Skip to content

Releases: mandiant/citrix-ioc-scanner-cve-2023-3519

v1.3

01 Sep 19:14
Compare
Choose a tag to compare
  • Fix bug that was causing checks for setuid files to silently fail
  • Add in some new indicators from 3p
  • Fix bug that caused some modules to not work on Linux

v1.2

17 Aug 20:25
Compare
Choose a tag to compare
  • Add detection for UPX packed binaries
  • Add detection for kscan utility
  • Fix false positive caused by truncated ps output due to terminal column width
  • Fix false positive where log files can show up in var/crash when the primary disk fills up
  • Amend language when files with nobody:root permissions are found to recommend manual review rather than automatically flagged the system as compromised

v1.1

16 Aug 14:41
Compare
Choose a tag to compare

Release to address scanner detecting itself in logs

v1.0

14 Aug 18:35
Compare
Choose a tag to compare
final round of FP pruning before launch