Changeset 1622
- Timestamp:
- 06/12/08 17:37:32 (6 months ago)
- Files:
-
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/FileMonitor.exl (modified) (1 diff)
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/ProcessMonitor.exl (modified) (1 diff)
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/RegistryMonitor.exl (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/FileMonitor.exl
r1612 r1622 406 406 + Write C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ 407 407 + Delete C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ 408 409 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 410 #MS Word 2003 sp0 411 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\.+ 412 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\.+ 413 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\.+ 414 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\.+ 415 416 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 417 #Assumes all files will be launched from the Desktop...if they are stored elsewhere, then we need to whitelist that... 418 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\Administrator\\Desktop\\.+ 419 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE C:\\Documents and Settings\\Administrator\\Desktop\\.+ 420 421 422 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 423 #MS PowerPoint 2003 sp0 424 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.MSO\\.+ 425 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.MSO\\.+ 426 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Desktop\\.+ 427 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Desktop\\.+ 428 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\Office\\.+ 429 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\Office\\.+ 430 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\PowerPoint\\.+ 431 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\PowerPoint\\.+ 432 433 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 434 #MS Excel 2003 sp0 435 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\Office\\.+ 436 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Application Data\\Microsoft\\Office\\.+ 437 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.MSO\\.+ 438 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.MSO\\.+ 439 + Write C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 440 + Delete C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 441 honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/ProcessMonitor.exl
r1612 r1622 66 66 #Seems to be valid for WinZip 8.0-11.1 67 67 + WINZIP32.EXE .* C:\\Program Files\\WinZip\\WINZIP32.EXE 68 69 70 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 71 #MS Office 2003 sp0 72 + WINWORD.EXE .* C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE 73 + POWERPNT.EXE .* C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE 74 + EXCEL.EXE .* C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/RegistryMonitor.exl
r1612 r1622 501 501 + DeleteValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Nico Mak Computing\\Common\\.+ 502 502 + SetValueKey C:\\WINDOWS\\explorer\.exe HKLM\\SOFTWARE\\Classes\\Applications\\winzip32\.exe\\.+ 503 504 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 505 #MS Word 2003 sp0 506 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 507 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 508 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 509 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 510 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 511 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\.+ 512 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 513 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Shared Tools\\.+ 514 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Shared Tools\\.+ 515 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD\.EXE HKCU\\Software\\Microsoft\\Shared 516 517 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 518 #MS PowerPoint 2003 sp0 519 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 520 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 521 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 522 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 523 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\.+ 524 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\.+ 525 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 526 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT\.EXE HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 527 + SetValueKey C:\\WINDOWS\\explorer\.exe HKLM\\SOFTWARE\\Classes\\Applications\\POWERPNT\.EXE\\.+ 528 + DeleteValueKey C:\\WINDOWS\\explorer\.exe HKLM\\SOFTWARE\\Classes\\Applications\\POWERPNT\.EXE\\.+ 529 530 531 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 532 #MS Excel 2003 sp0 533 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 534 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Office\\11\.0\\.+ 535 + DeleteValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 536 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Office\\Common\\.+ 537 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 538 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 539 + SetValueKey C:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\.+
