From 3dca01d5d563e5c357c2771ede239a81fe7a6c44 Mon Sep 17 00:00:00 2001 From: Shreya Malviya Date: Wed, 17 Aug 2022 17:28:18 +0530 Subject: [PATCH] Agent: Define MIMIKATZ_EVENT_TAGS as a frozenset --- .../mimikatz_credential_collector.py | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py b/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py index 592abffd4..a39023e0e 100644 --- a/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py +++ b/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py @@ -17,11 +17,13 @@ MIMIKATZ_CREDENTIAL_COLLECTOR_TAG = "mimikatz-credentials-collector" T1003_ATTACK_TECHNIQUE_TAG = "attack-t1003" T1005_ATTACK_TECHNIQUE_TAG = "attack-t1005" -MIMIKATZ_EVENT_TAGS = { - MIMIKATZ_CREDENTIAL_COLLECTOR_TAG, - T1003_ATTACK_TECHNIQUE_TAG, - T1005_ATTACK_TECHNIQUE_TAG, -} +MIMIKATZ_EVENT_TAGS = frozenset( + ( + MIMIKATZ_CREDENTIAL_COLLECTOR_TAG, + T1003_ATTACK_TECHNIQUE_TAG, + T1005_ATTACK_TECHNIQUE_TAG, + ) +) class MimikatzCredentialCollector(ICredentialCollector): @@ -74,7 +76,7 @@ class MimikatzCredentialCollector(ICredentialCollector): def _publish_credentials_stolen_event(self, collected_credentials: Sequence[Credentials]): credentials_stolen_event = CredentialsStolenEvent( - tags=frozenset(MIMIKATZ_EVENT_TAGS), + tags=MIMIKATZ_EVENT_TAGS, stolen_credentials=collected_credentials, )