Skip to content

Commit 1af2828

Browse files
authored
Merge pull request Pennyw0rth#344 from n00py/main
Add EnumAV Detection for Cortex XDR
2 parents f2311b3 + cdffba9 commit 1af2828

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

nxc/modules/enum_av.py

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -247,6 +247,14 @@ def LsarLookupNames(self, dce, policyHandle, service):
247247
"services": [{"name": "CSFalconService", "description": "CrowdStrike Falcon Sensor Service"}],
248248
"pipes": [{"name": "CrowdStrike\\{*", "processes": ["CSFalconContainer.exe", "CSFalconService.exe"]}]
249249
},
250+
{
251+
"name": "Cortex",
252+
"services": [
253+
{"name": "xdrhealth", "description": "Cortex XDR Health Helper"},
254+
{"name": "cyserver", "description": " Cortex XDR"}
255+
],
256+
"pipes": []
257+
},
250258
{
251259
"name": "Cybereason",
252260
"services": [

0 commit comments

Comments
 (0)