Inclusive language update

This commit is contained in:
Eric Conrad
2021-10-28 11:53:59 -04:00
parent 45c21e3821
commit 46bb325e0d
2 changed files with 7 additions and 6 deletions

View File

@ -1,12 +1,12 @@
# DeepWhite
Detective whitelisting using Sysmon event logs.
Detective safelisting using Sysmon event logs.
Parses the Sysmon event logs, grabbing the SHA256 hashes from process creation (event 1), driver load (event 6, sys), and image load (event 7, DLL) events.
## VirusTotal and Whitelisting setup
## VirusTotal and Safelisting setup
Setting up VirusTotal hash submissions and whitelisting:
Setting up VirusTotal hash submissions and safelisting:
The hash checker requires Post-VirusTotal:
@ -59,11 +59,11 @@ You can go *much* further than this with Sysmon. The Sysinternals Sysmon page ha
Also see @swiftonsecurity's awesome Sysmon config here: https://github.com/SwiftOnSecurity/sysmon-config
## Generating a Whitelist
## Generating a Safelist
Generate a custom whitelist on Windows (note: this is optional):
Generate a custom safelist on Windows (note: this is optional):
```
PS C:\> Get-ChildItem c:\windows\system32 -Include '*.exe','*.dll','*.sys','*.com' -Recurse | Get-FileHash| Export-Csv -Path whitelist.csv
PS C:\> Get-ChildItem c:\windows\system32 -Include '*.exe','*.dll','*.sys','*.com' -Recurse | Get-FileHash| Export-Csv -Path safelist.csv
```
Note: this will generate (harmless) 'PermissionDenied' warnings for locked files, etc. They may be ignored.

1
safelists/readme.md Normal file
View File

@ -0,0 +1 @@
Placeholder for safelists directory