8000 GitHub - tylabs/dovehawk_smb: SMB Exploitation Detection Module
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

tylabs/dovehawk_smb

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dovehawk.io SMB Exploitation Detection Module

This module detects RPC execution, SMB uploads of executable files, and Responder.py default activity such as LLMNR or NBD exploitation. Capture attacker IP and L2 MAC address. Note that executables are only detected being pushed to a system, not pulled.

This module is intended to detect lateral movement events in corporate environments and credential theft on a local network such as a conference or hotel.

Getting Started

This module supports reporting events to a central server. It also can be used locally only and will create a new Zeek log named dhsmb.log.

If you are installing from Github, copy config.zeek.orig to config.zeek. To use in local mode, leave this config file unchanged.

Sticker 1 Sticker 2

Screencaps

DoveHawk SMB/RPC Activity Reported

Dovehawk SMB Reports

Event On Remote Dashboard

Dovehawk Event

DoveHawk dhsmb.log Local Log

Logs alerts locally.

Dovehawk SMB Log

Requirements

Zeek 3.0 or higher.

zkg zeek package manager.

curl is required for ActiveHTTP requests.

Install

From a bundle:

sudo zkg unbundle dovehawk_smb.bundle

From GitHub:

sudo zkg install https://github.com/tylabs/dovehawk_smb

Contact

Tyler McLellan @tylabs

About

SMB Exploitation Detection Module

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published
0