHPT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/beyondcode/expose11N/AN/A101043672802025-04-04T13:57:03Z2020-04-14T19:18:38Z47758
1095*https://file.io/*.{0,1000}https\:\/\/file\.io\/.{0,1000}greyware_tool_keywordfile.ioInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - ContiCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47761
1096*https://file.io/?title=*.{0,1000}https\:\/\/file\.io\/\?title\=.{0,1000}greyware_tool_keywordfile.ioInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - ContiData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47762
1097*https://filebin.net/*.{0,1000}https\:\/\/filebin\.net\/.{0,1000}greyware_tool_keywordfilebin.netfile hosting platform abused by attackers to host malicious file - raw access and api availableT1119TA0009 - TA0010N/AN/ACollectionhttps://filebin.net11#filehostingserviceN/A88N/AN/AN/AN/A47763
1098*https://files.catbox.moe/*https:\/\/files\.catbox\.moe\/[^\s\n]+greyware_tool_keywordcatbox.moeThe cutest free file host you've ever seen - abused by threat actorsT1560.001 - T1190 - T1102 - T1027.002TA0001 - TA0005 - TA0042N/AN/ACollectionhttps://files[.]catbox.moe11#filehostingserviceN/A910N/AN/AN/AN/A47764
1099*https://fleetdm.com/resources/install-fleetctl.sh*.{0,1000}https\:\/\/fleetdm\.com\/resources\/install\-fleetctl\.sh.{0,1000}greyware_tool_keywordfleetdmManage everything in one placeT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://github.com/fleetdm/fleet11N/AN/A101048965582025-04-22T21:05:02Z2020-11-03T22:17:18Z47765
1100*https://freefilesync.org/donate*.{0,1000}https\:\/\/freefilesync\.org\/donate.{0,1000}greyware_tool_keywordfreefilesyncfreefilesync is a backup and file synchronization program abused by attacker for data exfiltrationT1567.002 - T1020 - T1039TA0010 N/ALockBitData Exfiltrationhttps://freefilesync.org/download.php11#filehostingserviceN/A910N/AN/AN/AN/A47768
1101*https://get.telebit.io*.{0,1000}https\:\/\/get\.telebit\.io.{0,1000}greyware_tool_keywordtelebit.cloudAccess your devices - Share your stuff (shell from telebit.cloud)T1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://telebit.cloud/11N/AN/A1010N/AN/AN/AN/A47769
1102*https://github.com/mandiant/SilkETW/releases/download/v0.8/SilkETW_SilkService_v8.zip*.{0,1000}https\:\/\/github\.com\/mandiant\/SilkETW\/releases\/download\/v0\.8\/SilkETW_SilkService_v8\.zip.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive11N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z47778
1103*https://github-com.translate.goog/*.{0,1000}https\:\/\/github\-com\.translate\.goog\/.{0,1000}greyware_tool_keywordtranslate.googaccessing github through google translate (evasion) false positive riskT1090.003TA0005N/AN/ADefense Evasionhttps://*-com.translate.goog/*01N/AN/A13N/AN/AN/AN/A47782
1104*https://gofile.io/d/*.{0,1000}https\:\/\/gofile\.io\/d\/.{0,1000}greyware_tool_keywordransomware_notesdetection patterns retrieved in ransomware notes archivesT1486TA0040N/AN/ARansomwarehttps://github.com/threatlabz/ransomware_notes11N/Adownloading files from gofile.io104354552025-04-04T19:06:04Z2022-08-01T15:14:59Z47785
1105*https://googleweblight.com/i?u=*ipfs.*.html*.{0,1000}https\:\/\/googleweblight\.com\/i\?u\=.{0,1000}ipfs\..{0,1000}\.html.{0,1000}greyware_tool_keywordgoogleweblight.comOpen Redirect vulnerability being exploited by threat actors in Google Web LightT1584.001 - T1534TA0008N/AN/APhishinghttps://x.com/1ZRR4H/status/172306203968000025511N/AN/A910N/AN/AN/AN/A47786
1106*https://gost.run/tutorials/*.{0,1000}https\:\/\/gost\.run\/tutorials\/.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z47787
1107*https://gost.run/tutorials/api/config*.{0,1000}https\:\/\/gost\.run\/tutorials\/api\/config.{0,1000}greyware_tool_keywordgostGO Simple Tunnel - a simple tunnel written in golangT1572TA0011 - TA0003N/ADispossessor - EMBER BEARC2https://github.com/go-gost/gost11N/AN/A101049865732025-02-18T15:35:15Z2020-02-12T14:58:08Z47788
1108*https://homeway.io/install.sh*.{0,1000}https\:\/\/homeway\.io\/install\.sh.{0,1000}greyware_tool_keywordhomeway.ioExpose local servers to the internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://homeway.io/11#linuxN/A1010N/AN/AN/AN/A47795
1109*https://hunter.io/*.{0,1000}https\:\/\/hunter\.io\/.{0,1000}greyware_tool_keywordHunter.ioused by attacker and pentester while gathering information. Hunter lets you find email addresses in seconds and connect with the people that matter for your businessT1597 - T1526 - T1087 - T1078 - T1056 - T1018 - T1016 - T1583 - T1589TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011N/AN/AReconnaissancehttps://hunter.io/11N/AN/AN/AN/AN/AN/AN/AN/A47796
1110*https://hypertunnel.ga*.{0,1000}https\:\/\/hypertunnel\.ga.{0,1000}greyware_tool_keywordhypertunnelExpose any local TCP/IP service on the internetT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/berstend/hypertunnel11N/AN/A1010248472022-12-08T19:13:24Z2018-06-11T05:29:58Z47797
1111*https://ip138.com/iplookup.asp?ip=*&action=2*.{0,1000}https\:\/\/ip138\.com\/iplookup\.asp\?ip\=.{0,1000}\&action\=2.{0,1000}greyware_tool_keywordanyvieweraccess your unattended PC from anywhereT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMwww.anyviewer.com11N/AN/A1010N/AN/AN/AN/A47799
1112*https://ipv4.myip.wtf/text*.{0,1000}https\:\/\/ipv4\.myip\.wtf\/text.{0,1000}greyware_tool_keywordipv4.myip.wtfget public ip address. Used by disctopia-c2T1016 - T1071.001TA0005 - TA0002N/AN/AReconnaissancehttps://github.com/3ct0s/disctopia-c2/blob/main/libraries/disctopia.py11N/Agreyware_tools high risks of false positivesN/A106091392024-07-18T10:16:19Z2022-01-02T22:03:10Z47800
1113*https://jprq.io/auth*.{0,1000}https\:\/\/jprq\.io\/auth.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z47803
1114*https://jprq.io/install.sh*.{0,1000}https\:\/\/jprq\.io\/install\.sh.{0,1000}greyware_tool_keywordjprqexpose TCP protocols such as HTTP - SSH etc. Any server!T1572TA0011 - TA0003N/AN/AC2https://github.com/azimjohn/jprq11N/AN/A101013011782025-03-24T21:45:09Z2020-04-18T10:12:42Z47804
1115*https://link.remote.it/support/rpi-linux-quick-install*.{0,1000}https\:\/\/link\.remote\.it\/support\/rpi\-linux\-quick\-install.{0,1000}greyware_tool_keywordremoteitExpose localhost to internetT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/remoteit/installer11#linuxN/A10102492024-04-17T00:45:45Z2019-01-29T21:06:02Z47807
1116*https://localtunnel.me*.{0,1000}https\:\/\/localtunnel\.me.{0,1000}greyware_tool_keywordlocaltunnellocaltunnel exposes your localhost to the worldT1021 - T1090 - T1573 - T1219 - T1562.001TA0001 - TA0005 - TA0008 - TA0011N/AN/AC2https://github.com/localtunnel/localtunnel11N/AN/A10102055814282024-03-20T17:04:54Z2012-06-18T02:33:30Z47809
1117*https://localtunnel.me*.{0,1000}https\:\/\/localtunnel\.me.{0,1000}greyware_tool_keywordlocaltunnelsserver for localtunnel.me - localtunnel exposes your localhost to the world for easy testing and sharingT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/localtunnel/server11N/AN/A810316310332024-03-20T09:14:46Z2013-06-16T22:30:48Z47810
1118*https://localxpose.io/download*.{0,1000}https\:\/\/localxpose\.io\/download.{0,1000}greyware_tool_keywordlocalxposeLocalXpose is a reverse proxy that enables you to expose your localhost to the internetT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://localxpose.io/11N/AN/A101N/AN/AN/AN/A47811
1119*https://login.remotepc.com/rpcnew*.{0,1000}https\:\/\/login\.remotepc\.com\/rpcnew.{0,1000}greyware_tool_keywordRemotePCRemotePC Remote administration toolT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotepc.com/11N/AN/A1010N/AN/AN/AN/A47812
1120*https://login.tailscale.com/admin/settings/keys*.{0,1000}https\:\/\/login\.tailscale\.com\/admin\/settings\/keys.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47813
1121*https://maildrop.cc/inbox/?mailbox=*.{0,1000}https\:\/\/maildrop\.cc\/inbox\/\?mailbox\=.{0,1000}greyware_tool_keywordmaildropdisposable email address to use anytime.T1071.003TA0005 - TA0001N/AN/ADefense Evasionhttps://maildrop.cc/11N/AN/A45N/AN/AN/AN/A47814
1122*https://media.discordapp.net/attachments/*.bat*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.bat.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47821
1123*https://media.discordapp.net/attachments/*.exe*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.exe.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47822
1124*https://media.discordapp.net/attachments/*.hta*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.hta.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47823
1125*https://media.discordapp.net/attachments/*.iso*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.iso.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47824
1126*https://media.discordapp.net/attachments/*.jar*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.jar.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47825
1127*https://media.discordapp.net/attachments/*.msi*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.msi.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47826
1128*https://media.discordapp.net/attachments/*.py*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.py.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47827
1129*https://media.discordapp.net/attachments/*.vbs*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.vbs.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47828
1130*https://media.discordapp.net/attachments/*.zip*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.zip.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47829
1131*https://mega.io/cmd#download*.{0,1000}https\:\/\/mega\.io\/cmd\#download.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47831
1132*https://mega.nz/file/*.{0,1000}https\:\/\/mega\.nz\/file\/.{0,1000}greyware_tool_keywordmega.nzDirect file download links on Mega.nz - file sharing activity often abused by attackers for CollectionT1105 - T1114 - T1083TA0009N/AAkira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black BastaCollectionN/A11#filehostingservice #P2PN/A78N/AN/AN/AN/A47832
1133*https://mega.nz/folder/*.{0,1000}https\:\/\/mega\.nz\/folder\/.{0,1000}greyware_tool_keywordmega.nzDirect folder sharing links on Mega.nz for accessing multiple files - file sharing activity often abused by attackers for CollectionT1105 - T1114 - T1083TA0009N/AAkira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black BastaCollectionN/A11#filehostingservice #P2PN/A78N/AN/AN/AN/A47833
1134*https://mega.nz/folder/8L80QKyL#glRTp6Zc0gppwp03IG03tA*.{0,1000}https\:\/\/mega\.nz\/folder\/8L80QKyL\#glRTp6Zc0gppwp03IG03tA.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47834
1135*https://mega.nz/folder/bxomFKwL#3V1dUJFzL98t1GqXX29IXg*.{0,1000}https\:\/\/mega\.nz\/folder\/bxomFKwL\#3V1dUJFzL98t1GqXX29IXg.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47835
1136*https://mega.nz/folder/D0w0nYiY#egvjqP5R-anbBdsJg8QRVg*.{0,1000}https\:\/\/mega\.nz\/folder\/D0w0nYiY\#egvjqP5R\-anbBdsJg8QRVg.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47836
1137*https://mega.nz/folder/gflVFLhC#6neMkeJrt4dWboRTc1NLUg*.{0,1000}https\:\/\/mega\.nz\/folder\/gflVFLhC\#6neMkeJrt4dWboRTc1NLUg.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11N/AN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47837
1138*https://mega.nz/linux/repo/*.{0,1000}https\:\/\/mega\.nz\/linux\/repo\/.{0,1000}greyware_tool_keywordMEGAsyncsynchronize or backup your computers to MEGAT1567.002 - T1537 - T1020 - T1030TA0010 - TA0040N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://mega.io/en/desktop11#linuxN/A1010N/AN/AN/AN/A47838
1139*https://mega.nz/linux/repo/*.deb*.{0,1000}https\:\/\/mega\.nz\/linux\/repo\/.{0,1000}\.deb.{0,1000}greyware_tool_keywordMEGAcmdCommand Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers)T1071 - T1041 - T1105TA0010 - TA0009N/AAkira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEARData Exfiltrationhttps://github.com/meganz/MEGAcmd11#linuxN/A101020224102025-04-09T07:52:26Z2017-08-28T16:58:54Z47839
1140*https://meshcentral.com/login*.{0,1000}https\:\/\/meshcentral\.com\/login.{0,1000}greyware_tool_keywordmeshcentralMeshCentral is a full computer management web site - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMhttps://github.com/Ylianst/MeshAgent11N/AN/A103264962025-03-19T18:43:56Z2017-10-12T21:26:52Z47840
1141*https://myexternalip.com/raw*.{0,1000}https\:\/\/myexternalip\.com\/raw.{0,1000}greyware_tool_keywordmyexternalip.comreturn external ip addressT1046 - T1595 - T1595.001TA0007 - TA0040N/AN/AReconnaissancehttps://myexternalip.com/raw11N/AFalse positives warning - used by some C2 projects but legitimate site16N/AN/AN/AN/A47844
1142*https://new.express.adobe.com/publishedV2/urn:aaid:sc:*.{0,1000}https\:\/\/new\.express\.adobe\.com\/publishedV2\/urn\:aaid\:sc\:.{0,1000}greyware_tool_keywordadobe.comAttackers can use adobe.com to masquerade their domain for phishing purposes.T1204.002 - T1036 - T1566.002TA0001 - TA0005N/AN/ADefense EvasionN/A01N/AN/A11N/AN/AN/AN/A47846
1143*https://nopaste.net/*.{0,1000}https\:\/\/nopaste\.net\/.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/AData Exfiltrationhttps://www.shellhub.io/11#Pastebinlike #filehostingservicemonitor PUT requests for data exfiltration810N/AN/AN/AN/A47847
1144*https://nordvpn.com*/ovpn/*.ovpn*.{0,1000}https\:\/\/nordvpn\.com.{0,1000}\/ovpn\/.{0,1000}\.ovpn.{0,1000}greyware_tool_keywordNordVPNOVPN configuration for nordvpn accessed within corporate networkT1090.003 - T1133 - T1572TA0003 - TA0001 - TA0011 - TA0010 - TA0005N/AN/AData Exfiltrationhttps://nordvpn.com01#VPNN/A810N/AN/AN/AN/A47848
1145*https://nsproducts.azureedge.net/nsm-*/NetSupport*.{0,1000}https\:\/\/nsproducts\.azureedge\.net\/nsm\-.{0,1000}\/NetSupport.{0,1000}greyware_tool_keywordNetSupportNetSupport Manager is a remote access tool that can be used legitimately for IT management but has also been abused by adversaries for remote system control and surveillanceT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ACuba - EvilCorp* - Black Basta - MoskalvzapoeRMMhttps://www.netsupportmanager.com/11N/AN/A1010N/AN/AN/AN/A47852
1146*https://oshi.at/*.{0,1000}https\:\/\/oshi\.at\/.{0,1000}greyware_tool_keywordOshiUploadEphemeral file sharing engineT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/ABlack BastaData Exfiltrationhttps://github.com/somenonymous/OshiUpload11#filehostingservice #P2PN/A102195252025-04-02T12:44:45Z2019-05-11T02:08:51Z47855
1147*https://pagekite.net/downloads/*.{0,1000}https\:\/\/pagekite\.net\/downloads\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z47856
1148*https://pagekite.net/pk/src/*.{0,1000}https\:\/\/pagekite\.net\/pk\/src\/.{0,1000}greyware_tool_keywordPyPagekiteThis is pagekite.py a fast and reliable tool to make localhost servers visible to the public Internet.T1572TA0011 - TA0003N/AN/AC2https://github.com/pagekite/PyPagekite11N/AN/A10107301232025-04-16T15:26:26Z2010-10-23T00:03:37Z47857
1149*https://portal.ehorus.com/#/agents/*.{0,1000}https\:\/\/portal\.ehorus\.com\/\#\/agents\/.{0,1000}greyware_tool_keywordEHORUS RMMPandora RC (formerly called eHorus) is a computer management system for MS Windows - Linux and MacOS that allows access to registered computers wherever they are from a browser without direct connectivity to their devices from the outside. (server based on VNC)T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlacksuit - RoyalRMMhttps://pandorafms.com/en/remote-control/11N/AN/A1010N/AN/AN/AN/A47870
1150*https://portal.xeox.com/*.{0,1000}https\:\/\/portal\.xeox\.com\/.{0,1000}greyware_tool_keywordxeoxEasily access and manage Windows devices remotely within XEOX - RMM abused by threat actorsT1021 - T1078 - T1219 - T1105 - T1046TA0011 - TA0010 - TA0003 - TA0005N/ADispossessorRMMhttps://xeox.com/remote-access/11N/AN/A1010N/AN/AN/AN/A47871
1151*https://portr.dev/client/installation/*.{0,1000}https\:\/\/portr\.dev\/client\/installation\/.{0,1000}greyware_tool_keywordPortrPortr is a tunnel solution that allows you to expose local http, tcp or websocket connections to the public internetT1572 - T1090TA0011 - TA0005N/AN/AC2https://github.com/amalshaji/portr11N/AN/A10102409722025-04-17T16:06:58Z2023-11-21T11:14:01Z47872
1152*https://privatebin.net/*.{0,1000}https\:\/\/privatebin\.net\/.{0,1000}greyware_tool_keywordprivatebin.netInteresting observation on the file-sharing platform preferences derived from the negotiations chats with Black Basta victimsT1071.001 - T1567.002 - T1005TA0010 - TA0009N/ABlack BastaData ExfiltrationN/A01#PastebinLikeN/A56N/AN/AN/AN/A47873
1153*https://privatix-temp-mail-v1.p.rapidapi.com/request/domains/*.{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/domains\/.{0,1000}greyware_tool_keywordtemp-mailusing the API of a disposable email address to use anytime - could be abused by malicious actorsT1071.003TA0005 - TA0001N/AN/ADefense Evasiontemp-mail.org11N/Aapi doc https://rapidapi.com/Privatix/api/temp-mail910N/AN/AN/AN/A47875
1154*https://privatix-temp-mail-v1.p.rapidapi.com/request/mail/id/null/*.{0,1000}https\:\/\/privatix\-temp\-mail\-v1\.p\.rapidapi\.com\/request\/mail\/id\/null\/.{0,1000}greyware_tool_keywordtemp-mailusing the API of a disposable email address to use anytime - could be abused by malicious actorsT1071.003TA0005 - TA0001N/AN/ADefense Evasiontemp-mail.org11N/Aapi doc https://rapidapi.com/Privatix/api/temp-mail910N/AN/AN/AN/A47877
1155*https://privnote.com/*.{0,1000}https\:\/\/privnote\.com\/.{0,1000}greyware_tool_keywordprivnote.comtemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAkira - Black BastaCollectionhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Akira/20240620.json#L31C27-L31C4811#PastebinLikedownloading files url56504512025-04-19T17:43:15Z2023-05-02T16:17:48Z47878
1156*https://pubsub.zoho.com/*_deskUserPresence/pubsub*.{0,1000}https\:\/\/pubsub\.zoho\.com\/.{0,1000}_deskUserPresence\/pubsub.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47881
1157*https://put.io/?login*.{0,1000}https\:\/\/put\.io\/\?login.{0,1000}greyware_tool_keywordput.ioA storage and torrenting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AScattered Spider - RagnarLocker - MedusaData Exfiltrationhttps://put.i11#filehostingservice #P2PN/A1010N/AN/AN/AN/A47882
1158*https://put.io/default/magnet?url=*.{0,1000}https\:\/\/put\.io\/default\/magnet\?url\=.{0,1000}greyware_tool_keywordput.ioA storage and torrenting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AScattered Spider - RagnarLocker - MedusaCollectionhttps://put.i11#filehostingservice #P2PN/A1010N/AN/AN/AN/A47883
1159*https://put.io/transfers*.{0,1000}https\:\/\/put\.io\/transfers.{0,1000}greyware_tool_keywordput.ioA storage and torrenting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AScattered Spider - RagnarLocker - MedusaData Exfiltrationhttps://put.i11#filehostingservice #P2PN/A1010N/AN/AN/AN/A47884
1160*https://put.io/v2/oauth2/register*.{0,1000}https\:\/\/put\.io\/v2\/oauth2\/register.{0,1000}greyware_tool_keywordput.ioA storage and torrenting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AScattered Spider - RagnarLocker - MedusaData Exfiltrationhttps://put.i11#filehostingservice #P2PN/A1010N/AN/AN/AN/A47885
1161*https://qaz.im/*.{0,1000}https\:\/\/qaz\.im\/.{0,1000}greyware_tool_keywordqaz.imtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaData Exfiltrationhttps://qaz.im/11#filehostingserviceuploading files url1010N/AN/AN/AN/A47889
1162*https://qaz.im/load/*.{0,1000}https\:\/\/qaz\.im\/load\/.{0,1000}greyware_tool_keywordqaz.imtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.im/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47890
1163*https://qaz.im/zaq/*.{0,1000}https\:\/\/qaz\.im\/zaq\/.{0,1000}greyware_tool_keywordqaz.imtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.im/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47891
1164*https://qaz.is/*.{0,1000}https\:\/\/qaz\.is\/.{0,1000}greyware_tool_keywordqaz.istemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaData Exfiltrationhttps://qaz.is/11#filehostingserviceuploading files url1010N/AN/AN/AN/A47892
1165*https://qaz.is/load/*.{0,1000}https\:\/\/qaz\.is\/load\/.{0,1000}greyware_tool_keywordqaz.istemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.is/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47893
1166*https://qaz.is/zaq/*.{0,1000}https\:\/\/qaz\.is\/zaq\/.{0,1000}greyware_tool_keywordqaz.istemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.is/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47894
1167*https://qaz.su*.{0,1000}https\:\/\/qaz\.su.{0,1000}greyware_tool_keywordqaz.sutemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaData Exfiltrationhttps://qaz.su/11#filehostingserviceuploading files url1010N/AN/AN/AN/A47895
1168*https://qaz.su/load/*.{0,1000}https\:\/\/qaz\.su\/load\/.{0,1000}greyware_tool_keywordqaz.sutemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.su/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47896
1169*https://qaz.su/zaq/*.{0,1000}https\:\/\/qaz\.su\/zaq\/.{0,1000}greyware_tool_keywordqaz.sutemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.su/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47897
1170*https://qu.ax/*.*https\:\/\/qu\.ax\/[^\s\n]+greyware_tool_keywordqu.axqu.ax is a quick and private file hosting service - abused by threat actorsT1560.001 - T1190 - T1102 - T1027.002TA0001 - TA0005 - TA0042N/AN/ACollectionhttps://qu[.]ax/11#filehostingserviceN/A910N/AN/AN/AN/A47898
1171*https://rclone.org/install.sh*.{0,1000}https\:\/\/rclone\.org\/install\.sh.{0,1000}greyware_tool_keywordrcloneRclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groupsT1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083TA0010N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - GamaredonData Exfiltrationhttps://github.com/rclone/rclone11N/AN/A8104996344532025-04-22T16:26:31Z2014-03-16T16:19:57Z47906
1172*https://rdprelay*.support.services.microsoft.com*.{0,1000}https\:\/\/rdprelay.{0,1000}\.support\.services\.microsoft\.com.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A47907
1173*https://remoteassistance.support.services.microsoft.com/*.{0,1000}https\:\/\/remoteassistance\.support\.services\.microsoft\.com\/.{0,1000}greyware_tool_keywordQuickAssistSharing remote desktop with Microsoft Quick assitT1021 - T1071 - T1090TA0003 - TA0008 - TA0011LokiBotBlack BastaRMMhttps://apps.microsoft.com/detail/9p7bp5vnwkx511N/AQuick assist could be preinstalled in some Windows versions1010N/AN/AN/AN/A47909
1174*https://remotedesktop.google.com/_/oauthredirect*.{0,1000}https\:\/\/remotedesktop\.google\.com\/_\/oauthredirect.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com11N/AN/A1010N/AN/AN/AN/A47910
1175*https://remotedesktop.google.com/headless*.{0,1000}https\:\/\/remotedesktop\.google\.com\/headless.{0,1000}greyware_tool_keywordGoogle Remote DesktopGoogle Chrome Remote Desktop to access remote computers - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AScattered Spider*RMMhttps://remotedesktop.google.com11N/AN/A1010N/AN/AN/AN/A47911
1176*https://rentry.co/*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}greyware_tool_keywordrentry.coaccessing a pastebinlike site - often abused by malwareT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A58N/AN/AN/AN/A47912
1177*https://rentry.co/*/raw*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A47913
1178*https://rentry.co/cdn-cgi/challenge-platform/*.{0,1000}https\:\/\/rentry\.co\/cdn\-cgi\/challenge\-platform\/.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A47914
1179*https://requestbin.net/r/*.{0,1000}https\:\/\/requestbin\.net\/r\/.{0,1000}greyware_tool_keywordrequestbin.netallows users to create a unique URL to collect and inspect HTTP requests. It is commonly used for debugging webhooks - it can also be abused by attackers for verifying the reachability and effectiveness of their payloadsT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2http://requestbin.net11N/AOut of band interaction domains1010N/AN/AN/AN/A47915
1180*https://s3.amazonaws.com/sshx/sshx-*.{0,1000}https\:\/\/s3\.amazonaws\.com\/sshx\/sshx\-.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z47916
1181*https://s3.filebin.net/filebin/*.{0,1000}https\:\/\/s3\.filebin\.net\/filebin\/.{0,1000}greyware_tool_keywordfilebin.netfile hosting platform abused by attackers to host malicious file - raw access and api availableT1119TA0009N/AN/ACollectionhttps://filebin.net11#filehostingserviceN/A88N/AN/AN/AN/A47917
1182*https://secure.logmeinrescue.com/R?i=2&Code=*.{0,1000}https\:\/\/secure\.logmeinrescue\.com\/R\?i\=2\&Code\=.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A47919
1183*https://secure.logmeinrescue.com/TechnicianConsole/Launch*.{0,1000}https\:\/\/secure\.logmeinrescue\.com\/TechnicianConsole\/Launch.{0,1000}greyware_tool_keywordLogMeInLogMeIn is a legitimate remote support software that allows IT and customer support teams to remotely access and control devices to provide support - abused by threat actors T1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ABlackSuit - Royal - Trigona - YanluowangRMMhttps://www.logmein.com11N/AN/A1010N/AN/AN/AN/A47920
1184*https://send.exploit.in/api/download*.{0,1000}https\:\/\/send\.exploit\.in\/api\/download.{0,1000}greyware_tool_keywordsend.exploit.indownloading files - hosting service frequently exploited by attackers - should be blockedT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ALockBit - Hive - Black BastaCollectionN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47921
1185*https://send.exploit.in/api/info/*.{0,1000}https\:\/\/send\.exploit\.in\/api\/info\/.{0,1000}greyware_tool_keywordsend.exploit.inuploading files - hosting service frequently exploited by attackers - should be blockedT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ALockBit - Hive - Black BastaData ExfiltrationN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47922
1186*https://send.exploit.in/api/metadata/*.{0,1000}https\:\/\/send\.exploit\.in\/api\/metadata\/.{0,1000}greyware_tool_keywordsend.exploit.inuploading files - hosting service frequently exploited by attackers - should be blockedT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ALockBit - Hive - Black BastaData ExfiltrationN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47923
1187*https://senet-flets.v6.softether.co.jp/ddns/ddns.aspx*.{0,1000}https\:\/\/senet\-flets\.v6\.softether\.co\.jp\/ddns\/ddns\.aspx.{0,1000}greyware_tool_keywordSoftEtherVPNCross-platform multi-protocol VPN software abused by attackersT1133 - T1210 - T1573 - T1219 - T1571TA0001 - TA0002 - TA0003 - TA0005 - TA0010N/AGALLIUMDefense Evasionhttps://github.com/SoftEtherVPN/SoftEtherVPN11#VPNN/A8101218326472025-04-13T22:05:51Z2014-01-02T12:40:57Z47924
1188*https://share.riseup.net/2*.{0,1000}https\:\/\/share\.riseup\.net\/2.{0,1000}greyware_tool_keywordshare.riseup.nettemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLockerCollectionhttps://share.riseup.net11#filehostingservicedownloading files url1010N/AN/AN/AN/A47925
1189*https://share.riseup.net/up*.{0,1000}https\:\/\/share\.riseup\.net\/up.{0,1000}greyware_tool_keywordshare.riseup.nettemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLockerData Exfiltrationhttps://share.riseup.net11#filehostingserviceuploading files url1010N/AN/AN/AN/A47926
1190*https://silentbreaksecurity.com/adaptive-dll-hijacking*.{0,1000}https\:\/\/silentbreaksecurity\.com\/adaptive\-dll\-hijacking.{0,1000}greyware_tool_keywordIObitUnlockerunlocking locked files on Windows systemsT1222 - T1070 - T1485TA0005 - TA0040N/APLAYDefense Evasionhttps://www.iobit.com/en/iobit-unlocker.php#11N/Aoften used legitimatly - admin tool59N/AN/AN/AN/A47929
1191*https://slack.com/api/channels.create*.{0,1000}https\:\/\/slack\.com\/api\/channels\.create.{0,1000}greyware_tool_keywordslackAPI usage of slack - creating channel - abused by multiple C2T1059.003 - T1071.004 - T1562.001TA0002 - TA0010 - TA0011N/AN/AC2https://github.com/mthcht/Purpleteam/blob/main/Detection/Threat%20Hunting/generic/C2_abusing_API_services.md01N/A/!\ very high risk of FP - hunting only12184192024-12-20T10:22:25Z2022-12-05T12:40:02Z47930
1192*https://spark.adobe.com/page/*.{0,1000}https\:\/\/spark\.adobe\.com\/page\/.{0,1000}greyware_tool_keywordadobe.comAttackers can use adobe.com to masquerade their domain for phishing purposes.T1204.002 - T1036 - T1566.002TA0001 - TA0005N/AN/ADefense Evasionhttps://www.joesandbox.com/analysis/515360/0/html01N/AN/A11N/AN/AN/AN/A47936
1193*https://sshx.io/get*.{0,1000}https\:\/\/sshx\.io\/get.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z47939
1194*https://sshx.io/s/*.{0,1000}https\:\/\/sshx\.io\/s\/.{0,1000}greyware_tool_keywordsshxFast collaborative live terminal sharing over the webT1021.004 - T1041 - T1059 - T1071.001TA0002 - TA0009 - TA0011 - TA0010N/AN/AC2https://github.com/ekzhang/sshx11N/AN/A101063792202025-02-12T20:40:30Z2022-02-12T23:29:33Z47940
1195*https://steamcommunity.com/profiles/*.{0,1000}https\:\/\/steamcommunity\.com\/profiles\/.{0,1000}greyware_tool_keywordsteamSteam profiles have been leveraged to host payload addresses for malware delivery - making them a potential threat vector in corporate environments. This tactic can serve as a valuable hunting tip for threat detection effortsT1102 - T1091 - T1204TA0001 - TA0009Lumma StealerN/ACollectionN/A01N/AN/A11N/AN/AN/AN/A47941
1196*https://store-*.ufile.io/v1/upload/*.{0,1000}https\:\/\/store\-.{0,1000}\.ufile\.io\/v1\/upload\/.{0,1000}greyware_tool_keywordufile.iotemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AHiveData Exfiltrationhttps://ufile.io11N/Auploading files url1010N/AN/AN/AN/A47942
1197*https://sun.aweray.com/*/download*.{0,1000}https\:\/\/sun\.aweray\.com\/.{0,1000}\/download.{0,1000}greyware_tool_keywordawerayall-in-one secure remote access control and support solutionT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/AN/ARMMsun.aweray.com11N/AN/A1010N/AN/AN/AN/A47943
1198*https://tailscale.com/s/resolvconf-overwrite*.{0,1000}https\:\/\/tailscale\.com\/s\/resolvconf\-overwrite.{0,1000}greyware_tool_keywordtailscaleTailscale connects your team's devices and development environments for easy access to remote resources.T1021 - T1573 TA0005 - TA0001 - TA0010 N/AScattered Spider*Defense Evasionhttps://github.com/tailscale/tailscale11N/AN/A9102219617712025-04-22T19:46:43Z2020-01-31T22:00:03Z47954
1199*https://temp.sh/*/*.{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000}greyware_tool_keywordtemp.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47955
1200*https://temp.sh/upload*.{0,1000}https\:\/\/temp\.sh\/upload.{0,1000}greyware_tool_keywordtemp.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47956
1201*https://tempsend.com/*.{0,1000}https\:\/\/tempsend\.com\/.{0,1000}greyware_tool_keywordtempsend.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/ACollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47957
1202*https://tempsend.com/send*.{0,1000}https\:\/\/tempsend\.com\/send.{0,1000}greyware_tool_keywordtempsend.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/AData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47958
1203*https://termbin.com/test*.{0,1000}https\:\/\/termbin\.com\/test.{0,1000}greyware_tool_keywordtermbin.comaccessing paste raw contentT1119TA0009N/AN/ACollectiontermbin.com11N/AN/A88N/AN/AN/AN/A47959
1204*https://textbin.net/raw/*.{0,1000}https\:\/\/textbin\.net\/raw\/.{0,1000}greyware_tool_keywordtextbin.nettextbin.net raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectiontextbin.net11#PastebinLikegreyware tool - risks of False positive !1010N/AN/AN/AN/A47960
1205*https://tmate.io/t/*.{0,1000}https\:\/\/tmate\.io\/t\/.{0,1000}greyware_tool_keywordtmateInstant terminal sharingT1071 - T1105 - T1573 - T1021TA0010 - TA0011 - TA0008 - TA0002N/AWatchDogC2https://github.com/tmate-io/tmate11#linuxN/A101057863152023-10-16T11:59:37Z2013-06-12T20:29:22Z47962
1206*https://tmpfiles.org/dl/*.exe*.{0,1000}https\:\/\/tmpfiles\.org\/dl\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordtmpfiles.orgdownload of an executable files from tmpfiles.org often used by ransomware groupsT1566.002 - T1192 - T1105TA0001 - TA0002N/AN/ACollectionN/A11#filehostingservicegreyware tool - risk of false positive !1010N/AN/AN/AN/A47963
1207*https://tox.chat/download.html*.{0,1000}https\:\/\/tox\.chat\/download\.html.{0,1000}greyware_tool_keywordransomware_notesdetection patterns retrieved in ransomware notes archivesT1486TA0040N/AN/ARansomwarehttps://github.com/threatlabz/ransomware_notes11N/AN/A104354552025-04-04T19:06:04Z2022-08-01T15:14:59Z47965
1208*https://track.adform.net/C/?bn=*;cpdir=http*.{0,1000}https\:\/\/track\.adform\.net\/C\/\?bn\=.{0,1000}\;cpdir\=http.{0,1000}greyware_tool_keywordtrack.adform.netAttackers can use track.adform.net to masquerade their domain for phishing purposes.T1204.002 - T1036 - T1566.002TA0001 - TA0005N/AN/ADefense Evasionhttps://www.joesandbox.com/analysis/514456/0/html01N/AN/A55N/AN/AN/AN/A47966
1209*https://transfer.sh*.{0,1000}https\:\/\/transfer\.sh.{0,1000}greyware_tool_keywordtransfer.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47967
1210*https://transfert-my-files.com/files/*.{0,1000}https\:\/\/transfert\-my\-files\.com\/files\/.{0,1000}greyware_tool_keywordtransfert-my-files.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/ACollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47970
1211*https://transfert-my-files.com/inc/upload.php*.{0,1000}https\:\/\/transfert\-my\-files\.com\/inc\/upload\.php.{0,1000}greyware_tool_keywordtransfert-my-files.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/AData Exfiltrationhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47971
1212*https://tunnel.pyjam.as/*.{0,1000}https\:\/\/tunnel\.pyjam\.as\/.{0,1000}greyware_tool_keywordtunnelSSL-terminated ephemeral HTTP tunnels to your local machineT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://gitlab.com/pyjam.as/tunnel11N/AN/A1010N/AN/AN/AN/A47973
1213*https://tunnelmole.com/docs*.{0,1000}https\:\/\/tunnelmole\.com\/docs.{0,1000}greyware_tool_keywordtunnelmole-clienttmole - Share your local server with a Public URLT1572TA0011 - TA0003N/AN/AC2https://github.com/robbie-cahill/tunnelmole-client/11N/AN/A10101382862025-04-04T09:06:21Z2023-02-08T08:27:57Z47974
1214*https://tunwg.com*.{0,1000}https\:\/\/tunwg\.com.{0,1000}greyware_tool_keywordtunwgEnd to end encrypted secure tunnel to local serversT1572 - T1048TA0011 - TA0010 - TA0005N/AN/AC2https://github.com/ntnj/tunwg11N/AN/A101023682024-09-18T15:03:45Z2023-01-16T17:51:13Z47977
1215*https://ufile.io/*.{0,1000}https\:\/\/ufile\.io\/.{0,1000}greyware_tool_keywordufile.iotemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AHiveCollectionhttps://ufile.io11N/Adownloading files url56N/AN/AN/AN/A47978
1216*https://ufile.io/v1/upload/*.{0,1000}https\:\/\/ufile\.io\/v1\/upload\/.{0,1000}greyware_tool_keywordufile.iotemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AHiveData Exfiltrationhttps://ufile.io11#filehostingserviceuploading files url1010N/AN/AN/AN/A47979
1217*https://update.lansweeper.com/installation.aspx*.{0,1000}https\:\/\/update\.lansweeper\.com\/installation\.aspx.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/11N/AN/A67N/AN/AN/AN/A47981
1218*https://us4-wms6.zoho.com*.{0,1000}https\:\/\/us4\-wms6\.zoho\.com.{0,1000}greyware_tool_keywordZoho AssistZoho Assist Remote access software - abused by attackersT1021 - T1071 - T1090TA0003 - TA0008 - TA0011N/ALockBit - Scattered Spider*RMMhttps://www.zoho.com/assist/11N/AN/A1010N/AN/AN/AN/A47982
1219*https://usaupload.com/account/ajax/load_files*.{0,1000}https\:\/\/usaupload\.com\/account\/ajax\/load_files.{0,1000}greyware_tool_keywordusauploaduploading files to usauploadT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/AN/AData Exfiltrationhttps://usaupload.com/11#filehostingserviceN/A1010N/AN/AN/AN/A47983
1220*https://usaupload.com/account/ajax/uploader*.{0,1000}https\:\/\/usaupload\.com\/account\/ajax\/uploader.{0,1000}greyware_tool_keywordusauploaduploading files to usauploadT1030 - T1048 - T1078.004 - T1105 - T1567.001TA0010N/AN/AData Exfiltrationhttps://usaupload.com/11#filehostingserviceN/A1010N/AN/AN/AN/A47984
1221*https://we.tl/t-*.{0,1000}https\:\/\/we\.tl\/t\-.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47987
1222*https://webhook.site/*-*-*-*.{0,1000}https\:\/\/webhook\.site\/.{0,1000}\-.{0,1000}\-.{0,1000}\-.{0,1000}greyware_tool_keywordwebhook.sitetest HTTP webhooks with this handy tool that displays requests instantly - abused by attacker for payload callback confirmationT1102 - T1071 - T1560.001TA0011 - TA0042N/AN/AC2https://github.com/webhooksite/webhook.site11N/AOut of band interaction domains101058064572025-04-04T10:42:59Z2016-03-21T08:45:42Z47990
1223*https://wetransfer.com/api/v4/transfers/*.{0,1000}https\:\/\/wetransfer\.com\/api\/v4\/transfers\/.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47991
1224*https://wetransfer.com/downloads/*.{0,1000}https\:\/\/wetransfer\.com\/downloads\/.{0,1000}greyware_tool_keywordwetransferWeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share filesT1608.001 - T1566 - T1002 - T1048 - T1204TA0001 - TA0002 - TA0010N/AEXOTIC LILYPhishinghttps://twitter.com/mthcht/status/165885384832318259711N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47992
1225*https://www.4shared.com/get/*.{0,1000}https\:\/\/www\.4shared\.com\/get\/.{0,1000}greyware_tool_keyword4shared.comDownloading a file from 4shared.comT1105 - T1071 - T1125TA0009N/ATurlaCollection4shared.com11#filehostingserviceN/A65N/AN/AN/AN/A47998
1226*https://www.autohotkey.com/download/*.{0,1000}https\:\/\/www\.autohotkey\.com\/download\/.{0,1000}greyware_tool_keywordAhk2ExeOfficial AutoHotkey script compiler - misused in scripting malicious executablesT1059 - T1204 - T1036 - T1027TA0002 - TA0005N/AN/ADefense Evasionhttps://github.com/AutoHotkey/Ahk2Exe11N/AN/A776581182025-03-09T02:27:33Z2011-08-01T10:28:19Z47999
1227*https://www.btunnel.in/downloads*.{0,1000}https\:\/\/www\.btunnel\.in\/downloads.{0,1000}greyware_tool_keywordbtunnelBtunnel is a publicly accessible reverse proxyT1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://www.btunnel.in11N/AN/A98N/AN/AN/AN/A48003
1228*https://www.dataplicity.com/*.py*.{0,1000}https\:\/\/www\.dataplicity\.com\/.{0,1000}\.py.{0,1000}greyware_tool_keywordDataplicityenables connecting local systems to dataplicity cloud for remotely accessing them over the internet.T1090 - T1102 - T1043 - T1071TA0010 - TA0005 - TA0011N/AN/AData Exfiltrationhttps://github.com/wildfoundry/dataplicity-agent11N/AN/A92167322024-06-10T20:17:43Z2016-07-27T14:23:01Z48004
1229*https://www.duckdns.org/update?domains=*.{0,1000}https\:\/\/www\.duckdns\.org\/update\?domains\=.{0,1000}greyware_tool_keywordduckdns.orgA simple C# DuckDNS updater - free dynamic DNS hosted on AWS - often used by threat actors for contacting C2T1568.002 - T1071.001TA0011 - TA0005N/AN/ADefense Evasionhttps://www.duckdns.org/install.jsp11N/AN/A510N/AN/AN/AN/A48005
1230*https://www.email-format.com/d/*.{0,1000}https\:\/\/www\.email\-format\.com\/d\/.{0,1000}greyware_tool_keywordemail-formatused by attackers to find informations about a company usersT1593 - T1596 - T1213TA0009N/AN/AReconnaissancehttps://www.email-format.com11N/AN/AN/AN/AN/AN/AN/AN/A48006
1231*https://www.guerrillamail.com/compose*.{0,1000}https\:\/\/www\.guerrillamail\.com\/compose.{0,1000}greyware_tool_keywordguerrillamaildisposable email address to use anytime.T1071.003TA0005 - TA0001N/AN/ADefense Evasionhttps://www.guerrillamail.com11N/AN/A1010N/AN/AN/AN/A48008
1232*https://www.guerrillamail.com/inbox*.{0,1000}https\:\/\/www\.guerrillamail\.com\/inbox.{0,1000}greyware_tool_keywordguerrillamaildisposable email address to use anytime.T1071.003TA0005 - TA0001N/AN/ADefense Evasionhttps://www.guerrillamail.com11N/AN/A89N/AN/AN/AN/A48009
1233*https://www.lansweeper.com/installation.aspx*.{0,1000}https\:\/\/www\.lansweeper\.com\/installation\.aspx.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/11N/AN/A67N/AN/AN/AN/A48012
1234*https://www.majorgeeks.com/files/details/pc_hunter.html*.{0,1000}https\:\/\/www\.majorgeeks\.com\/files\/details\/pc_hunter\.html.{0,1000}greyware_tool_keywordPCHunterPCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirusT1562 - T1055 - T1070TA0005 - TA0004N/ALockBit - Conti - 8BASE - TargetCompany - Hive - QilinDefense Evasionhttps://www.majorgeeks.com/files/details/pc_hunter.html11N/AN/A810N/AN/AN/AN/A48013
1235*https://www.mediafire.com/api/*/folder/get_content.php*.{0,1000}https\:\/\/www\.mediafire\.com\/api\/.{0,1000}\/folder\/get_content\.php.{0,1000}greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1114 - T1083TA0009N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A48014
1236*https://www.nirsoft.net/toolsdownload/*.{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}greyware_tool_keywordnirsoft toolsNirSoft is a legitimate software company that develops system utilities for Windows. Some of its tools can be used by malicious actors to recover passwords harvest sensitive information and conduct password attacks.T1003 - T1003.001 - T1003.002 - T1110 - T1566TA0002 - TA0003 - TA0004 - TA0006 - TA0007 - TA0008 - TA0011N/AN/ACollectionN/A11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48016
1237*https://www.nirsoft.net/toolsdownload/*.exe*.{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordnirsoft toolssome of nirsoft tools can be abused by attackers to retrieve passwords T1003 - T1021 - T1056 - T1110 - T1212 - T1552TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011N/AN/ACredential Accessnirsoft.net11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48017
1238*https://www.nirsoft.net/toolsdownload/*.zip*.{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordnirsoft toolssome of nirsoft tools can be abused by attackers to retrieve passwords T1003 - T1021 - T1056 - T1110 - T1212 - T1552TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011N/AN/ACredential Accessnirsoft.net11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48018
1239*https://www.nirsoft.net/utils/*.exe*.{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordnirsoft toolssome of nirsoft tools can be abused by attackers to retrieve passwords T1003 - T1021 - T1056 - T1110 - T1212 - T1552TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011N/AN/ACredential Accessnirsoft.net11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48019
1240*https://www.nirsoft.net/utils/*.zip*.{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordnirsoft toolssome of nirsoft tools can be abused by attackers to retrieve passwords T1003 - T1021 - T1056 - T1110 - T1212 - T1552TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011N/AN/ACredential Accessnirsoft.net11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48020
1241*https://www.premiumize.me/*.{0,1000}https\:\/\/www\.premiumize\.me\/.{0,1000}greyware_tool_keywordpremiumize.mehosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/ACollectionwww.premiumize.me11#filehostingservice #P2PN/A1010N/AN/AN/AN/A48022
The file is too large to be shown. View Raw