I have a couple of feature reqs for the Binlib
extension:
- If the file is a PE file and has an OriginalFileName value (the value collected by sysmon) have it displayed.
- The
telfhash
for ELF binaries - GitHub - trendmicro/telfhash: Symbol hash for ELF files - Validate the file size is shown in the first_seen event if it’s already been collected behind the scenes and doesn’t need to be re-fetched/acquired or add it to the first_seen event
- An API call to check how many binaries your organization has in its binlib instance, and the total file size.
- Expand binlib to include files collected in the
doc_cache_get
files - Reference: Endpoint Agent Commands
Long term: It’d be cool if you clicked a file in the binlib it showed both the file hex/strings/wide strings