Skip to content

Plugins

Ceramicskate0 edited this page Aug 25, 2018 · 14 revisions

SWELF PLugins:

Summary:

SWELF Plugins are simply Powershell (.ps1) scripts that are executed by SWELF and then any output that the script has is sent as a log in the format you specify. The scripts are forced through AMSI and if the Microsoft AMSI (which could also plugin to you endpoint AV) module says its safe it is allowed to run. If its found to be malware SWELF will make sure you know.

Plugins Layout:

  • The directory of what you want SWELF to find in the output (just like Event Log)

C:\..\..\Plugins\Plugin_Searchs

  • The folder that tells SWELF where to find the Powershell seachs file is here. Including Whitelists.

C:\..\..\Plugins\Plugin_Searchs\Searchs.txt

  • All the Scripts that SWELF is to run as Plugins must be in this directory

C:\..\..\Plugins\Scripts

  • This is where SWELF will look on the local machine for the plugins/scripts it is to run. It will not look anywhere else. You must place the scripts and anything they need in this location.

IMPORTANT NOTE:

When central configuration is utilized for plugins I left it to you to get the scripts to the endpoint to execute.

Useful Plugins

Clone this wiki locally