diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/analysis.yaml b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/analysis.yaml new file mode 100644 index 0000000..3ae1370 --- /dev/null +++ b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/analysis.yaml @@ -0,0 +1,14 @@ +analysis: + duration_sec: 60 + timestamp: '2024-07-01T11:36:15.019084+00:00' +kunai: + args: + - --include=all + - --send-data-min-len=0 + version: kunai 0.2.4 +sample: + args: [] +system: + kernel: 5.10.0-30-cloud-amd64 + uname: 'Linux kunai-sandbox 5.10.0-30-cloud-amd64 #1 SMP Debian 5.10.218-1 (2024-06-01) + x86_64 GNU/Linux' diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/dump.pcap b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/dump.pcap new file mode 100644 index 0000000..e27ca53 Binary files /dev/null and b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/dump.pcap differ diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.jsonl.gz b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.jsonl.gz new file mode 100644 index 0000000..a984239 Binary files /dev/null and b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.jsonl.gz differ diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.stderr b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.stderr new file mode 100644 index 0000000..d61efcd --- /dev/null +++ b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/kunai.stderr @@ -0,0 +1,2 @@ +[2024-06-17T10:05:51Z WARN kunai] syscalls_sys_exit_execve probe is not compatible with current kernel: min=KernelVersion::MIN max=5.9.0 current=5.10.0 +[2024-06-17T10:05:52Z WARN kunai] syscalls_sys_exit_execveat probe is not compatible with current kernel: min=KernelVersion::MIN max=5.9.0 current=5.10.0 diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.stderr b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.stderr new file mode 100644 index 0000000..e69de29 diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.stdout b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.stdout new file mode 100644 index 0000000..e69de29 diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.svg b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.svg new file mode 100644 index 0000000..7d463ab --- /dev/null +++ b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/analysis/sample.svg @@ -0,0 +1,131 @@ + + + + + + +%3 + + + +guuid=8af8dc2d-0b00-0000-2952-45d858040000 pid=1112 + +/usr/bin/sudo + + + +guuid=94f0922e-0b00-0000-2952-45d859040000 pid=1113 + +/tmp/sample.bin + + + +guuid=8af8dc2d-0b00-0000-2952-45d858040000 pid=1112->guuid=94f0922e-0b00-0000-2952-45d859040000 pid=1113 + + +execve + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114 + +/usr/bin/dash + + + +guuid=94f0922e-0b00-0000-2952-45d859040000 pid=1113->guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114 + + +execve + + + +guuid=a5f4b62e-0b00-0000-2952-45d85b040000 pid=1115 + +/usr/bin/rm + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114->guuid=a5f4b62e-0b00-0000-2952-45d85b040000 pid=1115 + + +execve + + + +guuid=a7a2c72e-0b00-0000-2952-45d85c040000 pid=1116 + +/usr/bin/cp + +write-file + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114->guuid=a7a2c72e-0b00-0000-2952-45d85c040000 pid=1116 + + +execve + + + +guuid=0c9a2d2f-0b00-0000-2952-45d85d040000 pid=1117 + +/usr/bin/chmod + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114->guuid=0c9a2d2f-0b00-0000-2952-45d85d040000 pid=1117 + + +execve + + + +guuid=7b5b402f-0b00-0000-2952-45d85e040000 pid=1118 + +/dev/shm/kdmtmpflush + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114->guuid=7b5b402f-0b00-0000-2952-45d85e040000 pid=1118 + + +execve + + + +guuid=9204502f-0b00-0000-2952-45d860040000 pid=1120 + +/usr/bin/rm + +delete-file + + + +guuid=d01fa62e-0b00-0000-2952-45d85a040000 pid=1114->guuid=9204502f-0b00-0000-2952-45d860040000 pid=1120 + + +execve + + + +guuid=08274e2f-0b00-0000-2952-45d85f040000 pid=1119 + +/dev/shm/kdmtmpflush + +bpf-socket-filter + +zombie + + + +guuid=7b5b402f-0b00-0000-2952-45d85e040000 pid=1118->guuid=08274e2f-0b00-0000-2952-45d85f040000 pid=1119 + + +clone + + + diff --git a/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73 b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73 new file mode 100644 index 0000000..e3c4df2 Binary files /dev/null and b/linux/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73/fa0defdabd9fd43fe2ef1ec33574ea1af1290bd3d763fdb2bed443f2bd996d73 differ