osquery-defense-kit/process/name_path_mismatch.sql

34 lines
991 B
MySQL
Raw Normal View History

2022-09-09 16:51:52 +00:00
SELECT p.name,
f.filename,
p.path,
p.cmdline
FROM processes p
JOIN file f ON p.path = f.path
WHERE SUBSTR(f.filename, 0, 8) != SUBSTR(p.name, 0, 8)
AND NOT (p.name='gjs' AND filename='gjs-console')
2022-09-12 10:52:28 +00:00
AND NOT (p.name='gnome-character' AND filename='gjs-console')
2022-09-09 16:51:52 +00:00
AND NOT (p.name='mysqld' AND filename='mariadbd')
AND NOT (p.name='tmux:client' AND filename='tmux')
AND NOT (p.name='tmux:server' AND filename='tmux')
2022-09-10 11:24:17 +00:00
AND NOT (p.name LIKE 'clangd:%' AND filename='clangd')
2022-09-09 16:51:52 +00:00
AND NOT (p.name='nix-daemon' AND filename='nix')
AND NOT (p.name='systemd-udevd' AND filename='udevadm')
2022-09-12 15:17:51 +00:00
AND NOT (p.name LIKE 'npm%' AND filename='node')
2022-09-10 11:24:17 +00:00
AND NOT (p.name='GUI Thread' AND filename='resolve')
2022-09-09 16:51:52 +00:00
AND NOT (p.name='X' AND filename='Xorg')
AND NOT p.path LIKE '/nix/store/%/bin/bash'
AND NOT p.path LIKE '/usr/bin/python3%'
AND NOT filename IN (
2022-09-11 19:07:54 +00:00
'bash',
'chrome',
2022-09-09 16:51:52 +00:00
'dash',
'electron',
'firefox',
2022-09-11 19:07:54 +00:00
'ruby',
'sh',
'slack',
2022-09-09 16:51:52 +00:00
'systemd',
2022-09-14 11:54:39 +00:00
'busybox',
2022-09-11 19:07:54 +00:00
'thunderbird'
2022-09-09 16:51:52 +00:00
)