ossf / ossf/package-analysis

add baits to sandbox container

Open
#586 1 comment 4 reactions 1 assignee View on GitHub

@elainechien is already working on this.

Since May 23, 2023.

dynamic analysis enhancement
Dominant language
Go
Stars
912
Forks
74
PR merge metrics
No merged PRs in 30d

Description

Suggesting adding baits to lure attackers into interacting such as

  • ssh keys
  • environment variables with interesting tokens
  • browser database files
  • discord
  • aws credentials and config
  • .npmrc

In addition to monitoring the interaction with such files, with the visibility https://github.com/ossf/package-analysis/issues/585 can give, observing such sensitive content being exfiltrated to a C2 server, we can add a label in the report such as "EXFILTRATING_SENSITIVE_INFORMATION"

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.