You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
if ('edrsensor.sys' in @matches || 'hbflt.sys' in @matches || 'bdsvm.sys' in @matches || 'gzflt.sys' in @matches || 'bddevflt.sys' in @matches || 'AVCKF.SYS' in @matches || 'Atc.sys' in @matches || 'AVC3.SYS' in @matches || 'TRUFOS.SYS' in @matches || 'BDSandBox.sys' in @matches) {
120
120
blog($bid, "BitDefender Found!");
121
121
}
122
122
123
123
## Bromium
124
-
if ('brfilter.sys' || 'BrCow_x_x_x_x.sys' || 'bemk.sys' in @matches) {
124
+
if ('brfilter.sys' in @matches || 'BrCow_x_x_x_x.sys' in @matches || 'bemk.sys' in @matches) {
125
125
blog($bid, "Bromium Found!");
126
126
}
127
127
128
128
### Carbon Black
129
-
if ('CarbonBlackK.sys' || 'carbonblackk.sys' || "Parity.sys" || "cbk7.sys" || "cbstream.sys" || "ctifile.sys" in @matches) {
129
+
if ('CarbonBlackK.sys' in @matches || 'carbonblackk.sys' in @matches || "Parity.sys" in @matches || "cbk7.sys" in @matches || "cbstream.sys" in @matches || "ctifile.sys" in @matches) {
130
130
blog($bid, "Carbon Black Found!");
131
131
}
132
132
133
133
### Check Point Software Technologies
134
-
if ('epregflt.sys' || 'medlpflt.sys' || 'dsfa.sys' || 'cposfw.sys' || 'epklib.sys' in @matches) {
134
+
if ('epregflt.sys' in @matches || 'medlpflt.sys' in @matches || 'dsfa.sys' in @matches || 'cposfw.sys' in @matches || 'epklib.sys' in @matches) {
135
135
blog($bid, "Check Point Software Technologies Found!");
136
136
}
137
137
138
138
### Cisco AMP
139
-
if ('CiscoAMPCEFWDriver.sys' || 'CiscoAMPHeurDriver.sys' in @matches) {
139
+
if ('CiscoAMPCEFWDriver.sys' in @matches || 'CiscoAMPHeurDriver.sys' in @matches) {
140
140
blog($bid, "Cisco AMP Found!")
141
141
}
142
142
143
143
### Cisco Secure Endpoint
144
-
if ('csacentr.sys' || 'csaenh.sys' || 'csareg.sys' || 'csascr.sys' || 'csaav.sys' || 'csaam.sys' in @matches) {
144
+
if ('csacentr.sys' in @matches || 'csaenh.sys' in @matches || 'csareg.sys' in @matches || 'csascr.sys' in @matches || 'csaav.sys' in @matches || 'csaam.sys' in @matches) {
145
145
blog($bid, "Cisco Found!");
146
146
}
147
147
@@ -151,17 +151,17 @@ sub list {
151
151
}
152
152
153
153
### Comodo Security Solutions
154
-
if ('cfrmd.sys' || 'cmdccav.sys' || 'cmdguard.sys' || 'CmdMnEfs.sys' || 'MyDLPMF.sys' in @matches) {
154
+
if ('cfrmd.sys' in @matches || 'cmdccav.sys' in @matches || 'cmdguard.sys' in @matches || 'CmdMnEfs.sys' in @matches || 'MyDLPMF.sys' in @matches) {
155
155
blog($bid, "Comodo Security Solutions Found!");
156
156
}
157
157
158
158
### CrowdStrike
159
-
if ('im.sys' || 'CSAgent.sys' || 'CSBoot.sys' || 'CSDeviceControl.sys' || 'cspcm2.sys' in @matches) {
159
+
if ('im.sys' in @matches || 'CSAgent.sys' in @matches || 'CSBoot.sys' in @matches || 'CSDeviceControl.sys' in @matches || 'cspcm2.sys' in @matches) {
160
160
blog($bid, "CrowdStrike Found!");
161
161
}
162
162
163
163
### CyberArk
164
-
if ('CybKernelTracker.sys' || 'vfdrv.sys' || 'vfnet.sys' || 'vfpd.sys' in @matches ) {
164
+
if ('CybKernelTracker.sys' in @matches || 'vfdrv.sys' in @matches || 'vfnet.sys' in @matches || 'vfpd.sys' in @matches ) {
165
165
blog($bid, "CyberArk Software Found!");
166
166
}
167
167
@@ -171,17 +171,17 @@ sub list {
171
171
}
172
172
173
173
### Cylance Inc.
174
-
if ('CyOptics.sys' || 'CyProtectDrv32.sys' || 'CyProtectDrv64.sys' in @matches) {
174
+
if ('CyOptics.sys' in @matches || 'CyProtectDrv32.sys' in @matches || 'CyProtectDrv64.sys' in @matches) {
175
175
blog($bid, "Cylance Inc. Found!");
176
176
}
177
177
178
178
### Dell Secureworks
179
-
if ('groundling32.sys' || 'groundling64.sys' in @matches) {
179
+
if ('groundling32.sys' in @matches || 'groundling64.sys' in @matches) {
180
180
blog($bid, "Dell Secureworks Found!");
181
181
}
182
182
183
183
### Elastic Security for Endpoint
184
-
if ('ElasticEndpoint.sys' || 'ElasticEndpointDriver.sys' in @matches) {
184
+
if ('ElasticEndpoint.sys' in @matches || 'ElasticEndpointDriver.sys' in @matches) {
185
185
blog($bid, "Elastic Security for Endpoint detected!")
186
186
}
187
187
@@ -191,17 +191,17 @@ sub list {
191
191
}
192
192
193
193
### ESET
194
-
if ('edevmon.sys' || 'ehdrv.sys' || 'eamonm.sys' || 'ekbdflt.sys' in @matches) {
194
+
if ('edevmon.sys' in @matches || 'ehdrv.sys' in @matches || 'eamonm.sys' in @matches || 'ekbdflt.sys' in @matches) {
195
195
blog($bid, "ESET Found!");
196
196
}
197
197
198
198
### FireEye
199
-
if ('FeKern.sys' || 'WFP_MRT.sys' in @matches) {
199
+
if ('FeKern.sys' in @matches || 'WFP_MRT.sys' in @matches) {
200
200
blog($bid, "FireEye Found!");
201
201
}
202
202
203
203
### F-Secure
204
-
if ('xfsgk.sys' || 'fsgk.sys' || 'fsatp.sys' || 'fshs.sys' in @matches) {
204
+
if ('xfsgk.sys' in @matches || 'fsgk.sys' in @matches || 'fsatp.sys' in @matches || 'fshs.sys' in @matches) {
205
205
blog($bid, "F-Secure Found!");
206
206
}
207
207
@@ -211,7 +211,7 @@ sub list {
211
211
}
212
212
213
213
### Kaspersky
214
-
if ('klifks.sys' || 'klifaa.sys' || 'Klifsm.sys' in @matches) {
214
+
if ('klifks.sys' in @matches || 'klifaa.sys' in @matches || 'Klifsm.sys' in @matches) {
if ('mfeaskm.sys' in @matches || 'mfencfilter.sys' in @matches || 'epdrv.sys' in @matches || 'mfencoas.sys' in @matches || 'mfehidk.sys' in @matches || 'swin.sys' in @matches || 'hdlpflt.sys' in @matches || 'mfprom.sys' in @matches || 'MfeEEFF.sys' in @matches) {
230
230
blog($bid, "McAfee Found!");
231
231
}
232
232
@@ -236,12 +236,12 @@ sub list {
236
236
}
237
237
238
238
### Palo Alto
239
-
if ('telam.sys' in @matches {
239
+
if ('telam.sys' in @matches) {
240
240
blog($bid, "Palo Alto Cortex Found!");
241
-
})
241
+
}
242
242
243
243
### Panda Security
244
-
if ('PSINPROC.SYS' || 'PSINFILE.SYS' || 'amfsm.sys' || 'amm8660.sys' || 'amm6460.sys' in @matches) {
244
+
if ('PSINPROC.SYS' in @matches || 'PSINFILE.SYS' in @matches || 'amfsm.sys' in @matches || 'amm8660.sys' in @matches || 'amm6460.sys' in @matches) {
if ('SAVOnAccess.sys' in @matches || 'savonaccess.sys' in @matches || 'sld.sys' in @matches || 'SophosED.sys' in @matches || 'sntp.sys' in @matches || 'swi_callout.sys' in @matches || 'hmpalert.sys' in @matches || 'sdcfilter.sys' in @matches || 'SophosBootDriver.sys' in @matches) {
if ('pgpwdefs.sys' in @matches || 'GEProtection.sys' in @matches || 'diflt.sys' in @matches || 'sysMon.sys' in @matches || 'ssrfsf.sys' in @matches || 'emxdrv2.sys' in @matches || 'reghook.sys' in @matches || 'spbbcdrv.sys' in @matches || 'bhdrvx86.sys' in @matches || 'bhdrvx64.sys' in @matches || 'SISIPSFileFilter.sys' in @matches || 'symevent.sys' in @matches || 'vxfsrep.sys' in @matches || 'VirtFile.sys' in @matches || 'SymAFR.sys' in @matches || 'symefasi.sys' in @matches || 'symefa.sys' in @matches || 'symefa64.sys' in @matches || 'SymHsm.sys' in @matches || 'evmf.sys' in @matches || 'GEFCMP.sys' in @matches || 'VFSEnc.sys' in @matches || 'pgpfs.sys' in @matches || 'fencry.sys' in @matches || 'symrg.sys' in @matches) {
if ('TMUMS.sys' in @matches || 'hfileflt.sys' in @matches || 'TMUMH.sys' in @matches || 'AcDriver.sys' in @matches || 'SakFile.sys' in @matches || 'SakMFile.sys' in @matches || 'fileflt.sys' in @matches || 'TmEsFlt.sys' in @matches || 'tmevtmgr.sys' in @matches || 'TmFileEncDmk.sys' in @matches) {
275
275
blog($bid, "Trend Micro Inc Found!");
276
276
}
277
277
278
278
### Verdasys
279
-
if ('dgdmk.sys' || 'ndgdmk.sys' in @matches) {
279
+
if ('dgdmk.sys' in @matches || 'ndgdmk.sys' in @matches) {
0 commit comments