-
rule name should be HKTL_ldapdomaindump_bloodhound as per the description "Detects hack tools related to ldapdomaindump"
-
this rule produces FP because ldapdomaindump is an official debian package and therefor appears in e.g. ~/..cache/mintinstall/pkginfo.json
"apt:python3-ldapdomaindump": {
"pkg_hash": "apt:python3-ldapdomaindump",
"name": "python3-ldapdomaindump"
},
... MATCHED_1: Str1: "ldapdomaindump" in ": "python3-ldap3"\x0a },\x0a "apt:python3-ldapdomaindump": {\x0a "pkg_hash": "apt:python3-ldapdoma" at 0x4af536 RULEDATE_1: 2019-02-04 TAGS_1: FILE, HKTL RULENAME_1: HKTL_ladpdomaindump_bloodhound
rule name should be HKTL_ldapdomaindump_bloodhound as per the description "Detects hack tools related to ldapdomaindump"
this rule produces FP because ldapdomaindump is an official debian package and therefor appears in e.g. ~/..cache/mintinstall/pkginfo.json
... MATCHED_1: Str1: "ldapdomaindump" in ": "python3-ldap3"\x0a },\x0a "apt:python3-ldapdomaindump": {\x0a "pkg_hash": "apt:python3-ldapdoma" at 0x4af536 RULEDATE_1: 2019-02-04 TAGS_1: FILE, HKTL RULENAME_1: HKTL_ladpdomaindump_bloodhound