Files
Kostas 9e0c2a7912 Enhance Linux Telemetry with New Features and Improvements (#99)
* Uptycs addition

* Update EDR_telem.json

Updates based on evidence to be provided.

* Update EDR_telem.json

Minor correction to match evidence provided.

* Post-review update for Uptycs

* Update EDR_telem.json

Changes per updated evidence provided privately.

* Update EDR_telem.json: Update Process Access to "No"

* Initial commit for linux telemetry generator script.

* Refactor Linux telemetry generator script to include user account activities

* Remove unused imports from Linux telemetry generator script

* Add process hijack demo script using ptrace as suggested here: https://github.com/tsale/EDR-Telemetry/issues/21#issuecomment-2450048423

* Update raw_access_read function to read from /dev/sda in read-only mode and improve error handling

* Fix function name typo in process_hijack_demo.py and refactor network socket management in lnx_telem_gen.py

* Rename process_access to start_hijacking and update references; add network_connect method to NetworkSocketManager

* Remove commented-out main function and unused RemoteLibraryInjector class from lnx_telem_gen.py

* Refactor error handling in driver_load.py, scheduled_task.py, and process_tampering.py; add success messages and improve exception raising. Added README file.

* Add eBPF execution functionality via pamspy

* Update LINUX_TELEMETRY_GENERATOR_GUIDE.md

* Remove requirements.txt and correct apt installations for Debian in LINUX_TELEMETRY_GENERATOR_GUIDE.md

* Enhance Linux Telemetry Generator: Add PrettyTable dependency, improve process filtering, and implement execution summary logging

* Restore ProcessAccess event handling and reduce delay between events in lnx_telem_gen.py

* Add EDR telemetry configuration for process, file, user, network, and service activities

* Linux telem update

* Add Linux support to EDR telemetry scoring and enhance command line interface

* Refactor SentinelOne field in EDR telemetry configuration to remove redundancy

* No code changes made.

---------

Co-authored-by: Josh Lemon - Uptycs <116134008+joshlemon-uptycs@users.noreply.github.com>
Co-authored-by: SecurityAura <SecurityAura@users.noreply.github.com>
Co-authored-by: Ján Trenčanský <j91321@users.noreply.github.com>
Co-authored-by: mthcht <mthcht@users.noreply.github.com>"
2024-12-16 22:17:28 -08:00

1.3 KiB

Telemetry Generator

The telemetry generation tool is an early version (v0.1) software designed to help generate and test telemetry data. It utilizes the Invoke-AtomicRedTeam framework to map sub-categories to their corresponding atomic red team tests in order to generate the telemetry. This mapping information is stored in the config.json file, which the tool reads and executes the techniques accordingly.

Users have the flexibility to execute either one technique or all of the techniques by passing the -Name parameter (default=All). This makes it easy to generate telemetry and test it against the comparison table of the project, ensuring alignment and accuracy.

However, it is important to note that some sub-categories cannot be tested using this tool, such as USB Mount/Unmount and everything from the EDR-SysOps category. Despite these limitations, the telemetry generation tool serves as a valuable resource for generating and testing telemetry data in accordance with the Invoke-AtomicRedTeam framework.

Feature Proofing

As the project expands and evolves, the telemetry generation tool will continue to improve and incorporate new features and capabilities. This ongoing development will ensure that the tool remains relevant and effective in generating and testing telemetry data in line with the Invoke-AtomicRedTeam framework and the project's goals.