osquery-defense-kit/incident_response/files-recently-written.sql

53 lines
1.4 KiB
MySQL
Raw Permalink Normal View History

2023-05-12 20:17:10 +00:00
-- Returns a list of recently written files
--
-- tags: postmortem
-- platform: posix
-- interval: 3600
2024-02-16 22:21:00 +00:00
SELECT
*
FROM
file
WHERE
(
path LIKE "/var/tmp/%"
OR path LIKE "/var/tmp/%/%"
OR path LIKE "/Applications/%"
OR path LIKE "/Applications/%/%"
OR path LIKE "/home/%/%"
OR path LIKE "/home/%/.%/%"
OR path LIKE "/home/%/.%/%/%"
OR path LIKE "/home/%/.config/%"
OR path LIKE "/home/%/.config/%/%"
OR path LIKE "/Library/%/%"
OR path LIKE "/Library/.%"
OR path LIKE "/Library/Application Support/%"
OR path LIKE "/Library/Application Support/.%"
OR path LIKE "/tmp/%"
OR path LIKE "/tmp/%/%"
OR path LIKE "/tmp/.%/%%"
OR path LIKE "/Users/%/%"
OR path LIKE "/Users/%/%/%"
OR path LIKE "/Users/%/.%/%"
OR path LIKE "/Users/%/.%/%/%"
OR path LIKE "/Users/Library/%"
OR path LIKE "/Users/Library/%/%"
OR path LIKE "/Users/Library/.%"
OR path LIKE "/Users/Library/Application Support/%"
OR path LIKE "/Users/Library/Application Support/%/%"
OR path LIKE "/Users/Library/Application Support/.%"
OR path LIKE "/var/%"
OR path LIKE "/var/%/%"
)
AND (
mtime > (strftime('%s', 'now') -3600)
OR (
atime > (strftime('%s', 'now') -3600)
AND file.type = "regular"
2023-05-12 20:17:10 +00:00
)
2024-02-16 22:21:00 +00:00
OR ctime > (strftime('%s', 'now') -3600)
OR btime > (strftime('%s', 'now') -3600)
)
AND NOT path LIKE "%/../%"
GROUP BY
inode;