Agent: Add _ATTACK_TECHNIQUE_ to attack_technique tags

This commit is contained in:
Ilija Lazoroski 2022-08-16 14:11:16 +02:00
parent fdd0368837
commit c3557caf1c
1 changed files with 9 additions and 4 deletions

View File

@ -16,11 +16,16 @@ logger = logging.getLogger(__name__)
DEFAULT_DIRS = ["/.ssh/", "/"]
SSH_CREDENTIAL_COLLECTOR_TAG = "SSHCredentialsStolen"
T1003_TAG = "T1003"
T1005_TAG = "T1005"
T1145_TAG = "T1145"
T1003_ATTACK_TECHNIQUE_TAG = "T1003"
T1005_ATTACK_TECHNIQUE_TAG = "T1005"
T1145_ATTACK_TECHNIQUE_TAG = "T1145"
SSH_COLLECTOR_EVENT_TAG = {SSH_CREDENTIAL_COLLECTOR_TAG, T1003_TAG, T1005_TAG, T1145_TAG}
SSH_COLLECTOR_EVENT_TAG = {
SSH_CREDENTIAL_COLLECTOR_TAG,
T1003_ATTACK_TECHNIQUE_TAG,
T1005_ATTACK_TECHNIQUE_TAG,
T1145_ATTACK_TECHNIQUE_TAG,
}
def get_ssh_info(