mirror of
https://github.com/chainguard-dev/osquery-defense-kit
synced 2025-02-16 09:27:06 +00:00
Merge pull request #365 from tstromberg/fpr-apr25
mark command-events & execdir-events as 'extra' due to high CPU usage
This commit is contained in:
commit
a0c49efb3f
@ -6,7 +6,7 @@
|
|||||||
-- false positives:
|
-- false positives:
|
||||||
-- * possible, but none known
|
-- * possible, but none known
|
||||||
--
|
--
|
||||||
-- tags: transient process events
|
-- tags: transient process events extra
|
||||||
-- platform: darwin
|
-- platform: darwin
|
||||||
-- interval: 180
|
-- interval: 180
|
||||||
SELECT -- Child
|
SELECT -- Child
|
||||||
|
@ -9,7 +9,7 @@
|
|||||||
--
|
--
|
||||||
-- interval: 240
|
-- interval: 240
|
||||||
-- platform: darwin
|
-- platform: darwin
|
||||||
-- tags: filesystem events
|
-- tags: filesystem events extra
|
||||||
SELECT
|
SELECT
|
||||||
COALESCE(
|
COALESCE(
|
||||||
REGEX_MATCH (REPLACE(pe.path, u.directory, '~'), '(.*)/', 1),
|
REGEX_MATCH (REPLACE(pe.path, u.directory, '~'), '(.*)/', 1),
|
||||||
|
Loading…
Reference in New Issue
Block a user