Linux HackTool Execution
Description
Detects known hacktool execution based on image name.
Query · sigma
selection_c2_frameworks: Image|endswith: - /crackmapexec - /havoc - /merlin-agent - /merlinServer-Linux-x64 - /msfconsole - /msfvenom - /ps-empire server - /ps-empire - /sliver-client - /sliver-server - /Villain.py selection_c2_framework_cobaltstrike: Image|contains: - /cobaltstrike - /teamserver selection_scanners: Image|endswith: - /autorecon - /httpx - /legion - /naabu - /netdiscover - /nuclei - /recon-ng selection_scanners_sniper: Image|contains: /sniper selection_web_enum: Image|endswith: - /dirb - /dirbuster - /eyewitness - /feroxbuster - /ffuf - /gobuster - /wfuzz - /whatweb selection_web_vuln: Image|endswith: - /joomscan - /nikto - /wpscan selection_exploit_tools: Image|endswith: - /aircrack-ng - /bloodhound-python - /bpfdos - /ebpfki - /evil-winrm - /hashcat - /hoaxshell.py - /hydra - /john - /ncrack - /nxc-ubuntu-latest - /pidhide - /pspy32 - /pspy32s - /pspy64 - /pspy64s - /setoolkit - /sqlmap - /writeblocker selection_linpeas: Image|contains: /linpeas condition: 1 of selection_*
Known false positives
- Unlikely