diff --git a/yaml/awerayawesun.yaml b/yaml/awerayawesun.yaml deleted file mode 100644 index b9c1d6d..0000000 --- a/yaml/awerayawesun.yaml +++ /dev/null @@ -1,38 +0,0 @@ -Name: AweRay (AweSun) -Description: AweRay (AweSun) is a remote monitoring and management (RMM) tool. More - information will be added as it becomes available. -Author: '' -Created: '' -LastModified: '' -Details: - Website: '' - PEMetadata: - Filename: '' - OriginalFileName: '' - Description: '' - Privileges: '' - Free: '' - Verification: '' - SupportedOS: [] - Capabilities: [] - Vulnerabilities: [] - InstallationPaths: - - aweray_remote*.exe - - AweSun.exe -Artifacts: - Disk: [] - EventLog: [] - Registry: [] - Network: - - Description: Known remote domains - Domains: - - asapi-us.aweray.net - - asapi.aweray.net - Ports: [] -Detections: -- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/aweray__awesun__network_sigma.yml - Description: Detects potential network activity of AweRay (AweSun) RMM tool -- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/aweray__awesun__processes_sigma.yml - Description: Detects potential processes activity of AweRay (AweSun) RMM tool -References: [] -Acknowledgement: [] diff --git a/yaml/ocamlfuse.yaml b/yaml/ocamlfuse.yaml deleted file mode 100644 index 8f34f50..0000000 --- a/yaml/ocamlfuse.yaml +++ /dev/null @@ -1,27 +0,0 @@ -Name: Ocamlfuse -Description: Ocamlfuse is a remote monitoring and management (RMM) tool. More information - will be added as it becomes available. -Author: '' -Created: '' -LastModified: '' -Details: - Website: '' - PEMetadata: - Filename: '' - OriginalFileName: '' - Description: '' - Privileges: '' - Free: '' - Verification: '' - SupportedOS: [] - Capabilities: [] - Vulnerabilities: [] - InstallationPaths: [] -Artifacts: - Disk: [] - EventLog: [] - Registry: [] - Network: [] -Detections: [] -References: [] -Acknowledgement: [] diff --git a/yaml/royal_server.yaml b/yaml/royal_server.yaml index 7999560..5904c98 100644 --- a/yaml/royal_server.yaml +++ b/yaml/royal_server.yaml @@ -29,5 +29,6 @@ Artifacts: Detections: - Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/royal_server_network_sigma.yml Description: Detects potential network activity of Royal Server RMM tool -References: [] +References: +- https://royalapps.com/server/main/features Acknowledgement: [] diff --git a/yaml/x2go.yaml b/yaml/x2go.yaml index 79c86e7..d551a6a 100644 --- a/yaml/x2go.yaml +++ b/yaml/x2go.yaml @@ -23,5 +23,6 @@ Artifacts: Registry: [] Network: [] Detections: [] -References: [] +References: +- https://wiki.x2go.org/doku.php Acknowledgement: []