forked from p15670423/monkey
Agent: Add _ATTACK_TECHNIQUE_ to attack_technique tags
This commit is contained in:
parent
fdd0368837
commit
c3557caf1c
|
@ -16,11 +16,16 @@ logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
DEFAULT_DIRS = ["/.ssh/", "/"]
|
DEFAULT_DIRS = ["/.ssh/", "/"]
|
||||||
SSH_CREDENTIAL_COLLECTOR_TAG = "SSHCredentialsStolen"
|
SSH_CREDENTIAL_COLLECTOR_TAG = "SSHCredentialsStolen"
|
||||||
T1003_TAG = "T1003"
|
T1003_ATTACK_TECHNIQUE_TAG = "T1003"
|
||||||
T1005_TAG = "T1005"
|
T1005_ATTACK_TECHNIQUE_TAG = "T1005"
|
||||||
T1145_TAG = "T1145"
|
T1145_ATTACK_TECHNIQUE_TAG = "T1145"
|
||||||
|
|
||||||
SSH_COLLECTOR_EVENT_TAG = {SSH_CREDENTIAL_COLLECTOR_TAG, T1003_TAG, T1005_TAG, T1145_TAG}
|
SSH_COLLECTOR_EVENT_TAG = {
|
||||||
|
SSH_CREDENTIAL_COLLECTOR_TAG,
|
||||||
|
T1003_ATTACK_TECHNIQUE_TAG,
|
||||||
|
T1005_ATTACK_TECHNIQUE_TAG,
|
||||||
|
T1145_ATTACK_TECHNIQUE_TAG,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
def get_ssh_info(
|
def get_ssh_info(
|
||||||
|
|
Loading…
Reference in New Issue