Skip to content

Commit 6e31e38

Browse files
authored
Add additional Danger Types and Download Interrupts to Chromium (#29)
Based on my commit made in Feb EricZimmerman/SQLECmd#88 implements the same missing values from the Chromium Source code. I noticed there is code in Output/SQLiteHunter.yaml based on the definitions do I need to update these too or is this sufficient? I haven't tested this on Velociraptor but it should be fine as I followed the same format as the others.
1 parent f4c701c commit 6e31e38

1 file changed

Lines changed: 9 additions & 3 deletions

File tree

definitions/ChromiumBrowser_HistoryVisits.yaml

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -57,11 +57,17 @@ Sources:
5757
LET StateLookup <= dict(`0`='In Progress', `1`='Complete', `2`="Cancelled", `3`="Interrupted", `4`="Interrupted")
5858
LET DangerType <= dict(`0`='Not Dangerous', `1`="Dangerous", `2`='Dangerous URL', `3`='Dangerous Content',
5959
`4`='Content May Be Malicious', `5`='Uncommon Content', `6`='Dangerous But User Validated',
60-
`7`='Dangerous Host', `8`='Potentially Unwanted', `9`='Whitelisted by Policy')
60+
`7`='Dangerous Host', `8`='Potentially Unwanted', `9`='Whitelisted by Policy',
61+
`10`='Download Pending Detailed Verdict', `11`='Blocked By Policy Password Protected', `12`='Blocked By Policy Download Too Large',
62+
`13`='Sensitive Content Warning', `14`='Sensitive Content Blocked', `15`='Deep Scanned Safe',
63+
`16`='Deep Scanned Dangerous But Opened By User', `17`='Prompt For Deep Scanning', `18`='Blocked Unsupported Filetype',
64+
`19`='Dangerous Associated With Account Compromise', `20`='Deep Scan Failed', `21`='Encrypted Archive Prompt for Local Password Scanning',
65+
`22`='Encrypted Archive Prompt for Local Password Scanning Pending Detailed Verdict', `23`='Blocked by Policy Scan Failed')
6166
LET InterruptReason <= dict(`0`= 'No Interrupt', `1`= 'File Error', `2`='Access Denied', `3`='Disk Full',
6267
`5`='Path Too Long',`6`='File Too Large', `7`='Virus', `10`='Temporary Problem', `11`='Blocked',
63-
`12`='Security Check Failed', `13`='Resume Error', `20`='Network Error', `21`='Operation Timed Out',
64-
`22`='Connection Lost', `23`='Server Down', `30`='Server Error', `31`='Range Request Error',
68+
`12`='Security Check Failed', `13`='Resume Error File Too Short', `14`='File Hash Mismatch', `15`='File Same As Source',
69+
`20`='Network Error', `21`='Operation Timed Out', `22`='Connection Lost', `23`='Server Down',
70+
`24`='Network Request Invalid', `30`='Server Error', `31`='Range Request Error',
6571
`32`='Server Precondition Error', `33`='Unable to get file', `34`='Server Unauthorized',
6672
`35`='Server Certificate Problem', `36`='Server Access Forbidden', `37`='Server Unreachable',
6773
`38`='Content Length Mismatch', `39`='Cross Origin Redirect', `40`='Cancelled', `41`='Browser Shutdown',

0 commit comments

Comments
 (0)