Skip to content

Commit 3a5c109

Browse files
authored
Merge pull request Pennyw0rth#371 from termanix/patch-5
2 parents 54cad53 + 5b186f4 commit 3a5c109

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

nxc/modules/enum_av.py

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -358,6 +358,27 @@ def LsarLookupNames(self, dce, policyHandle, service):
358358
{"name": "sophoslivequery_*", "processes": [""]}
359359
]
360360
},
361+
{
362+
"name": "Trellix Endpoint Detection and Response (EDR)",
363+
"services": [
364+
{"name": "McAfee Endpoint Security Platform Service", "description": "Trellix Core Service"},
365+
{"name": "mfemactl", "description": "Trellix Management Service"},
366+
{"name": "mfemms", "description": "McAfee Management Service"},
367+
{"name": "mfefire", "description": "Trellix Firewall Core Service"},
368+
{"name": "masvc", "description": "Trellix Agent Service"},
369+
{"name": "macmnsvc", "description": "Trellix Agent Common Service"},
370+
{"name": "mfetp", "description": "Trellix Endpoint Threat Prevention Service"},
371+
{"name": "mfewc", "description": "Trellix Endpoint Security Web Control Service"},
372+
{"name": "mfeaack", "description": "Trellix Anti-Malware Core Service"}
373+
],
374+
"pipes": [
375+
{"name": "TrellixEDR_Pipe_*", "processes": ["McAfeeEDR.exe"]},
376+
{"name": "mfemactl_*", "processes": ["mfemactl.exe"]},
377+
{"name": "mfefire_*", "processes": ["mfefire.exe"]},
378+
{"name": "McAfeeAgent_Pipe_*", "processes": ["McAfeeAgent.exe"]},
379+
{"name": "mfetp_*", "processes": ["mfetp.exe"]}
380+
]
381+
},
361382
{
362383
"name": "Trend Micro Endpoint Security",
363384
"services": [

0 commit comments

Comments
 (0)