osquery-defense-kit/detection/impact/unexpected-etc-hosts.sql

32 lines
691 B
MySQL
Raw Normal View History

SELECT
*
FROM
etc_hosts
WHERE
hostnames NOT IN (
'localhost',
'localhost ip6-localhost ip6-loopback',
2022-10-13 22:08:03 +00:00
'localhost localhost.localdomain localhost4 localhost4.localdomain4',
'ip6-allnodes',
'ip6-allrouters',
'kubernetes'
)
AND address NOT IN (
'127.0.1.1',
2022-10-13 22:08:03 +00:00
'127.0.0.1',
'::1',
'ff02::1',
'ff02::2',
'255.255.255.255',
'fe00::0',
'ff00::0'
)
AND hostnames NOT LIKE 'localhost.%'
AND hostnames NOT LIKE '%.svc'
2022-10-13 21:58:29 +00:00
AND hostnames NOT LIKE '%.%-%.%.dev'
2022-10-13 22:06:07 +00:00
AND hostnames NOT LIKE '%.wtf'
AND hostnames NOT LIKE '%.test'
AND hostnames NOT LIKE '%.internal'
AND hostnames NOT LIKE '%.local'
AND hostnames NOT LIKE 'ip6-%'