Fenrir Simple Bash IOC Scanner Logo

Fenrir Simple Bash IOC Scanner

0
Free
Updated 11 March 2025
Visit Website

Fenrir is a simple IOC scanner bash script. It allows scanning Linux/Unix/OSX systems for the following Indicators of Compromise (IOCs): Hashes MD5, SHA1 and SHA256 (using md5sum, sha1sum, sha -a 256) File Names string - checked for substring of the full path, e.g. "temp/p.exe" in "/var/temp/p.exe" Strings grep in files C2 Server checking for C2 server strings in 'lsof -i' and 'lsof -i -n' output Hot Time Frame using stat in different modes - define min and max epoch time stamp and get all files that have been created in between Basic characteristics: Bash Script No installation or agent needed Uses common tools to extract attributes (e.g. md5sum, grep, stat in different modes) Intended to run on any Linux / Unix / OS X with Bash Low footprint - Ansible playbook with RAM drive solution Smart exclusions (file size, extension, certain directories) speeds up the scan process Why Fenrir? FENRIR is the 3rd tool after THOR and LOKI. THOR is our full featured APT Scanner with many modules and export types for corporate customers. LOKI is a free and open IOC scanner that uses YARA as signature format. The problem with both predecessors is that both have certain limitations.

FEATURES

SIMILAR TOOLS

NFStream is a multiplatform Python framework for network flow data analysis with a focus on speed and flexibility.

A tool for enumerating subdomains of a given domain

Akamai Guardicore Segmentation is a microsegmentation tool that provides network visibility, policy creation, and enforcement to prevent lateral movement and protect critical assets in diverse IT environments.

A fast domain resolver and subdomain bruteforcing tool

A multiplatform C++ library for capturing, parsing, and crafting network packets with support for various network protocols.

TCPFLOW is a tool for capturing data transmitted over TCP connections.

A foundational guide for using deception against computer network adversaries using honeypots to detect adversaries before they accomplish their goals.

A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved