mirror of
https://github.com/chainguard-dev/osquery-defense-kit
synced 2024-12-18 03:54:30 +00:00
Ignore syncthing, nuclei, fix typos
This commit is contained in:
parent
8b9894ec74
commit
202ce6be45
@ -52,6 +52,7 @@ WHERE
|
|||||||
'~/Library/Application Support/CleanMyMac X Menu',
|
'~/Library/Application Support/CleanMyMac X Menu',
|
||||||
'~/Library/Application Support/CleanMyMac X',
|
'~/Library/Application Support/CleanMyMac X',
|
||||||
'~/Library/Application Support/Code',
|
'~/Library/Application Support/Code',
|
||||||
|
'~/Library/Application Support/nuclei',
|
||||||
'~/Library/Application Support/Docker Desktop',
|
'~/Library/Application Support/Docker Desktop',
|
||||||
'~/Library/Application Support/DropboxElectron',
|
'~/Library/Application Support/DropboxElectron',
|
||||||
'~/Library/Application Support/GitHub Desktop',
|
'~/Library/Application Support/GitHub Desktop',
|
||||||
|
@ -183,7 +183,7 @@ WHERE
|
|||||||
'/Users/Shared/LogiOptionsPlus/cache',
|
'/Users/Shared/LogiOptionsPlus/cache',
|
||||||
'/Users/Shared/Red Giant/Uninstall'
|
'/Users/Shared/Red Giant/Uninstall'
|
||||||
)
|
)
|
||||||
AND NOT directory LIKE '/Users/%/.docker/cli-plugins'
|
AND NOT f.directory LIKE '/Users/%/.docker/cli-plugins'
|
||||||
AND NOT directory LIKE '/Users/%/.nix-profile/bin'
|
AND NOT f.directory LIKE '/Users/%/.nix-profile/bin'
|
||||||
GROUP BY
|
GROUP BY
|
||||||
f.path
|
f.path
|
||||||
|
@ -65,7 +65,7 @@ WHERE
|
|||||||
SELECT
|
SELECT
|
||||||
pid
|
pid
|
||||||
FROM
|
FROM
|
||||||
processesP
|
processes
|
||||||
WHERE
|
WHERE
|
||||||
pid > 0
|
pid > 0
|
||||||
AND REGEX_MATCH (
|
AND REGEX_MATCH (
|
||||||
|
@ -54,6 +54,7 @@ WHERE
|
|||||||
AND NOT exception_key IN (
|
AND NOT exception_key IN (
|
||||||
'10011,6,0,launchd,Software Signing',
|
'10011,6,0,launchd,Software Signing',
|
||||||
'10011,6,0,webfilterproxyd,Software Signing',
|
'10011,6,0,webfilterproxyd,Software Signing',
|
||||||
|
'22000,6,500,syncthing,Developer ID Application: Kastelo AB (LQE5SYM783)',
|
||||||
'1024,6,0,systemmigrationd,Software Signing',
|
'1024,6,0,systemmigrationd,Software Signing',
|
||||||
'1313,6,500,hugo,',
|
'1313,6,500,hugo,',
|
||||||
'1338,6,500,registry,',
|
'1338,6,500,registry,',
|
||||||
|
Loading…
Reference in New Issue
Block a user