Updated beacons/sh.py to work with enumerate()

This commit is contained in:
justinta89 2016-03-14 16:13:40 -06:00
parent 0ecec691a0
commit 9a14e02766

View file

@ -78,12 +78,12 @@ def beacon(config):
'tag': pid}
if 'execve' in line:
comps = line.split('execve')[1].split('"')
for ind in enumerate(comps):
for ind, field in enumerate(comps):
if ind == 1:
event['cmd'] = comps[ind]
event['cmd'] = field
continue
if ind % 2 != 0:
event['args'].append(comps[ind])
event['args'].append(field)
event['user'] = __context__[pkey][pid]['user']
ret.append(event)
if not __context__[pkey][pid]['vt'].isalive():