Changeset 1511

Show
Ignore:
Timestamp:
04/10/08 10:47:45 (1 month ago)
Author:
xkovah
Message:

Added to the file:
#XENO: I recommend commenting out all blacklist entries until this has some way to
#deal with the fact that these will always be written to the tmp file if you visit
#a link to one of these directly…If we could add whitelist entries back in AFTER
#these, pointing at the tmp file dir, signifying that we don't care as long as it
#is in that dir, but care about everything else, then this would be usable…but until
#then…not so much.
#I tested adding a + entry for the temp downloads file after the - entry. It seemed
#to work for .vb files, but not .exe files, which is what we care about much more.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • honeyclient/trunk/thirdparty/capture-mod/FileMonitor.exl

    r1510 r1511  
    5151+   Write   C:\\WINDOWS\\system32\\services\.exe    C:\\WINDOWS\\system32\\config\\SecEvent\.Evt 
    5252#Mapping 
    53 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\wbem.* 
     53+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\wbem\\.+ 
    5454#Cataloging 
    5555+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\CatRoot2\\.+ 
     
    128128################################################### 
    129129# Alert about executables or scripts that are written to disk 
     130#XENO: I recommend commenting out all blacklist entries until this has some way to 
     131#deal with the fact that these will always be written to the tmp file if you visit 
     132#a link to one of these directly...If we could add whitelist entries back in AFTER 
     133#these, pointing at the tmp file dir, signifying that we don't care as long as it 
     134#is in that dir, but care about everything else, then this would be usable...but until 
     135#then...not so much. 
     136#I tested adding a + entry for the temp downloads file after the - entry. It seemed 
     137#to work for .vb files, but not .exe files, which is what we care about much more. 
    130138#-  Write   .*  .+\.bat 
    131139#-  Write   .*  .+\.cmd 
    132140#commented out for VMwareService.exe, since it writes .inf files. 
    133141#-  Write   .*  .+\.inf 
    134 - Write   .*  .+\.lnk 
    135 - Write   .*  .+\.msi 
    136 - Write   .*  .+\.msp 
    137 - Write   .*  .+\.pif 
    138 - Write   .*  .+\.reg 
    139 - Write   .*  .+\.sct 
    140 - Write   .*  .+\.shs 
     142#-    Write   .*  .+\.lnk 
     143#-    Write   .*  .+\.msi 
     144#-    Write   .*  .+\.msp 
     145#-    Write   .*  .+\.pif 
     146#-    Write   .*  .+\.reg 
     147#-    Write   .*  .+\.sct 
     148#-    Write   .*  .+\.shs 
    141149#commented out for sites that download \.scr into the temp files folder. 
    142150#-  Write   .*  .+\.scr 
    143 - Write   .*  .+\.wsc 
    144 - Write   .*  .+\.wsf 
    145 - Write   .*  .+\.wsh 
     151#-    Write   .*  .+\.wsc 
     152#-    Write   .*  .+\.wsf 
     153#-    Write   .*  .+\.wsh 
    146154#commented out for IE because \.com cache files and \.vb script files are very common 
    147 #-    Write   .*  .+\.vb 
     155- Write   .*  .+\.vb 
    148156#-  Write   .*  .+\.com 
    149 #commented out for IE because \.exe downloads to the cache dir are very common 
    150 # TODO: This is a bug that needs to be resolved. 
     157#commented out for IE because .exe downloads to the cache dir are very common 
    151158#-  Write   .*  .+\.exe 
    152159# Alert about modifications to startup locations 
     
    261268+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\SoftwareDistribution\\DataStore\\Logs 
    262269+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32 
    263 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\config 
    264270+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\repair 
    265271+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\SoftwareDistribution 
    266 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\SoftwareDistribution\\Download 
    267 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\SoftwareDistribution\\Download.* 
    268 +   Delete  C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\SoftwareDistribution\\Download.* 
    269272+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Cookies 
    270273+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Cookies\\index.dat 
     
    273276+   Write   C:\\WINDOWS\\system32\\WgaTray\.exe C:\\Documents and Settings\\.+\\Local Settings\\History\\History.IE5.* 
    274277+   Delete  C:\\WINDOWS\\system32\\WgaTray\.exe C:\\Documents and Settings\\.+\\Local Settings\\History\\History.IE5.* 
    275 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin.* 
     278+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\.* 
    276279+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop 
    277280+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop\\%USERPROFILE%\\Local Settings\\Application Data\\Microsoft\\Feeds Cache 
     
    297300+   Delete  C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\.+\\Cookies\\index.dat 
    298301+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\WinSxS\\Policies\\.* 
    299 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\WinSxS 
    300302+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\ 
    301 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\Temp\\WGANotify\.settings 
    302 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\config 
    303 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\.+\\Application Data\\.+ 
    304 +   Delete  C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\.+\\Application Data\\.+ 
    305 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\.+\\Application Data\\Microsoft\\CryptnetUrlCache.* 
    306 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\All Users