Windows_Hacktool_WinPEAS_ng_861d3264
Description
WinPEAS detection based on the dotNet binary, File Info module
Query · yara
strings:
$win_0 = "ConsoleHost_history.txt" ascii wide
$win_1 = "Interesting files and registry" ascii wide
$win_2 = "Cloud Credentials" ascii wide
$win_3 = "Accessed:{2} -- Size:{3}" ascii wide
$win_4 = "Unattend Files" ascii wide
$win_5 = "Looking for common SAM" ascii wide
$win_6 = "Found installed WSL distribution" ascii wide
$win_7 = "Check skipped, if you want to run it" ascii wide
$win_8 = "Cached GPP Passwords" ascii wide
$win_9 = "[cC][rR][eE][dD][eE][nN][tT][iI][aA][lL]|[pP][aA][sS][sS][wW][oO]" ascii wide
condition:
5 of them