read_syslog |
T1070.002 — Clear Linux or Mac System Logs |
Reads log entries to detect evidence of log tampering or gaps |
|
T1078 — Valid Accounts |
Identifies authentication events indicating credential reuse |
|
T1110 — Brute Force |
Detects patterns of failed login attempts |
scan_network |
T1049 — System Network Connections Discovery |
Lists active listening sockets and connections |
|
T1071 — Application Layer Protocol |
Identifies unexpected outbound connections on standard ports |
|
T1572 — Protocol Tunneling |
Detects unusual port usage that may indicate tunneling |
hash_binary |
T1036 — Masquerading |
Verifies file integrity to detect replaced or trojanized binaries |
|
T1027 — Obfuscated Files or Information |
Produces SHA-256 hashes for threat intelligence correlation |
check_privilege_escalation_vectors |
T1548 — Abuse Elevation Control Mechanism |
Checks for SUID/SGID binaries, sudo misconfigurations |
|
T1574.009 — Path Interception by Unquoted Service Path |
Detects unquoted Windows service paths |
|
T1068 — Exploitation for Privilege Escalation |
Identifies writable service binaries and weak permissions |
inspect_persistence_locations |
T1053 — Scheduled Task/Job |
Inspects cron jobs, systemd timers, and Windows scheduled tasks |
|
T1547.001 — Registry Run Keys / Startup Folder |
Checks Windows Run keys and startup directories |
|
T1543 — Create or Modify System Process |
Inspects systemd services and Windows services |
|
T1546.003 — Windows Management Instrumentation Event Subscription |
Checks for WMI persistence |
audit_account_changes |
T1136 — Create Account |
Detects recently created local or domain accounts |
|
T1098 — Account Manipulation |
Identifies group membership changes, especially to privileged groups |
|
T1531 — Account Access Removal |
Detects account deletions or lockouts that may indicate anti-forensics |
correlate_process_network |
T1071 — Application Layer Protocol |
Maps processes to their network connections for C2 detection |
|
T1095 — Non-Application Layer Protocol |
Identifies processes using raw sockets or unusual protocols |
|
T1571 — Non-Standard Port |
Detects processes communicating on unexpected ports |
|
T1573 — Encrypted Channel |
Flags encrypted connections to non-standard destinations |
capture_coverage_baseline |
T1082 — System Information Discovery |
Captures full system state for comparison and anomaly detection |
|
T1057 — Process Discovery |
Lists all running processes with metadata |
|
T1007 — System Service Discovery |
Enumerates installed and running services |