Multi_Hacktool_LinPEAS_ng_02c12676
Description
LinPEAS detection based on the Base module
Query · yara
strings:
$base_0 = "$(printf '\\033')" base64
$base_1 = "Enumerate and search Privilege Escalation vectors." base64
$base_2 = "grep -c processor /proc/cpuinfo" base64
$base_3 = "Do you like PEASS?" base64
$base_4 = "RED/YELLOW: 95% a PE vector" base64
$base_5 = "\\(root\\)|\\(shadow\\)|\\(admin\\)|\\(video\\)|\\(adm\\)|\\(wheel\\)|\\(auth\\)" base64
$base_6 = "peass{SUIDVB1_HERE}" base64
$base_7 = "file|free|main|more|read|split|write" base64
$base_8 = "cap_sys_admin:mount|python" base64
$base_9 = "timeout 1 su $(whoami) -c whoami" base64
condition:
5 of them