Jump to content

LAN Turtle IOC's ?


operat0r_001

Recommended Posts

I wanted to ask around before I create my own for the LAN Turtle but the current OIC we have is for ANY realtek device with PID  8152. Basically looking for out of the box file paths or if anybody has a Process monitor log or created OIC's for it before. I also wanted to know if there any different revs I am missing (the one I got was in a little envelope  lily about 1-3 yers old. So I can add IOC's for them.

(regmod:enum\usb\vid_0bda&pid_8152)

Edited by operat0r_001
Link to comment
Share on other sites

UPDATE: looks like as far as USB everything else is dynamic... I used USBDeview.exe from sysinternals to sort out the bits. I plan to look at what drivers it uses with process monitor and go from there. The issue there is it may be different from win 7 to 10 or builds of windows etc...

Link to comment
Share on other sites

  • 1 month later...

w00t the old alert was triggering on ANY 8152 (realtek) Device ... these added modload triggers will minimize false positives tested with only windows 10

 

q=modload:rassstp.sys modload:rtux64w10.sys (regmod:enum\usb\vid_0bda&pid_8152)

added modload:rassstp.sys to confirmed use of LAN turtle to reduce false positives 
 

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...