Trawler icon indicating copy to clipboard operation
Trawler copied to clipboard

Script level todos

Open baileydauterman opened this issue 5 months ago • 1 comments

  • [ ] JSON Detection Output to easily encapsulate more details
  • [ ] Non-Standard Service/Task running as/created by Local Administrator
  • [ ] Browser Extension Analysis
  • [ ] Temporary RID Hijacking
  • [ ] ntshrui.dll - https://www.mandiant.com/resources/blog/malware-persistence-windows-registry
  • [ ] Add file metadata for detected files (COM/DLL Hijacks, etc)
  • [ ] Add more suspicious paths for running processes
  • [ ] Iterate through HKEY_USERS when encountering HKEY_CURRENT_USER hive reference

baileydauterman avatar Oct 05 '24 16:10 baileydauterman