Skip to content

Commit

Permalink
Add Linux tests
Browse files Browse the repository at this point in the history
  • Loading branch information
tstromberg committed Dec 17, 2024
1 parent 92dee88 commit 31d664f
Show file tree
Hide file tree
Showing 8 changed files with 434 additions and 0 deletions.
25 changes: 25 additions & 0 deletions tests/linux/2024.sbcl.market/sbcl.clean.simple
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# linux/2024.sbcl.market/sbcl.clean: high
c2/addr/url: low
c2/tool_transfer/arch: low
crypto/rc4: low
data/compression/zstd: low
discover/user/HOME: low
discover/user/USER: low
evasion/file/location/var_tmp: medium
evasion/rootkit/userspace: high
exec/dylib/address_check: low
exec/dylib/symbol_address: medium
exec/program: medium
exec/program/background: low
exec/shell/echo: medium
fs/file/delete: low
fs/file/truncate: low
fs/link_read: low
fs/path/dev: medium
fs/path/tmp: medium
fs/path/var: low
fs/permission/modify: low
fs/proc/self_exe: medium
fs/symlink_resolve: low
fs/tempdir/TEMP: low
net/url/embedded: low
28 changes: 28 additions & 0 deletions tests/linux/clean/eza.simple
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# linux/clean/eza: medium
anti-static/elf/multiple: medium
c2/addr/url: low
c2/tool_transfer/arch: low
c2/tool_transfer/os: medium
credential/server/htpasswd: medium
credential/shell/bash_history: medium
credential/ssh/authorized_hosts: medium
crypto/ed25519: low
crypto/rc4: low
data/encoding/base64: low
discover/user/HOME: low
evasion/file/prefix: medium
exec/dylib/iterate: low
exec/dylib/symbol_address: medium
fs/link_read: low
fs/mount: low
fs/path/etc: low
fs/path/home_config: low
fs/proc/self_cgroup: medium
fs/proc/self_exe: medium
fs/proc/self_mountinfo: medium
fs/symlink_resolve: low
fs/tempdir/TEMP: low
net/url/embedded: low
persist/shell/bash: medium
persist/shell/zsh: medium
process/multithreaded: low
126 changes: 126 additions & 0 deletions tests/linux/clean/kolide/launcher.simple
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
# linux/clean/kolide/launcher: medium
c2/addr/http_dynamic: medium
c2/addr/ip: medium
c2/addr/url: low
c2/tool_transfer/arch: low
c2/tool_transfer/os: medium
collect/archives/zip: medium
collect/databases/mysql: medium
collect/databases/postgresql: medium
collect/databases/sqlite: medium
credential/keychain: medium
credential/password: low
credential/ssl/private_key: low
crypto/aes: low
crypto/cipher: medium
crypto/decrypt: low
crypto/ecdsa: low
crypto/ed25519: low
crypto/public_key: low
crypto/tls: low
data/compression/gzip: low
data/compression/zlib: low
data/embedded/base64_terms: medium
data/embedded/base64_url: medium
data/embedded/html: medium
data/embedded/pem_certificate: low
data/encoding/base64: low
data/encoding/json: low
data/encoding/json_decode: low
data/hash/blake2b: low
data/hash/md5: low
discover/network/netstat: medium
discover/processes/list: medium
discover/system/cpu: low
discover/system/hostname: low
discover/system/platform: medium
discover/user/USER: low
evasion/file/prefix: medium
evasion/logging/acct: low
exec/cmd: medium
exec/plugin: low
exec/program: medium
exec/shell/TERM: low
exec/shell/command: medium
exec/system_controls/systemd: medium
exfil/upload: medium
fs/directory/create: low
fs/directory/list: low
fs/directory/remove: low
fs/file/create: medium
fs/file/delete: low
fs/file/open: low
fs/file/read: low
fs/file/rename: low
fs/file/stat: low
fs/file/truncate: low
fs/file/write: low
fs/link_read: low
fs/lock_update: low
fs/mount: low
fs/path/boot: medium
fs/path/etc: low
fs/path/etc_hosts: medium
fs/path/etc_resolv.conf: low
fs/path/home_config: low
fs/path/tmp: medium
fs/path/usr_bin: low
fs/path/usr_local: medium
fs/path/usr_sbin: low
fs/path/var: low
fs/path/var_log: medium
fs/permission/chown: medium
fs/permission/modify: medium
fs/proc/self_mountinfo: medium
fs/tempdir: low
fs/tempdir/TEMP: low
fs/tempdir/TMPDIR: low
fs/tempdir/create: low
fs/tempfile: low
hw/dev/block_ice: medium
impact/remote_access/net_term: medium
net/dns: low
net/dns/reverse: medium
net/dns/servers: low
net/dns/txt: low
net/download: medium
net/http/2: low
net/http/accept: medium
net/http/accept_encoding: low
net/http/auth: low
net/http/content_length: medium
net/http/cookies: medium
net/http/form_upload: medium
net/http/post: medium
net/http/proxy: low
net/http/request: low
net/ip/host_port: medium
net/ip/icmp: medium
net/ip/parse: medium
net/ip/tcp_state_tracker: medium
net/resolve/hostname: low
net/resolve/hostport_parse: low
net/socket/listen: medium
net/socket/local_addr: low
net/socket/peer_address: low
net/socket/receive: low
net/socket/send: low
net/tcp/connect: medium
net/tcp/grpc: low
net/tcp/sftp: medium
net/tcp/ssh: medium
net/udp/receive: low
net/udp/send: low
net/url/embedded: low
net/url/encode: medium
net/url/parse: low
net/url/request: medium
os/fd/sendfile: low
os/kernel/key_management: low
os/kernel/netlink: low
persist/pid_file: medium
privesc/setuid: low
privesc/sudo: medium
process/groupid_set: low
process/groups_set: low
process/multithreaded: low
212 changes: 212 additions & 0 deletions tests/linux/clean/kolide/osqueryd.simple
Original file line number Diff line number Diff line change
@@ -0,0 +1,212 @@
# linux/clean/kolide/osqueryd: medium
anti-static/elf/multiple: medium
anti-static/obfuscation/obfuscate: low
c2/addr/http_dynamic: medium
c2/addr/ip: medium
c2/addr/url: low
c2/client: medium
c2/tool_transfer/arch: low
c2/tool_transfer/os: medium
collect/databases/leveldb: medium
collect/databases/sqlite: medium
credential/cloud/aws: medium
credential/keychain: medium
credential/password: low
credential/shell/bash_history: medium
credential/shell/zsh_history: medium
credential/sniffer/bpf: medium
credential/ssh/authorized_hosts: medium
credential/ssl/private_key: low
crypto/aes: low
crypto/cipher: medium
crypto/decrypt: low
crypto/ed25519: low
crypto/gost89: low
crypto/openssl: medium
crypto/public_key: low
crypto/tls: low
data/base64/decode: medium
data/compression/bzip2: low
data/compression/gzip: low
data/compression/lzma: low
data/compression/zlib: low
data/compression/zstd: low
data/embedded/pem_private_key: medium
data/encoding/base64: low
data/hash/blake2b: low
data/hash/md5: low
data/hash/sha1: low
data/hash/sha256: low
data/hash/whirlpool: medium
data/random/insecure: low
discover/cloud/google_metadata: low
discover/components/docker: medium
discover/group/lookup: medium
discover/network/interface: low
discover/network/interface_list: medium
discover/network/mac_address: medium
discover/process/name: medium
discover/process/parent: low
discover/process/runtime_deps: medium
discover/system/cpu: low
discover/system/hostname: low
discover/system/machine_id: low
discover/system/platform: low
discover/system/sysinfo: medium
discover/user/HOME: low
discover/user/USER: low
discover/user/name_get: low
evasion/bypass_security/linux/iptables: medium
evasion/file/location/var_run: medium
evasion/file/prefix: medium
evasion/hide_artifacts/pivot_root: medium
evasion/logging/acct: low
evasion/logging/current_logins: medium
evasion/logging/dev_log: medium
evasion/process_injection/ptrace: medium
evasion/process_injection/readelf: medium
exec/conditional/LANG: low
exec/dylib/address_check: low
exec/dylib/iterate: low
exec/dylib/symbol_address: medium
exec/plugin: low
exec/program: medium
exec/program/background: low
exec/reconfigure/hostname_set: low
exec/shell/SHELL: low
exec/shell/TERM: low
exec/shell/arbitrary_command_dev_null: medium
exec/shell/echo: medium
exec/shell/exec: medium
exec/shell/ignore_output: medium
exec/system_controls/apparmor: medium
exec/system_controls/systemd: low
exec/tty/vhangup: low
exfil/collection: medium
fs/attributes/remove: medium
fs/attributes/set: medium
fs/blkid: low
fs/directory/create: low
fs/directory/remove: low
fs/event_monitoring: low
fs/fifo_create: low
fs/file/capabilities_set: low
fs/file/delete: medium
fs/file/delete_forcibly: low
fs/file/flags_change: low
fs/file/open: low
fs/file/open_by_handle: low
fs/file/times_set: medium
fs/file/truncate: low
fs/link_create: low
fs/link_read: low
fs/lock_update: low
fs/loopback: medium
fs/mount: low
fs/mounts_read: medium
fs/node_create: low
fs/path/boot: medium
fs/path/etc: low
fs/path/etc_hosts: medium
fs/path/from_cookie: low
fs/path/home: low
fs/path/home_config: low
fs/path/root: medium
fs/path/tmp: medium
fs/path/users: medium
fs/path/usr_bin: low
fs/path/usr_lib_python: medium
fs/path/usr_local: medium
fs/path/usr_sbin: low
fs/path/var: low
fs/path/var_log: medium
fs/path/windows_root: low
fs/permission/chown: low
fs/permission/modify: medium
fs/proc/arbitrary_pid: medium
fs/proc/cpuinfo: medium
fs/proc/meminfo: medium
fs/proc/mounts: medium
fs/proc/self_exe: medium
fs/proc/self_mountinfo: medium
fs/proc/self_status: medium
fs/proc/stat: medium
fs/quota_manipulate: low
fs/swap/off: low
fs/swap/on: low
fs/symlink_resolve: low
fs/tempdir: low
fs/tempdir/TEMP: low
fs/tempdir/TMPDIR: low
fs/tempfile: low
fs/unmount: low
fs/watch: low
hw/cpu: medium
hw/dev/block_ice: medium
hw/dev/diskmapper: medium
hw/dev/mapper: medium
impact/degrade/linux_paths: medium
impact/infection/worm: medium
impact/reboot: low
impact/remote_access/heartbeat: medium
impact/remote_access/iptables: medium
lateral/scan/tool: medium
mem/anonymous_file: medium
net/dns/txt: low
net/http/2: low
net/http/accept: low
net/http/accept_encoding: low
net/http/auth: low
net/http/cookies: medium
net/http/form_upload: medium
net/http/post: medium
net/http/proxy: low
net/http/request: low
net/http/websocket: medium
net/ip/host_port: medium
net/ip/icmp: medium
net/ip/multicast_send: low
net/ip/parse: medium
net/ip/resolve: low
net/ip/send_unicast: low
net/ip/string: medium
net/ip/syncookie: medium
net/proxy/socks5: medium
net/proxy/tunnel: medium
net/resolve/hostname: low
net/resolve/hostport_parse: low
net/rpc/ntlm: medium
net/socket/listen: medium
net/socket/local_addr: low
net/socket/pair: medium
net/socket/peer_address: low
net/socket/receive: low
net/socket/reuseport: medium
net/socket/send: low
net/tcp/ssh: medium
net/url/embedded: medium
net/url/encode: medium
os/fd/epoll: low
os/fd/read: low
os/fd/sendfile: low
os/kernel/key_management: low
os/kernel/netlink: low
os/kernel/opencl: medium
os/kernel/perfmon: low
os/kernel/seccomp: low
os/time/clock_set: low
persist/cron/tab: medium
persist/kernel_module/symbol_lookup: medium
persist/kernel_module/unload: medium
persist/pid_file: medium
persist/ssh_authorized_keys: medium
privesc/setuid: low
process/chroot: low
process/create: low
process/groupid_set: low
process/groups_set: low
process/multithreaded: low
process/name_set: medium
process/namespace_set: low
process/unshare: low
sus/intercept: medium
Loading

0 comments on commit 31d664f

Please sign in to comment.