mirror of
https://github.com/evilsocket/opensnitch.git
synced 2026-06-08 20:27:34 +00:00
Preliminary version of a task for scanning IOCs in background
(Indicator Of Compromise).
It can execute scripts and commands in background periodically.
- Added a new task scheduler to configure when the task is launched.
Previously we only had an "Interval" field to run the task
periodically. Now it's possible to select the day of the week, specify
multiple times, hours or minutes.
"schedule": [
{
"weekday": [5,6],
"time": ["09:55:00", "20:15:20"],
},
{
"weekday": [0,1,2,3,4],
"time": ["15:00:00"],
}
],
Used only in this task for now.
- This task supports 4 "tools": yara, scripts and debsums/dpkg.
* The "yara" tool acts as a frontend to the yara cli tool, used to scan
for IOCs with YARA rules.
* The "debsums"/"dpkg" tools can be used to:
- report changes in the MD5 checksums of installed Debian
packages (debsums -c).
- report changes in configuration files of installed Debian
packages (debsums -ce).
- verify the integrity of Debian packages (dpkg --verify, dpkg
--verify <package1> <packag2>).
The output of the format (rpm) is not parsed yet.
Configuration example of the task to report the output of the command
debsums:
{
"name": "IOC-scanner",
"data": {
"interval": "15s",
"schedule": [
{
"weekday": [0,1,2,3,4,5,6],
"time": ["22:00:00"]
}
],
"tools": [
{
"name": "debsums",
"msgStart": "IOC scanner debsums started",
"msgEnd": "IOC scanner debsums finished",
"enabled": false,
"cmd": ["debsums", "-c"],
"options": {
"dirs": [],
"files": [],
"reports": {
"path": "/etc/opensnitchd/tasks/iocscanner/reports",
"format": ""
}
}
}
]
}
The field "name" defines which tool to use. It's also used to parse and
format the output of the specified command.
The output of the command is sent to the GUI as an alert, and the
results can be reviewed under the Rules tab -> Alerts.