Skip to content

Added Metasploit rules.#1

Open
lucky-luk3 wants to merge 1 commit intomicrosoft:mainfrom
lucky-luk3:main
Open

Added Metasploit rules.#1
lucky-luk3 wants to merge 1 commit intomicrosoft:mainfrom
lucky-luk3:main

Conversation

@lucky-luk3
Copy link
Copy Markdown

  • Metasploit local exploit suggester module
  • Metasploit Hashdump module

Both are created from events observed in laboratory environment when those modules where used.

* Metasploit local exploit suggester module
* Metasploit Hashdump module
@ghost
Copy link
Copy Markdown

ghost commented Oct 18, 2021

CLA assistant check
All CLA requirements met.

@Cyb3rWard0g
Copy link
Copy Markdown
Contributor

Hello @lucky-luk3 !

Thank you for sharing your rules! A few comments:

What do you think?

@lucky-luk3
Copy link
Copy Markdown
Author

Thanks @Cyb3rWard0g for you suggestions! :)
I did the setup like this because I believed it was the best way to reduce false positives and detect the execution of metasploit.
The commands are not very specific and I thought that this way it would be better, but I agree with your suggestions :)
I will change it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants