-
Notifications
You must be signed in to change notification settings - Fork 107
/
artifact.lua
4081 lines (3626 loc) · 206 KB
/
artifact.lua
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
--[[
Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
or more contributor license agreements. You may not install, use, modify,
or distribute this file unless you have a valid commercial license from
Elasticsearch B.V. or one of its affiliates. If you are interested in
obtaining Elastic's permission to use this file, please contact
elastic_license@elastic.co.
--]]
local utils = {}
-- ExtensionData creates an extension data table from the given arguments.
-- @param category int: Category of the extension.
-- @param lowEntropy boolean: True when the extension is known to have a low entropy.
-- @param magicBytes table: Represents the file magic bytes.
-- @return table: A table representing the extension data.
function utils.ExtensionData(category, lowEntropy, magicBytes)
local obj = {}
obj.category = category
obj.lowEntropy = lowEntropy
obj.magicBytes = magicBytes
return obj
end
-- Returns the hexadecimal representation of the binary data. Every byte of data
-- is converted into the corresponding 2-digit hex representation. The returned
-- bytes object is therefore twice as long as the length of data.
-- @param buff string: Represents the binary data.
-- @return string: hexlified string.
function utils.Hexlify(buff)
local t = {}
for i = 1, #buff do
table.insert(t, string.format('%02X', string.byte(string.sub(buff, i, i))))
end
return table.concat(t, '')
end
-- Split a string by a separator.
-- @param str string: The subject string.
-- @param sep string: The separator used to split the string.
-- @return table: A table representing the split string.
function utils.Split(str, sep)
local result = {}
local regex = ('([^%s]+)'):format(sep)
for each in str:gmatch(regex) do
table.insert(result, each)
end
return result
end
-- Returns a boolean representing if key exists in the provided table.
-- @param inputTable table: The subject table.
-- @param key string: The key to check for.
-- @return boolean: True if the key exists in the table.
function utils.TableHasKey(inputTable, key)
return inputTable[key] ~= nil
end
-- Returns a boolean representing if value exists in the provided table.
-- @param inputTable table: The subject table.
-- @param value string: The value to check for.
-- @return boolean: True if the value exists in the table.
function utils.TableHasValue(inputTable, value)
for _, v in ipairs(inputTable) do
if v == value then
return true
end
end
return false
end
-- Performs a deep copy of an object. This function supports: tables as keys,
-- recursive tables, and preserves meta-tables.
-- @param obj table: The subject table.
-- @param seen table: A table meant to be ignored by the "outside" caller and
-- only used for recursive calls. It avoids repeated deep copying of tables that
-- occur more than once in a single table.
-- @param Table table: The newly copied table.
function utils.Copy(obj, seen)
if type(obj) ~= 'table' then
return obj
end
if seen and seen[obj] then
return seen[obj]
end
local s = seen or {}
local res = setmetatable({}, getmetatable(obj))
s[obj] = res
for k, v in pairs(obj) do
res[utils.Copy(k, s)] = utils.Copy(v, s)
end
return res
end
-- Converts a byte string to an array of bytes.
-- @param str string: The subject string.
-- @return table: A table containing the resulted array of bytes.
function utils.StringToByteArray(str)
local result = {}
for i = 1, #str do
table.insert(result, string.byte(str, i));
end
return result
end
-- Removes alternate data stream (if exists) from the provided file path,
-- e.g. C:\test.txt:Zone.Identifier => C:\test.txt.
-- @param str string: The subject file path.
-- @return string: The curated string if ADS is found. Otherwise, a copy of the string.
function utils.RemoveAdsFromPath(str)
local volumeIndex = string.find(str, ':', nil, true)
-- If we confirm the second character was a colon (e.g. 'C:'), then
-- proceed with attempting to remove an ADS from the remaining path.
if volumeIndex ~= nil then
if volumeIndex == 2 then
return utils.RemoveAdsFromExtension(str, volumeIndex + 1)
end
end
return str
end
-- Removes alternate data stream (if exists) from the provided filename,
-- extension, or partial path. e.g. test.txt:Zone.Identifier => test.txt
-- @param str string: The subject file name.
-- @param startIndex integer: An index to start the search from.
-- @return string: The curated string if ADS is found. Otherwise, a copy of the string.
function utils.RemoveAdsFromExtension(str, startIndex)
startIndex = startIndex or 1
local adsIndex = string.find(str, ':', startIndex, true)
if adsIndex ~= nil then
return string.sub(str, startIndex, adsIndex - 1)
end
return str
end
-- NormalizePath attempts to find the parent of a directory but in terms of
-- responsibility. This is useful when we want to know processes that
-- attempt to modify directories outside of their scope. i.g:
-- c:\\program files\\google\\sdk\\list.py ==> c:\\program files\\google\\
-- Any process which modifies files outside its scope it considered suspicious.
-- @param str string: The subject file path.
-- @return string: The normalized file path in success, or nil otherwise.
function utils.NormalizePath(filePath)
-- Lower case the file path for easy pattern matching.
filePath = filePath:lower()
-- "Program Files" and "Program Files (x86) can use the shorter version,
-- that is "progra~1" and "progra~2" correspondingly.
filePath = filePath:gsub('progra~1', 'program files')
filePath = filePath:gsub('progra~2', 'program files (x86)')
-- If the file path does not start with a drive letter, abort.
local match = filePath:match('^%a:\\')
if match == nil then
return nil
end
local match = filePath:match('^%a:\\programdata\\.-\\')
if match ~= nil then
return match
end
match = filePath:match('^%a:\\program files\\.-\\')
if match ~= nil then
return match
end
match = filePath:match('^%a:\\program files %(x86%)\\.-\\')
if match ~= nil then
return match
end
match = filePath:match('^%a:\\.-\\')
if match ~= nil then
return match
end
match = filePath:match('(.*[/\\])')
if match ~= nil then
return match
end
return nil
end
-- Check if a file extension is typically used by Microsoft Office, the first
-- two characters of the filename will be checked to determine if this may be
-- an Office lock file and will not be subjected to a header magic byte check.
-- @param extension string: The subject extension name.
-- @param fileName string: The subject file name.
-- @return boolean: True when an MS Office lock file is found. False otherwise.
function utils.IsOfficeLockFile(extension, fileName)
-- A list of known Microsoft Office Extensions.
local officeExtensions = {
'doc',
'docb',
'docm',
'docx',
'dotm',
'dotx',
'dot',
'wbk',
'pot',
'potm',
'potx',
'ppam',
'pps',
'ppsm',
'ppsx',
'ppt',
'pptm',
'pptx',
'sldm',
'sldx',
'xla',
'xlam',
'xll',
'xlm',
'xls',
'xlsb',
'xlsm',
'xlsx',
'xlt',
'xltm',
'xltx',
'xlw'
}
if utils.TableHasValue(officeExtensions, extension) then
local index = string.find(fileName, '~$', nil, true)
if index ~= nil then
if index == 1 then
return true
end
end
end
return false
end
-- Prints out tables summarizing process event activity sorted by operations and
-- extensions.
-- @param processData table: A table containing process data.
-- @return void.
function utils.PrintExtensionTables(processData)
utils.DebugLog('=================')
utils.DebugLog('Create Extensions')
for k, v in pairs(processData.createExtensions) do
utils.DebugLog('*** ' .. k)
for _, v2 in pairs(v) do
utils.DebugLog(v2.operation .. ' | ' .. string.sub(v2.entropy, 1, 4) .. ' | ' .. v2.alertScore .. ' | ' ..
string.sub(v2.filePath, 1, 200))
end
end
utils.DebugLog('=================')
utils.DebugLog('Modify Extensions')
for k, v in pairs(processData.modifyExtensions) do
utils.DebugLog('*** ' .. k)
for _, v2 in pairs(v) do
utils.DebugLog(v2.operation .. ' | ' .. string.sub(v2.entropy, 1, 4) .. ' | ' .. v2.alertScore .. ' | ' ..
string.sub(v2.filePath, 1, 200))
end
end
utils.DebugLog('=================')
utils.DebugLog('Delete Extensions')
for k, v in pairs(processData.deleteExtensions) do
utils.DebugLog('*** ' .. k)
for _, v2 in pairs(v) do
utils.DebugLog(v2.operation .. ' | ' .. string.sub(v2.entropy, 1, 4) .. ' | ' .. v2.alertScore .. ' | ' ..
string.sub(v2.filePath, 1, 200))
end
end
utils.DebugLog('=================')
utils.DebugLog('Rename Extensions')
for k, v in pairs(processData.renameExtensions) do
utils.DebugLog('*** ' .. k)
for _, v2 in pairs(v) do
utils.DebugLog(v2.operation .. ' | ' .. string.sub(v2.entropy, 1, 4) .. ' | ' .. v2.alertScore .. ' | ' ..
string.sub(v2.filePath, 1, 200))
end
end
utils.DebugLog('=================')
utils.DebugLog('Overwrite Extensions')
for k, v in pairs(processData.overwriteExtensions) do
utils.DebugLog('*** ' .. k)
for _, v2 in pairs(v) do
utils.DebugLog(v2.operation .. ' | ' .. string.sub(v2.entropy, 1, 4) .. ' | ' .. v2.alertScore .. ' | ' ..
string.sub(v2.filePath, 1, 200))
end
end
utils.DebugLog('=================')
utils.DebugLog('headerMismatchExtensions')
for k, v in pairs(processData.headerMismatchExtensions) do
utils.DebugLog('*** ' .. k)
end
utils.DebugLog('=================')
utils.DebugLog('entropyMismatchExtensions')
for k, v in pairs(processData.entropyMismatchExtensions) do
utils.DebugLog('*** ' .. k .. ' : ' .. v)
end
end
-- Provides a quick string summary of a process activity by tallying the different
-- types of file operations.
-- @param processData table: A table containing process data.
-- @return void.
function utils.PrintOperationTables(processData)
local creates = 0
local modifies = 0
local deletes = 0
local renames = 0
local overwrites = 0
for _, v in pairs(processData.createExtensions) do
creates = creates + #v
end
for _, v in pairs(processData.modifyExtensions) do
for _, _ in pairs(v) do
modifies = modifies + 1
end
end
for _, v in pairs(processData.deleteExtensions) do
deletes = deletes + #v
end
for _, v in pairs(processData.renameExtensions) do
renames = renames + #v
end
for _, v in pairs(processData.overwriteExtensions) do
overwrites = overwrites + #v
end
local operationString =
'PID: ' .. processData.processId .. ' Creates: ' .. creates .. ' | Modifies: ' .. modifies .. ' | Deletes: ' ..
deletes .. ' | Renames: ' .. renames .. ' | Overwrites: ' .. overwrites
return operationString
end
-- Prints a lua table. This function supports printing nested tables.
-- @param t Table: The table subject for printing.
-- @return: void.
function utils.PrintTable(t)
local printTable_cache = {}
local function sub_printTable(t, indent)
if (printTable_cache[tostring(t)]) then
utils.DebugLog(indent .. '*' .. tostring(t))
else
printTable_cache[tostring(t)] = true
if (type(t) == 'table') then
for pos, val in pairs(t) do
if (type(val) == 'table') then
utils.DebugLog(indent .. '[' .. pos .. '] => ' .. tostring(t) .. ' {')
sub_printTable(val, indent .. string.rep(' ', string.len(pos) + 8))
utils.DebugLog(indent .. string.rep(' ', string.len(pos) + 6) .. '}')
elseif (type(val) == 'string') then
utils.DebugLog(indent .. '[' .. pos .. '] => "' .. val .. '"')
else
utils.DebugLog(indent .. '[' .. pos .. '] => ' .. tostring(val))
end
end
else
utils.DebugLog(indent .. tostring(t))
end
end
end
if (type(t) == 'table') then
utils.DebugLog(tostring(t) .. ' {')
sub_printTable(t, ' ')
utils.DebugLog('}')
else
sub_printTable(t, ' ')
end
end
------------------------------------------------------------------------------
-- The functions below are wrappers over functions that are called directly by
-- the sensor, when the lua module is used outside of the endpoint, the `mock`
-- module implements the required functions to mock.
------------------------------------------------------------------
-- Wrapper function around llog.
-- @param str string: The subject file path.
-- @return void.
function utils.DebugLog(str)
-- TODO decouple logging.
if globals.logging then
-- llog(globals.namespace.nameString .. ': ' .. str)
llog(str)
end
end
-- Get the list of all user profiles.
-- @return table: A table representing the list of user profiles.
function utils.GetAllUserProfiles()
local results = {}
-- FOLDERID_UserProfiles.
local usersDir = GetKnownFolderPath('{0762D272-C50A-4BB0-A382-697DCD729B80}')
local users = ListDir(usersDir)
for _, f in ipairs(users) do
if f.Type == 'DIR' then
table.insert(results, f.Path)
end
end
return results
end
-- Determines what product is in use.
-- @return string: a string representing the current product: elastic or endgame.
function utils.GetProduct()
-- check if we can resolve lproduct() func.
if lproduct ~= nil then
-- Check which product is in use.
return lproduct()
else
-- lproduct will be nil *only* if we are running an endgame sensor.
return 'endgame'
end
end
-- Check if the actual sensor version is less than the provided version string.
-- @param targetVersion string: The targeted version.
-- @return boolean: True or false for properly formatted strings (ex. major.minor.release),
-- or false on formatting errors,
-- or true if lversion is nil.
function utils.CurrentVersionLessThan(targetVersion)
if not utils.IsVersionAvailable() then
return true
end
local currentVersion = lversion('sensor')
-- Validate parameters.
if (not currentVersion) or (not targetVersion) then
return false
end
-- Grab the pieces.
local currentMajor, currentMinor, currentRelease
local targetMajor, targetMinor, targetRelease
_, _, currentMajor, currentMinor, currentRelease = string.find(currentVersion, '(%d+)%.(%d+)%.(%d+)')
_, _, targetMajor, targetMinor, targetRelease = string.find(targetVersion, '(%d+)%.(%d+)%.(%d+)')
-- Validate major version parsing.
if (not currentMajor) or (not targetMajor) then
return false
end
-- Compare major versions.
if (currentMajor < targetMajor) then
return true
end
if (currentMajor == targetMajor) then
-- Validate minor version parsing.
if (not currentMinor) or (not targetMinor) then
return false
end
-- Compare minor versions.
if (currentMinor < targetMinor) then
return true
end
if (currentMinor == targetMinor) then
-- Validate release version parsing.
if (not currentRelease) or (not targetRelease) then
return false
end
-- Compare release versions.
if (currentRelease < targetRelease) then
return true
end
end
end
return false
end
-- Determines if lversion function is available for use in lua. lversion will
-- be nil only if we are running sensor version 3.53 or lower.
-- @return boolean: True if lversion is nil. False otherwise.
function utils.IsVersionAvailable()
if lversion ~= nil then
return true
else
return false
end
end
local alert = {
-- Limits the number of diagnostic alerts generated.
DIAGNOSTIC_ALERT_CAP = 10,
-- Mapping between file operations and their string representation.
FILE_OP_STR_MAP = {'creation', 'modification', 'deletion', 'rename', 'overwrite', 'open'}
}
-- Inserts the input alert metric into the list of event data alert metrics.
-- @param eventData table: A table containing event data.
-- @param alertMetric string: The subject alert name.
-- @return table: A table representing the new event data alert metrics.
function alert.RaiseFileAlertMetric(eventData, alertMetric)
if not utils.TableHasKey(eventData.alertMetrics, alertMetric) then
table.insert(eventData.alertMetrics, alertMetric)
end
return eventData.alertMetrics
end
-- Handle alert generation by passing a table to the sensor callback via `lemit`.
-- @param alertProcessData table: A table containing alert process data.
-- @param isDiagnostic boolean: A boolean that indicates whether or not this is
-- a designated diagnostic alert.
-- @return boolean: True in every case. TODO: fix possible return values.
function alert.GenerateAlert(alertProcessData, isDiagnostic)
local processTable = {}
local product = utils.GetProduct()
if product == nil or product == '' then
-- GetProduct() will return "endgame" if import isn't found and
-- lproduct() will always return a value, so if this is the case we're
-- in undefined behavior territory and should bail.
utils.DebugLog('Error collecting product information via GetProduct()')
return true
end
if isDiagnostic and globals.namespace.totalAlerts >= alert.DIAGNOSTIC_ALERT_CAP then
-- globals.alertGenerated = true
utils.DebugLog('alert.DIAGNOSTIC_ALERT_CAP REACHED! alert will not be generated for PID: ' ..
alertProcessData.processId)
return true
end
if isDiagnostic and alertProcessData.diagnosticAlertQueued then
utils.DebugLog('FINALLY generate our DIAGNOSTIC alert!')
-- set boolean to false to avoid duplicate diagnostic alerts
alertProcessData.diagnosticAlertQueued = false
elseif isDiagnostic and alertProcessData.diagnosticAlerted then
utils.DebugLog('PREVIOUSLY DIAGNOSTIC ALERTED ON THIS PROCESS!')
return true
elseif false == alertProcessData.activeAnalysis then
utils.DebugLog('Process no longer subject to active analysis')
return true
elseif true == alertProcessData.alerted then
utils.DebugLog('Previously alerted on this process in this namespace')
return true
end
if nil ~= alertProcessData.createExtensions then
utils.PrintExtensionTables(alertProcessData)
utils.PrintOperationTables(alertProcessData)
end
-- Set fields shared between endgame and elastic.
processTable.pid = alertProcessData.processId
processTable.is_alert = true
processTable.score = alertProcessData.totalScore
processTable.alert_files = {}
if isDiagnostic then
utils.DebugLog('DIAGNOSTIC ALERT: ' .. alertProcessData.processId)
alertProcessData.diagnosticAlerted = true
-- Endpoint/sensor still use 'beta_alert' key.
processTable.beta_alert = true
else
alertProcessData.activeAnalysis = false
alertProcessData.alerted = true
-- Endpoint/sensor still use 'beta_alert' key.
processTable.beta_alert = false
end
-- Emit alert in specific schema for corresponding product in use.
if product == 'endgame' then
alert.GenerateEndgameAlert(processTable, alertProcessData)
elseif product == 'elastic' then
processTable.canary_alert = alertProcessData.canary_alert
-- Add in RansomwareChildProcesses if present.
if nil ~= alertProcessData.child_processes then
processTable.child_processes = alertProcessData.child_processes
end
alert.GenerateElasticAlert(processTable, alertProcessData)
end
lemit(processTable)
globals.alertGenerated = true
globals.namespace.totalAlerts = globals.namespace.totalAlerts + 1
utils.DebugLog('namespace.totalAlerts: ' .. globals.namespace.totalAlerts)
return true
end
-- Generate an alert in the old Endgame schema.
-- @param processData table: A table containing process data.
-- @param alertProcessData table: A table containing alert process data.
-- @return void.
function alert.GenerateEndgameAlert(processTable, alertProcessData)
local tempMessage = {}
local incompatible = false
-- Set Endgame specific fields.
processTable.file_list = {}
processTable.process_alerts = {'PROCESS_LUA_ALERT'}
-- Check compatibility.
incompatible = utils.CurrentVersionLessThan('3.54.0')
for _, v in pairs(alertProcessData.events) do
tempMessage = {}
tempMessage.file_path = v.filePath
if not incompatible then
-- 3.54 and greater sensors are compatible with new changes;
-- schema changes and proper use of alert_files messages for extended
-- alert data needed for triage and event trace replay.
table.insert(processTable.file_list, tempMessage)
tempMessage = {}
tempMessage.file_path = v.filePath
tempMessage.score = v.alertScore
tempMessage.entropy = v.entropy
tempMessage.file_extension = v.fileExtension
tempMessage.bk_file_operation = v.operation
tempMessage.file_alerts = {}
tempMessage.header_string = v.headerString
for _, v2 in pairs(v.alertMetrics) do
table.insert(tempMessage.file_alerts, v2)
end
if utils.FILE_RENAME == v.operation then
tempMessage.file_previous_path = v.filePreviousPath
tempMessage.file_previous_extension = v.filePreviousExtension
end
table.insert(processTable.alert_files, tempMessage)
elseif incompatible then
-- Maintain clean filepath entries for 3.53.
table.insert(processTable.file_list, tempMessage)
end
end
-- Hacky version left in to support sending extended triage data for
-- 3.53 (since we didn't parse alert_files entries in the sensor).
if incompatible then
for _, v in pairs(alertProcessData.events) do
tempMessage = {}
tempMessage.file_path = v.fileName .. ' | ' .. v.alertScore .. ' | ' .. v.entropy .. ' | ' .. v.headerString
table.insert(processTable.file_list, tempMessage)
end
for _, v in pairs(alertProcessData.events) do
tempMessage = {}
tempMessage.file_path = v.fileName
for _, v2 in pairs(v.alertMetrics) do
tempMessage.file_path = tempMessage.file_path .. '|' .. v2
end
tempMessage.file_path = tempMessage.file_path .. ' | ' .. v.operation + .0
if utils.FILE_RENAME == v.operation then
tempMessage.file_path = tempMessage.file_path .. ' | ' .. v.filePreviousPath
end
table.insert(processTable.file_list, tempMessage)
end
end
end
-- Generates an alert in elastic ECS schema.
-- @param processData table: A table containing process data.
-- @param alertProcessData table: A table containing alert process data.
-- @return void.
function alert.GenerateElasticAlert(processTable, alertProcessData)
local tempMessage = {}
for _, v in pairs(alertProcessData.events) do
-- Output data in ECS Schema format
-- files :
-- fields :
-- operation :
-- entropy :
-- metrics :
-- extension :
-- original.path :
-- original.extension :
-- path :
-- data :
-- score :
tempMessage = {}
tempMessage.path = v.filePath
tempMessage.score = v.alertScore
tempMessage.entropy = v.entropy
tempMessage.extension = v.fileExtension
tempMessage.data = v.headerString
-- Lua arrays start from 1 so add 1 to correctly index the specified
-- file operation to string.
if nil ~= alert.FILE_OP_STR_MAP[v.operation + 1] then
tempMessage.operation = alert.FILE_OP_STR_MAP[v.operation + 1]
end
local metricsCount = 0
for _, v2 in pairs(v.alertMetrics) do
if 0 == metricsCount then
tempMessage.metrics = {}
end
table.insert(tempMessage.metrics, v2)
metricsCount = metricsCount + 1
end
if utils.FILE_RENAME == v.operation then
tempMessage.original = {}
tempMessage.original['path'] = v.filePreviousPath
tempMessage.original['extension'] = v.filePreviousExtension
end
-- As the endpoint doesn't parse alert_files (but rather pulls the
-- array out by the key) we can leave this the same and re-append
-- as new ECS `files` field in the endpoint.
table.insert(processTable.alert_files, tempMessage)
end
end
_G.globals = {}
globals.logging = false
globals.alertGenerated = false
globals.namespaces = {}
globals.config = {}
-- should always start as false
globals.diagnosticCanariesDropped = false
globals.productionCanariesDropped = false
globals.diagnosticStartupInvoked = false
globals.productionStartupInvoked = false
-- is this running on elastic 8.6.0 or newer?
globals.canaryCompatible = false
-- limit canary cleanup failure alerts
globals.bCanaryDiagnosticsEmitted = false
-- namespace is used to reference the current namespace while we are in the globals scope.
globals.namespace = nil
-- default metric values.
globals.config["ABNORMAL_EXTENSION_CHARACTERS"] = {}
globals.config["ABNORMAL_EXTENSION_CHARACTERS"]["score"] = 0.1
globals.config["CREATE_EXTENSION_KNOWN_HEADER_MISMATCH_WITH_PREVIOUSLY_DELETED_SUBSTRING"] = {}
globals.config["CREATE_EXTENSION_KNOWN_HEADER_MISMATCH_WITH_PREVIOUSLY_DELETED_SUBSTRING"]["score"] = 1.0
globals.config["CREATE_EXTENSION_KNOWN_SUBEXTENSION_KNOWN"] = {}
globals.config["CREATE_EXTENSION_KNOWN_SUBEXTENSION_KNOWN"]["score"] = 0.002
globals.config["CREATE_EXTENSION_KNOWN_SUBEXTENSION_KNOWN_AND_PREVIOUSLY_DELETED"] = {}
globals.config["CREATE_EXTENSION_KNOWN_SUBEXTENSION_KNOWN_AND_PREVIOUSLY_DELETED"]["score"] = 0.02
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN"]["score"] = 0.005
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_AND_PREVIOUSLY_DELETED"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_AND_PREVIOUSLY_DELETED"]["score"] = 0.03
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_AVERAGE"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_AVERAGE"]["score"] = 0.1
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGH"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGH"]["score"] = 0.15
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGHER"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGHER"]["score"] = 0.2
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGHEST"] = {}
globals.config["CREATE_EXTENSION_UNKNOWN_SUBEXTENSION_KNOWN_THRESHOLD_ENTROPY_HIGHEST"]["score"] = 0.5
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGH"] = {}
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGH"]["score"] = 0.05
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGHER"] = {}
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGHER"]["score"] = 0.15
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGHEST"] = {}
globals.config["CREATE_WITH_PREVIOUSLY_DELETED_FILEPATH_SUBSTRING_ENTROPY_HIGHEST"]["score"] = 0.25
globals.config["DELETE_EXTENSION_BLOCKLIST_PREVIOUSLY_CREATED_FILEPATH"] = {}
globals.config["DELETE_EXTENSION_BLOCKLIST_PREVIOUSLY_CREATED_FILEPATH"]["score"] = 0.75
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGH"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGH"]["score"] = 0.4
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGHER"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGHER"]["score"] = 0.5
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGHEST"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_POSSIBLE_MISMATCH_ENTROPY_HIGHEST"]["score"] = 0.6
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGH"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGH"]["score"] = 0.3
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHER"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHER"]["score"] = 0.4
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHEST"] = {}
globals.config["DELETE_EXTENSION_KNOWN_WITH_LOW_ENTROPY_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHEST"]["score"] = 0.5
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGH"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGH"]["score"] = 0.3
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHER"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHER"]["score"] = 0.4
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHEST"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN_ENTROPY_HIGHEST"]["score"] = 0.5
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING"]["score"] = 0.1
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGH"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGH"]["score"] = 0.2
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGHER"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGHER"]["score"] = 0.3
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGHEST"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_ENTROPY_HIGHEST"]["score"] = 0.4
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN"] = {}
globals.config["DELETE_WITH_PREVIOUSLY_CREATED_SUBSTRING_EXTENSION_UNKNOWN"]["score"] = 0.1
globals.config["ENTROPY_HIGHER"] = {}
globals.config["ENTROPY_HIGHER"]["score"] = 0.05
globals.config["ENTROPY_HIGHER_EXTENSION_UNKNOWN"] = {}
globals.config["ENTROPY_HIGHER_EXTENSION_UNKNOWN"]["score"] = 0.05
globals.config["ENTROPY_MISMATCH_HIGHER"] = {}
globals.config["ENTROPY_MISMATCH_HIGHER"]["score"] = 0.5
globals.config["ENTROPY_MISMATCH_HIGHER_WITH_HEADER_MISMATCH"] = {}
globals.config["ENTROPY_MISMATCH_HIGHER_WITH_HEADER_MISMATCH"]["score"] = 0.5
globals.config["ENTROPY_MISMATCH_HIGHEST"] = {}
globals.config["ENTROPY_MISMATCH_HIGHEST"]["score"] = 0.75
globals.config["ENTROPY_MISMATCH_HIGHEST_WITH_HEADER_MISMATCH"] = {}
globals.config["ENTROPY_MISMATCH_HIGHEST_WITH_HEADER_MISMATCH"]["score"] = 1.0
globals.config["EXTENSION_BLOCKLIST"] = {}
globals.config["EXTENSION_BLOCKLIST"]["score"] = 0.4
globals.config["HEADER_MISMATCH_EXTENSIONS_THRESHOLD_MET"] = {}
globals.config["HEADER_MISMATCH_EXTENSIONS_THRESHOLD_MET"]["score"] = 0.3
globals.config["PREVIOUS_HEADER_MISMATCH_EXTENSIONS_THRESHOLD_MET"] = {}
globals.config["PREVIOUS_HEADER_MISMATCH_EXTENSIONS_THRESHOLD_MET"]["score"] = 0.2
globals.config["RENAME_ENTROPY_MISMATCH_HIGHER"] = {}
globals.config["RENAME_ENTROPY_MISMATCH_HIGHER"]["score"] = 0.3
globals.config["RENAME_ENTROPY_MISMATCH_HIGHEST"] = {}
globals.config["RENAME_ENTROPY_MISMATCH_HIGHEST"]["score"] = 0.4
globals.config["RENAME_EXTENSION_KNOWN_TO_BLANK"] = {}
globals.config["RENAME_EXTENSION_KNOWN_TO_BLANK"]["score"] = 0.002
globals.config["RENAME_EXTENSION_KNOWN_TO_BLOCKLIST"] = {}
globals.config["RENAME_EXTENSION_KNOWN_TO_BLOCKLIST"]["score"] = 0.4
globals.config["RENAME_EXTENSION_KNOWN_TO_UNKNOWN"] = {}
globals.config["RENAME_EXTENSION_KNOWN_TO_UNKNOWN"]["score"] = 0.0025
globals.config["RENAME_EXTENSION_KNOWN_TO_UNKNOWN_MULTIPLE"] = {}
globals.config["RENAME_EXTENSION_KNOWN_TO_UNKNOWN_MULTIPLE"]["score"] = 0.005
globals.config["RENAME_EXTENSION_UNKNOWN_TO_BLOCKLIST"] = {}
globals.config["RENAME_EXTENSION_UNKNOWN_TO_BLOCKLIST"]["score"] = 0.3
globals.config["RENAME_EXTENSION_UNKNOWN_TO_UNKNOWN"] = {}
globals.config["RENAME_EXTENSION_UNKNOWN_TO_UNKNOWN"]["score"] = 0.01
globals.config["SUBEXTENSION_KNOWN"] = {}
globals.config["SUBEXTENSION_KNOWN"]["score"] = 0.003
globals.config["SUBEXTENSION_KNOWN_EXTENSION_UNKNOWN"] = {}
globals.config["SUBEXTENSION_KNOWN_EXTENSION_UNKNOWN"]["score"] = 0.0015
globals.config["SUBEXTENSION_UNKNOWN_AND_PREVIOUSLY_DELETED"] = {}
globals.config["SUBEXTENSION_UNKNOWN_AND_PREVIOUSLY_DELETED"]["score"] = 0.005
globals.config["TREND_SCORE_DELETE_CREATE_RATIO"] = {}
globals.config["TREND_SCORE_DELETE_CREATE_RATIO"]["score"] = 0.01
globals.config["TREND_SCORE_MORE_CREATES_THAN_DELETES"] = {}
globals.config["TREND_SCORE_MORE_CREATES_THAN_DELETES"]["score"] = 2.0
globals.config["TREND_SCORE_RENAME_EXTENSION_RATIO"] = {}
globals.config["TREND_SCORE_RENAME_EXTENSION_RATIO"]["score"] = 0.01
globals.config["TREND_SCORE_NUM_RENAMES"] = {}
globals.config["TREND_SCORE_NUM_RENAMES"]["score"] = 0.01
globals.config["TREND_SCORE_SINGLE_PREV_RENAME_EXTENSION"] = {}
globals.config["TREND_SCORE_SINGLE_PREV_RENAME_EXTENSION"]["score"] = 0.01
globals.INVALID_PROCESS_ID = 1
globals.PROCESS_EVENT_THRESHOLD = 200
globals.PROCESS_EXTENDED_EVENT_THRESHOLD = 400
globals.PROCESS_FINAL_EXTENDED_EVENT_THRESHOLD = 650
globals.PROCESS_TREND_FLOOR = 50
globals.PROCESS_ALERT_SCORE_THRESHOLD = 30.0
globals.PROCESS_PARENT_CHILD_ALERT_SCORE_THRESHOLD = 100.0
-- limits the number of diagnostic alerts generated
globals.DIAGNOSTIC_ALERT_CAP = 10
globals.CANARY_CREATE_FILE_ALERT_CAP = 5
globals.MAX_CHILD_PROCESSES = 5
-- TODO: refactor these RENAME globals to be paired with equivalent string mapping
globals.DEFAULT_RENAME = 0
globals.KNOWN_TO_SUSPICIOUS = 1
globals.KNOWN_TO_UNKNOWN = 2
globals.KNOWN_TO_BLANK = 3
globals.UNKNOWN_TO_SUSPICIOUS = 4
globals.UNKNOWN_TO_UNKNOWN = 5
globals.ENTROPY_REALLY_HIGH = 7.9
globals.ENTROPY_VERY_HIGH = 7.5
globals.ENTROPY_HIGH = 7.0
globals.FILE_CREATE_NEW = 0
globals.FILE_MODIFY = 1
globals.FILE_DELETE = 2
globals.FILE_RENAME = 3
globals.FILE_OVERWRITE = 4
globals.FILE_OPEN = 5
globals.fileOperationStringMappings = {'creation', 'modification', 'deletion', 'rename', 'overwrite', 'open'}
-- TODO: refactor the ENTROPY_STATUS_* globals along with string mapping like seen below
-- TODO x 2: refactor the parallel variables between these entries and
-- ENTROPY_REALLY_HIGH, ENTROPY_VERY_HIGH, ENTROPY_HIGH to avoid code
-- duplication and simplify code maintenance
-- globals.ENTROPY_STATUS_DEFAULT = 0
-- globals.ENTROPY_STATUS_HIGH = 1
-- globals.ENTROPY_STATUS_VERY_HIGH = 2
-- globals.ENTROPY_STATUS_REALLY_HIGH = 3
-- globals.ENTROPY_STATUS_MISMATCH_VERY_HIGH = 4
-- globals.ENTROPY_STATUS_MISMATCH_REALLY_HIGH = 5
--
-- globals.ENTROPY_STATUS_TO_STRING = {
-- [globals.ENTROPY_STATUS_DEFAULT]='ENTROPY_DEFAULT',
-- [globals.ENTROPY_STATUS_HIGH]='ENTROPY_HIGH',
-- [globals.ENTROPY_STATUS_VERY_HIGH]='ENTROPY_VERY_HIGH',
-- [globals.ENTROPY_STATUS_REALLY_HIGH]='ENTROPY_REALLY_HIGH',
-- [globals.ENTROPY_STATUS_MISMATCH_VERY_HIGH]='ENTROPY_MISMATCH_VERY_HIGH',
-- [globals.ENTROPY_STATUS_MISMATCH_REALLY_HIGH]='ENTROPY_MISMATCH_REALLY_HIGH',
-- }
globals.HEADER_MISMATCH_THRESHOLD = 5
globals.ENTROPY_MISMATCH_THRESHOLD = 5
globals.ENTROPY_STATUS_DEFAULT = 0
globals.ENTROPY_STATUS_HIGH = 1
globals.ENTROPY_STATUS_VERY_HIGH = 2
globals.ENTROPY_STATUS_REALLY_HIGH = 3
globals.ENTROPY_STATUS_MISMATCH_VERY_HIGH = 4
globals.ENTROPY_STATUS_MISMATCH_REALLY_HIGH = 5
-- table of file paths to ignore when processing file events.
globals.regexIgnorePaths = {
'^[a-z]:\\\\users\\\\.*\\\\appdata\\\\',
'^[a-z]:\\\\users\\\\.*\\\\downloads\\\\',
'^[a-z]:\\\\windows\\\\logs\\\\',
'^[a-z]:\\\\windows\\\\ccm\\\\',
'^[a-z]:\\\\windows\\\\csc\\\\',
'^[a-z]:\\\\windows\\\\ccmcache\\\\',
'^[a-z]:\\\\windows\\\\temp\\\\',
'^[a-z]:\\\\windows\\\\softwaredistribution\\\\',
'^[a-z]:\\\\windows\\\\prefetch\\\\',
'^[a-z]:\\\\windows\\\\installer\\\\',
'^[a-z]:\\\\windows\\\\rescache\\\\',
'^[a-z]:\\\\windows\\\\winsxs\\\\',
'^[a-z]:\\\\windows\\\\appcompat\\\\',
'^[a-z]:\\\\windows\\\\system32\\\\logfiles\\\\',
'^[a-z]:\\\\windows\\\\system32\\\\spp\\\\',
'^[a-z]:\\\\windows\\\\system32\\\\wdi\\\\',
'^[a-z]:\\\\windows\\\\system32\\\\winevt\\\\',
'^[a-z]:\\\\windows\\\\sys.*\\\\config\\\\systemprofile\\\\appdata\\\\',
'^[a-z]:\\\\programdata\\\\',
'^[a-z]:\\\\msocache\\\\',
'^[a-z]:\\\\ccmcache\\\\',
'^[a-z]:\\\\[$]windows[.]~bt\\\\',
'^[a-z]:\\\\[$]upgrade[.]~os\\\\',
'^[a-z]:\\\\sccmcontentlib\\\\',
'^[a-z]:\\\\sms_dp[$]\\\\',
'^[a-z]:\\\\program files\\\\steam\\\\',
'^[a-z]:\\\\program files \\(x86\\)\\\\steam\\\\',
'^[a-z]:\\\\program files\\\\microsoft configuration manager\\\\',
'^[a-z]:\\\\system volume information\\\\',
'^[a-z]:\\\\system recovery\\\\',
'^[a-z]:\\\\program files\\\\microsoft office servers\\\\.*\\\\data\\\\office ',
'^[a-z]:\\\\program files\\\\microsoft\\\\exchange ',
'^[a-z]:\\\\windows\\\\servic',
'^[a-z]:\\\\program files\\(x86\\)\\\\skf\\\\surveryor\\\\',
'^[a-z]:\\\\windows\\\\system32\\\\spool\\\\drivers\\\\',
'^[a-z]:\\\\dfsroots\\\\',
'^[a-z]:\\\\lscc\\\\',
'^[a-z]:\\\\_smstasksequence\\\\',
'^[a-z]:\\\\mimecast\\\\mse\\\\',
'.*\\\\!tdr.bin\\\\',
'.*\\\\.dropbox.cache\\\\',
'.*\\\\iis temporary compressed files\\\\',
'.*\\\\appdata\\\\local\\\\google\\\\chrome\\\\user data\\\\',
'.*\\\\microsoft sql server\\\\.*\\\\setup bootstrap\\\\update cache\\\\',
'.*\\\\microsoft\\\\windows\\\\inetcache\\\\content.mso\\\\',
'.*server\\\\applications\\\\gthrsvc\\\\',
'.*server\\\\.*\\\\clientaccess\\\\oab\\\\temp\\\\',
}
-- table of known Microsoft Office Extensions
globals.officeExtensions = {
'doc',