One-liners for triage
Short snippets I keep within reach during triage. None of them are clever. They are here because they save a search when the clock is running.
Python
Hash a file
Reads in chunks, so it works on large files without loading them into memory.
import hashlib
def hash_file(path):
hashes = {name: hashlib.new(name) for name in ("md5", "sha1", "sha256")}
with open(path, "rb") as f:
for chunk in iter(lambda: f.read(1024 * 1024), b""):
for h in hashes.values():
h.update(chunk)
return {name: h.hexdigest() for name, h in hashes.items()}
print(hash_file("sample.bin"))
Pull URLs out of a file
import re
with open("suspicious.txt", errors="ignore") as f:
urls = sorted(set(re.findall(r"https?://[^\s\"'<>]+", f.read())))
print("\n".join(urls))
Look up a hash in VirusTotal
Needs an API key. Look up hashes only: uploading a sample makes it available to other VirusTotal users, which may not be acceptable for customer data.
import os
import requests
file_hash = "<sha256>"
response = requests.get(
f"https://www.virustotal.com/api/v3/files/{file_hash}",
headers={"x-apikey": os.environ["VT_API_KEY"]},
timeout=30,
)
stats = response.json()["data"]["attributes"]["last_analysis_stats"]
print(stats)
Bash
Processes whose binary has been deleted
A running process with no file on disk is worth a look.
ls -l /proc/[0-9]*/exe 2>/dev/null | grep '(deleted)'
Listening ports and the process behind each
ss -tulnp
Top sources of failed SSH logins
The log is /var/log/auth.log on Debian and Ubuntu, /var/log/secure on RHEL-based systems.
grep "Failed password" /var/log/auth.log | grep -oE 'from [0-9a-fA-F.:]+' | sort | uniq -c | sort -nr | head
PowerShell
Established network connections with the owning process
Get-NetTCPConnection -State Established |
Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort,
@{Name = "Process"; Expression = { (Get-Process -Id $_.OwningProcess).ProcessName }}
Startup programs
Get-CimInstance -ClassName Win32_StartupCommand | Select-Object Name, Command, Location, User
Local administrators
Get-LocalGroupMember -Group "Administrators"
DNS client cache
Get-DnsClientCache | Select-Object Entry, RecordType, Data
AD users with password expiry dates
Useful for expiry notifications, and for spotting accounts that are overdue. Requires the ActiveDirectory module.
Get-ADUser -Filter 'Enabled -eq $true -and PasswordNeverExpires -eq $false' `
-Properties DisplayName, 'msDS-UserPasswordExpiryTimeComputed' |
Select-Object DisplayName, SamAccountName,
@{Name = "ExpiryDate"; Expression = { [datetime]::FromFileTime($_.'msDS-UserPasswordExpiryTimeComputed') }} |
Sort-Object ExpiryDate |
Export-Csv -Path .\password-expiry.csv -NoTypeInformation
Keep your own
A list like this is most useful when it is yours. Keep the snippets in a repository, add a line on what each one is for and when it misleads, and prune the ones you have not used in a year.