> For the complete documentation index, see [llms.txt](https://f1shh.gitbook.io/pentest-tips/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://f1shh.gitbook.io/pentest-tips/blue-team/threathunting.md).

# Threat Hunting

## Yara

```
# Basic Rule to match string
rule matchString {
	strings:
		$someString = "Match me!"
	condition: 
		$someString
}

# Match any of the following strings
rule matchString {
	strings:
		$someString = "Match me!"
		$someString2 = "Or match me!"
		$someString3 = "Match me too!"
	condition: 
		any of them
}
```

### Cheatsheet

![Yara Rule cheatsheet](https://3786860458-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FenUJvnPIyhLsNhMd8SVO%2Fuploads%2Fgit-blob-cb60ecb212f9c0895ec0410a118d6efc6e00f3d7%2Fyararules.png?alt=media)

**source:** <https://blog.securitybreak.io/security-infographics-9c4d3bd891ef#18dd>

## Windows

Just use sysinternals...

* <https://docs.microsoft.com/en-us/sysinternals/>

## Linux

**View Processes:**

```bash
ps -aux
```

**List running Services:**

```bash
systemctl list-units --type=service --state=running
```

**Check your logs:**\
Can be useful to check for "nc" or other attacker tools:

```bash
cat /var/log/syslog | Grep <something>
```

**Active TCP and UDP connections:**

```bash
ss -tulpn
```

### Crontab

**Check your crontab:**

```bash
crontab -l
```

**Clear your crontab:**

```bash
crontab -r
```

## Log Analysis

```bash
# Get number of occurences
wc -l

# Get number of unique occurences
uniq -c

# Sort by number of uniq occurences
cat file.txt | uniq -c | sort -n
```
