2022-10-18 18:42:26 +00:00
|
|
|
-- Programs who were recently added to disk, based on btime/ctime
|
|
|
|
--
|
|
|
|
-- false-positives:
|
|
|
|
-- * many
|
|
|
|
--
|
|
|
|
-- tags: transient process state often
|
|
|
|
-- platform: linux
|
2022-10-19 20:19:53 +00:00
|
|
|
SELECT
|
|
|
|
p.pid,
|
2022-10-18 18:42:26 +00:00
|
|
|
p.path,
|
|
|
|
p.name,
|
|
|
|
p.cmdline,
|
|
|
|
p.cwd,
|
|
|
|
p.euid,
|
|
|
|
p.parent,
|
|
|
|
f.directory,
|
|
|
|
f.ctime,
|
2023-02-24 21:30:17 +00:00
|
|
|
f.size,
|
2022-10-18 18:42:26 +00:00
|
|
|
f.mtime,
|
2022-12-15 21:51:58 +00:00
|
|
|
p.cgroup_path,
|
2022-10-18 18:42:26 +00:00
|
|
|
p.start_time,
|
|
|
|
pp.path AS parent_path,
|
|
|
|
pp.name AS parent_name,
|
|
|
|
pp.cmdline AS parent_cmdline,
|
|
|
|
pp.cwd AS parent_cwd,
|
|
|
|
pp.euid AS parent_euid,
|
|
|
|
ch.sha256 AS child_sha256,
|
|
|
|
ph.sha256 AS parent_sha256
|
2022-10-19 20:19:53 +00:00
|
|
|
FROM
|
|
|
|
processes p
|
2022-10-18 18:42:26 +00:00
|
|
|
LEFT JOIN file f ON p.path = f.path
|
|
|
|
LEFT JOIN processes pp ON p.parent = pp.pid
|
|
|
|
LEFT JOIN hash AS ch ON p.path = ch.path
|
|
|
|
LEFT JOIN hash AS ph ON pp.path = ph.path
|
2022-10-19 20:19:53 +00:00
|
|
|
WHERE
|
|
|
|
p.start_time > 0
|
2022-11-22 14:21:03 +00:00
|
|
|
AND f.ctime > 0
|
|
|
|
AND p.start_time > (strftime('%s', 'now') - 7200)
|
2023-02-24 21:30:17 +00:00
|
|
|
AND (p.start_time - MAX(f.ctime, f.btime)) < 120
|
2022-10-18 18:42:26 +00:00
|
|
|
AND p.start_time >= MAX(f.ctime, f.ctime)
|
2022-10-19 20:19:53 +00:00
|
|
|
AND NOT f.directory IN ('/usr/lib/firefox', '/usr/local/kolide-k2/bin') -- Typically daemons or long-running desktop apps
|
2022-10-27 14:41:14 +00:00
|
|
|
-- These are binaries that are known to get updated and subsequently executed
|
2022-11-03 15:51:54 +00:00
|
|
|
--
|
|
|
|
-- What I would give for osquery to support binary signature verification on Linux
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path IN (
|
|
|
|
'',
|
|
|
|
'/opt/google/chrome/chrome',
|
2022-10-24 15:08:28 +00:00
|
|
|
'/opt/google/chrome/chrome_crashpad_handler',
|
|
|
|
'/opt/google/chrome/nacl_helper',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/opt/Lens/chrome_crashpad_handler',
|
|
|
|
'/opt/Lens/lens',
|
2023-02-24 21:30:17 +00:00
|
|
|
'/usr/lib/ibus/ibus-dconf',
|
|
|
|
'/usr/bin/limactl',
|
|
|
|
'/usr/lib/ibus/ibus-portal',
|
|
|
|
'/usr/lib/ibus/ibus-engine-simple',
|
2023-02-09 22:54:41 +00:00
|
|
|
'/usr/bin/faked',
|
2023-02-14 13:33:05 +00:00
|
|
|
'/usr/bin/appstreamcli',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/opt/sublime_text/sublime_text',
|
2023-01-27 01:40:47 +00:00
|
|
|
'/usr/lib/systemd/systemd-machined',
|
2023-02-09 01:06:26 +00:00
|
|
|
'/usr/lib/upowerd',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/bin/alacritty',
|
2023-02-24 17:15:56 +00:00
|
|
|
'/usr/bin/dash',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/bash',
|
2023-01-27 01:40:47 +00:00
|
|
|
'/usr/bin/rpmbuild',
|
2023-02-24 17:15:56 +00:00
|
|
|
'/usr/bin/make',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/cargo',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/bin/containerd',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/containerd-shim-runc-v2',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/bin/docker',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/bin/dockerd',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/docker-proxy',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/bin/fusermount3',
|
2022-10-21 18:13:29 +00:00
|
|
|
'/usr/bin/gedit',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/bin/gjs-console',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/gnome-keyring-daemon',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/bin/ibus-daemon',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/bin/kbfsfuse',
|
|
|
|
'/usr/bin/keybase',
|
2023-01-06 15:19:33 +00:00
|
|
|
'/usr/bin/keybase-redirector',
|
2022-12-19 23:06:06 +00:00
|
|
|
'/usr/bin/NetworkManager',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/bin/nm-applet',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/bin/obs',
|
2022-11-04 13:12:38 +00:00
|
|
|
'/usr/bin/pavucontrol',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/bin/pipewire',
|
2023-01-04 16:03:38 +00:00
|
|
|
'/usr/bin/pipewire-pulse',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/bin/python3.11',
|
2022-10-31 21:40:37 +00:00
|
|
|
'/usr/bin/rpi-imager',
|
2022-12-15 21:51:58 +00:00
|
|
|
'/usr/bin/snap',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/bin/tailscaled',
|
2023-02-21 00:10:12 +00:00
|
|
|
'/usr/bin/sshfs',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/bin/udevadm',
|
2022-12-15 21:51:58 +00:00
|
|
|
'/usr/bin/wireplumber',
|
2022-11-08 01:36:37 +00:00
|
|
|
'/usr/bin/wpa_supplicant',
|
2022-12-02 16:20:18 +00:00
|
|
|
'/usr/lib64/electron/electron',
|
2022-11-08 01:36:37 +00:00
|
|
|
'/usr/lib64/firefox/firefox',
|
|
|
|
'/usr/lib64/google-cloud-sdk/platform/bundledpythonunix/bin/python3',
|
2022-12-19 23:06:06 +00:00
|
|
|
'/usr/lib64/thunderbird/thunderbird',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/at-spi2-registryd',
|
|
|
|
'/usr/lib/at-spi-bus-launcher',
|
2022-12-02 16:20:18 +00:00
|
|
|
'/usr/libexec/bluetooth/bluetoothd',
|
2022-10-24 15:08:28 +00:00
|
|
|
'/usr/libexec/docker/docker-proxy',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/libexec/fwupd/fwupd',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/libexec/ibus-dconf',
|
|
|
|
'/usr/libexec/ibus-engine-simple',
|
|
|
|
'/usr/libexec/ibus-extension-gtk3',
|
|
|
|
'/usr/libexec/ibus-portal',
|
|
|
|
'/usr/libexec/ibus-x11',
|
2023-01-24 01:33:52 +00:00
|
|
|
'/usr/bin/hugo',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/libexec/snapd/snapd',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/libexec/sssd/sssd_kcm',
|
2023-01-04 16:03:38 +00:00
|
|
|
'/usr/libexec/tracker-extract-3',
|
2022-12-19 23:06:06 +00:00
|
|
|
'/usr/libexec/tracker-miner-fs-3',
|
2022-12-02 16:20:18 +00:00
|
|
|
'/usr/lib/flatpak-session-helper',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/fwupd/fwupd',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/lib/gdm',
|
2023-02-17 16:57:23 +00:00
|
|
|
'/usr/bin/gnome-shell',
|
|
|
|
'/usr/lib/gnome-shell-calendar-server',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/lib/gdm-session-worker',
|
2023-02-23 15:33:10 +00:00
|
|
|
'/usr/bin/sudo',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/lib/gdm-x-session',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/lib/google-cloud-sdk/platform/bundledpythonunix/bin/python3',
|
2022-11-16 16:18:45 +00:00
|
|
|
'/usr/lib/libreoffice/program/oosplash',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/lib/libreoffice/program/soffice.bin',
|
|
|
|
'/usr/lib/polkit-1/polkitd',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/slack/chrome_crashpad_handler',
|
|
|
|
'/usr/lib/slack/slack',
|
2022-11-03 20:05:07 +00:00
|
|
|
'/usr/lib/snapd/snapd',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/lib/systemd/systemd',
|
2023-02-24 21:30:17 +00:00
|
|
|
'/bin/containerd-shim-runc-v2',
|
|
|
|
'/bin/containerd',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/systemd/systemd-journald',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/lib/systemd/systemd-logind',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/systemd/systemd-oomd',
|
|
|
|
'/usr/lib/systemd/systemd-resolved',
|
|
|
|
'/usr/lib/systemd/systemd-timesyncd',
|
2022-12-19 23:06:06 +00:00
|
|
|
'/usr/lib/systemd/systemd-userdbd',
|
2023-01-04 16:03:38 +00:00
|
|
|
'/usr/lib/systemd/systemd-userwork',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/lib/tracker-extract-3',
|
2023-02-24 21:30:17 +00:00
|
|
|
'/usr/bin/gitsign-credential-cache',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/x86_64-linux-gnu/obs-plugins/obs-browser-page',
|
2022-12-15 21:51:58 +00:00
|
|
|
'/usr/lib/xdg-desktop-portal-gtk',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/lib/xf86-video-intel-backlight-helper',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/local/bin/kind',
|
2023-02-24 21:30:17 +00:00
|
|
|
'/usr/bin/golangci-lint',
|
2022-12-02 16:20:18 +00:00
|
|
|
'/usr/sbin/alsactl',
|
|
|
|
'/usr/sbin/avahi-daemon',
|
2022-10-19 19:26:03 +00:00
|
|
|
'/usr/sbin/chronyd',
|
2022-10-18 18:42:26 +00:00
|
|
|
'/usr/sbin/cupsd',
|
2023-01-20 14:29:10 +00:00
|
|
|
'/usr/sbin/ModemManager',
|
|
|
|
'/usr/sbin/NetworkManager',
|
2023-01-03 13:50:19 +00:00
|
|
|
'/usr/sbin/rngd',
|
2022-11-08 01:36:37 +00:00
|
|
|
'/usr/sbin/tailscaled',
|
2022-11-17 12:20:19 +00:00
|
|
|
'/usr/share/code/chrome_crashpad_handler',
|
|
|
|
'/usr/share/code/code',
|
|
|
|
'/usr/share/spotify-client/spotify',
|
|
|
|
'/usr/share/teams/team'
|
2022-10-18 18:42:26 +00:00
|
|
|
)
|
2022-11-17 12:20:19 +00:00
|
|
|
AND NOT p.path LIKE '/tmp/go-build%'
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path LIKE '/home/%/bin/%'
|
|
|
|
AND NOT p.path LIKE '/home/%/terraform-provider-%'
|
|
|
|
AND NOT p.path LIKE '/home/%/%.test'
|
|
|
|
AND NOT p.path LIKE '/home/%/Projects/%'
|
2022-12-15 21:51:58 +00:00
|
|
|
AND NOT p.path LIKE '/home/%/.local/share/nvim/mason/packages/%'
|
2022-12-02 16:20:18 +00:00
|
|
|
AND NOT p.path LIKE '/home/%/node_modules/.bin/%'
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path LIKE '/nix/store/%/bin/%'
|
2022-12-15 21:51:58 +00:00
|
|
|
AND NOT p.path LIKE '/nix/store/%/libexec/%'
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path LIKE '/usr/local/bin/%'
|
2022-11-10 16:04:48 +00:00
|
|
|
AND NOT p.path LIKE '/opt/%'
|
2023-01-26 16:40:54 +00:00
|
|
|
AND NOT p.path LIKE '/tmp/tmp.%/%/bin/%'
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path LIKE '/usr/local/Cellar/%'
|
2022-10-30 14:19:33 +00:00
|
|
|
AND NOT p.path LIKE '/home/%/.local/share/Steam/ubuntu12_64/%'
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT p.path LIKE '/usr/local/kolide-k2/bin/osqueryd-updates/%/osqueryd'
|
|
|
|
AND NOT p.path LIKE '%/.vscode/extensions/%'
|
2022-11-16 21:52:39 +00:00
|
|
|
AND NOT p.path LIKE '/tmp/terraform_%/terraform'
|
2023-02-24 17:15:56 +00:00
|
|
|
AND NOT (
|
|
|
|
p.name IN ('osqtool-x86_64', 'osqtool-arm64')
|
|
|
|
AND p.cmdline LIKE './%'
|
|
|
|
)
|
2022-10-18 18:42:26 +00:00
|
|
|
AND NOT pp.path IN ('/usr/bin/gnome-shell') -- Filter out developers working on their own code
|
|
|
|
AND NOT (
|
|
|
|
p.path LIKE '/home/%'
|
|
|
|
AND p.uid > 499
|
|
|
|
AND f.ctime = f.mtime
|
|
|
|
AND f.uid = p.uid
|
|
|
|
AND p.cmdline LIKE './%'
|
|
|
|
)
|
2023-02-21 00:10:12 +00:00
|
|
|
AND NOT (
|
2023-02-24 17:15:56 +00:00
|
|
|
p.path LIKE '/tmp/%/osqtool-%'
|
2023-02-21 00:10:12 +00:00
|
|
|
AND p.uid > 499
|
|
|
|
AND f.ctime = f.mtime
|
|
|
|
AND f.uid = p.uid
|
|
|
|
AND p.cmdline LIKE './%'
|
|
|
|
)
|
2022-12-16 22:37:32 +00:00
|
|
|
AND NOT (
|
|
|
|
p.path LIKE '/home/%/.magefile/%'
|
|
|
|
AND p.uid > 499
|
|
|
|
AND f.ctime = f.mtime
|
|
|
|
AND f.uid = p.uid
|
|
|
|
)
|
2022-10-19 20:19:53 +00:00
|
|
|
GROUP BY
|
|
|
|
p.pid
|