Skip to content

Commit

Permalink
Merge branch 'master' of https://github.com/dfirtnt/KapeFiles
Browse files Browse the repository at this point in the history
  • Loading branch information
dfirtnt committed Aug 30, 2023
2 parents 205e594 + b7afdfb commit e6d1ee4
Show file tree
Hide file tree
Showing 2 changed files with 33 additions and 0 deletions.
17 changes: 17 additions & 0 deletions Action1.tkape
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
Description: Action1 Application Logs
Author: Andrew Skatoff @DFIR_TNT
Version: 1.0
Id: 9cdf145a-c67e-45cd-bdec-1bcfeb2d50b1
RecreateDirectories: true
Targets:
-
Name: Action1 Client Application logs
Category: ApplicationLogs
Path: C:\Windows\Action1\logs
FileMask: '*.log'
Comment: "Contains Application Log entries such as service start and incomming connections, and deployed scripts/jobs."


# Documentation
# https://dfirtnt.wordpress.com/2023/08/23/rmm-action1-client-side-evidence/
# https://www.bleepingcomputer.com/news/security/hackers-start-abusing-action1-rmm-in-ransomware-attacks/
16 changes: 16 additions & 0 deletions Level.tkape
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
Description: Level.io Application Logs
Author: Andrew Skatoff @DFIR_TNT
Version: 1.0
Id: 5e2c322f-616c-42e4-9cd7-4546cf2412e6
RecreateDirectories: true
Targets:
-
Name: Action1 RMM Client Application logs
Category: ApplicationLogs
Path: C:\Program Files\Level
FileMask: '*.log'
Comment: "Contains Application Log entries such as service start and incomming connections."


# Documentation
# https://www.crowdstrike.com/blog/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies/

0 comments on commit e6d1ee4

Please sign in to comment.