Closed xychix closed 1 year ago
Incomplete. Need to doublecheck if the scripts that are running in the background on the c2server are ok with these new paths. So the cron job and the script in /usr/share/redelk/bin/copydownloads_outflankstage1.sh
Also the ruby scripts that generate the hyperlink in Kibana need to be updated to reflect the new path.
To check:
Waiting for bug fix in Stage1 regarding logging of downloaded files.
File URL in dashboard is incorrect. RedELK creates an URL for downloads/[uid]_[filename]
whereas it should be downloads/[uid]
(e.g. downloads/N6Q37TKNAZ_whisker.exe
instead of downloads/N6Q37TKNAZ
).
File URL in dashboard is incorrect. RedELK creates an URL for
downloads/[uid]_[filename]
whereas it should bedownloads/[uid]
(e.g.downloads/N6Q37TKNAZ_whisker.exe
instead ofdownloads/N6Q37TKNAZ
).
After review, this is fixed by the background running bash script that copies downloads/N6Q37TKNAZ
to downloads/N6Q37TKNAZ_whisker.exe
.
PR looks good. Merging.
This should fetch server v2 implants back into redelk main.log seems te be unused in new stage1 server.