diff --git a/network/detection/finger-detect.yaml b/network/detection/finger-detect.yaml new file mode 100644 index 0000000000..3216d42d83 --- /dev/null +++ b/network/detection/finger-detect.yaml @@ -0,0 +1,29 @@ +id: finger-detect + +info: + name: Finger Daemon Detection + author: DhiyaneshDK + severity: info + description: | + The finger daemon runs on TCP port 79. The client will (in the case of remote hosts) open a connection to port 79. + metadata: + verified: true + shodan-query: port:"79" action + tags: network,finger + +network: + - inputs: + - data: "\n" + + host: + - "{{Hostname}}" + - "{{Host}}:79" + + matchers: + - type: word + part: body + words: + - "User" + - "Action" + - "Node" + condition: and