-
Notifications
You must be signed in to change notification settings - Fork 61
Open
Labels
dynamic analysisIssues specific to the implementation of Dynamic AnalysisIssues specific to the implementation of Dynamic AnalysisenhancementNew feature or requestNew feature or request
Description
Suggesting adding baits to lure attackers into interacting such as
- ssh keys
- environment variables with interesting tokens
- browser database files
- discord
- aws credentials and config
- .npmrc
In addition to monitoring the interaction with such files, with the visibility #585 can give, observing such sensitive content being exfiltrated to a C2 server, we can add a label in the report such as "EXFILTRATING_SENSITIVE_INFORMATION"
maxfisher-g, aitrusnc, coffeehb and dukecat0
Metadata
Metadata
Assignees
Labels
dynamic analysisIssues specific to the implementation of Dynamic AnalysisIssues specific to the implementation of Dynamic AnalysisenhancementNew feature or requestNew feature or request