Skip to content

Commit 5b186f4

Browse files
authored
Update enum_av Added Trellix EDR
Signed-off-by: termanix <50464194+termanix@users.noreply.github.com>
1 parent 54cad53 commit 5b186f4

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

nxc/modules/enum_av.py

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -358,6 +358,27 @@ def LsarLookupNames(self, dce, policyHandle, service):
358358
{"name": "sophoslivequery_*", "processes": [""]}
359359
]
360360
},
361+
{
362+
"name": "Trellix Endpoint Detection and Response (EDR)",
363+
"services": [
364+
{"name": "McAfee Endpoint Security Platform Service", "description": "Trellix Core Service"},
365+
{"name": "mfemactl", "description": "Trellix Management Service"},
366+
{"name": "mfemms", "description": "McAfee Management Service"},
367+
{"name": "mfefire", "description": "Trellix Firewall Core Service"},
368+
{"name": "masvc", "description": "Trellix Agent Service"},
369+
{"name": "macmnsvc", "description": "Trellix Agent Common Service"},
370+
{"name": "mfetp", "description": "Trellix Endpoint Threat Prevention Service"},
371+
{"name": "mfewc", "description": "Trellix Endpoint Security Web Control Service"},
372+
{"name": "mfeaack", "description": "Trellix Anti-Malware Core Service"}
373+
],
374+
"pipes": [
375+
{"name": "TrellixEDR_Pipe_*", "processes": ["McAfeeEDR.exe"]},
376+
{"name": "mfemactl_*", "processes": ["mfemactl.exe"]},
377+
{"name": "mfefire_*", "processes": ["mfefire.exe"]},
378+
{"name": "McAfeeAgent_Pipe_*", "processes": ["McAfeeAgent.exe"]},
379+
{"name": "mfetp_*", "processes": ["mfetp.exe"]}
380+
]
381+
},
361382
{
362383
"name": "Trend Micro Endpoint Security",
363384
"services": [

0 commit comments

Comments
 (0)