GithubHelp home page GithubHelp logo

IOCs detection issue ? about tinycheck HOT 3 OPEN

loromire avatar loromire commented on June 21, 2024
IOCs detection issue ?

from tinycheck.

Comments (3)

Malpaga avatar Malpaga commented on June 21, 2024 1

Hi,
I am facing the same problem after analyzing 20 minutes of capture from a purposefully compromised phone.
An SQLite database is included with TinyCheck, you can find it in the parent directory for the app (/usr/share/TinyCheck/tinycheck.sqlite3). Apparently it already has around 4,2k IOC entries, mostly domain names.
After verification, the domain name of the server reached by the tested stalkerware was found in the sqlite ioc database.
Analysis still failed however and no problem was found within the tested device.

I will search a bit more and keep you informed if I find anything !

from tinycheck.

enricoDec avatar enricoDec commented on June 21, 2024 1

As @Malpaga mentioned, TinyCheck comes with a default list of IOC, which can be manually extended. In the Wiki you can see how to add new IOC.
I would recommend testing if TinyChecks analysis is working by manually starting it (described how-to in the Wiki here). In the past I had it failing and not reporting it in the frontend, but by manually starting it in the command line you can check if errors are thrown (in my case Zeek was not installed).

from tinycheck.

EvgenyAblesov avatar EvgenyAblesov commented on June 21, 2024

Hello everyone in this thread!

loromire, please provide more information about device you running on?

If you experiencing some troubles with 32-bit version on RPi4, please refer to https://forums.raspberrypi.com/viewtopic.php?t=351727

Long story short: RPi4 + 32-bit OS --> add "arm_64bit=0" line with no quotes to the end of your /boot/config.txt

from tinycheck.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.