Common Information
Type Value
Value
rule pentest_tool_dopwn {
	meta:
		description = "Detects dopwn"
		author = " [email protected] "
		date = "2021-06-28"
		license = "Apache License 2.0"
		hash1 = "6fae4c6c34478fb515b8510d14071fc955a13e6bfb93121220342fec866317d1"
	strings:
		$ = "grab the digitalocean secret and take over the DO account too" ascii wide nocase
		$ = "registry/clusterrolebindings" ascii wide nocase
		$ = "k8s-ca-cert" ascii wide nocase
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2021-07-13 49 Resources for Investigating Cloud and Container Penetration Testing Tools - Cado Security | Cloud Investigation