Commit Graph

429 Commits

Author SHA1 Message Date
Thomas Strömberg
0cba2837bc
Merge pull request #193 from tstromberg/debian
Debian uid0: add dhclient and unattended-upgr
2023-02-23 10:39:15 -05:00
Thomas Stromberg
d253820cf2
Debian: add dhclient and unattended-upgr 2023-02-23 10:35:26 -05:00
Thomas Strömberg
ab5c01a998
Merge pull request #190 from zestysoft/fpr-2
Add osquery to keyboard_sniffer
2023-02-23 10:34:04 -05:00
Thomas Stromberg
d904ca60cf
Add exceptions for Debian running under lima 2023-02-23 10:33:10 -05:00
Ian Brown
737eb93b48
Add osquery to keyboard_sniffer
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-21 22:07:08 -08:00
Thomas Stromberg
baab22e282
Run make reformat-updates 2023-02-20 19:12:51 -05:00
Thomas Stromberg
3a4e0450a6
Uncomment remaining columns 2023-02-20 19:11:23 -05:00
Thomas Stromberg
d3780c0a6c
Remove ubuntu-lts false-positives on lima 2023-02-20 19:10:12 -05:00
Thomas Stromberg
e8cf7ecbe3
fpr: exceptions for pacman, StreamDeck, gcloud, Rocket, thunderbird 2023-02-20 18:04:17 -05:00
Thomas Stromberg
82de4c9c2a
systemd units: increase size bucket from 100 to 225 2023-02-20 13:10:07 -05:00
Thomas Stromberg
75b7ec5552
macos sniffers: back out osquery change until we understand it better, sort exceptions 2023-02-20 11:58:43 -05:00
Ian Brown
d64fd44604
fix
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-19 19:44:31 -08:00
Ian Brown
91f653262c
More osquery matches
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-19 11:24:54 -08:00
Ian Brown
96e95a7f37
Add additional talkers
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-19 11:11:13 -08:00
Ian Brown
74114dd34e
Swap like for equal
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 16:11:35 -08:00
Ian Brown
ffd552aa54
Missed one
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 16:10:48 -08:00
Ian Brown
551d7dbb8c
fpr: Fujitsu, vmware, objective-see, paragon, etc
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 12:02:40 -08:00
Thomas Stromberg
5949ad1551
overwritten memory: filter out pathless kernel bits 2023-02-17 17:20:20 -05:00
Thomas Stromberg
c2b0423606
Rewrite exotic-command-events-linux with INSTR to decrease CPU time 2023-02-17 16:39:52 -05:00
Thomas Stromberg
504ef2c8dd
gcloud: filter out last_update_check, last_survey_prompt 2023-02-17 12:03:36 -05:00
Thomas Stromberg
d25a89f241
execdir events macOS: Fix ambiguous path 2023-02-17 12:01:08 -05:00
Thomas Stromberg
f87541c945
False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
Thomas Strömberg
8976bfecf2
Merge pull request #179 from tstromberg/ddexec
New detector: overwritten memory map
2023-02-17 10:49:57 -05:00
Thomas Stromberg
2e95606d9c
New detector: overwritten memory map 2023-02-17 10:49:19 -05:00
Thomas Stromberg
a655122eec
name path mismatch: only whitelist shells with same cmdlines 2023-02-17 10:47:49 -05:00
Thomas Stromberg
3d13d4995a
hidden system paths: include inode 2023-02-17 10:41:42 -05:00
Thomas Stromberg
00398d447b
Look for setuid binaries in /usr/libexec too 2023-02-17 10:41:28 -05:00
Thomas Stromberg
bc359d69ce
Linux events: decrease CPU usage of elevated children & execdir 2023-02-17 10:40:58 -05:00
Thomas Stromberg
ec675bfb8d
New detector: unexpected ssh-authorized-keys 2023-02-14 20:36:27 -05:00
Thomas Stromberg
5eefbd0dba
Add chattr, setenforce to unexpected-sysutils 2023-02-14 20:35:24 -05:00
Thomas Stromberg
cf858d193d
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe 2023-02-14 20:16:02 -05:00
Thomas Stromberg
8d4531198f
fpr: My ORA, Ecamm, setroubleshootd, etc 2023-02-14 19:46:36 -05:00
Thomas Stromberg
d897f0b50d
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
Thomas Stromberg
99f8793169
Remove com.docker.backend (macOS specific) 2023-02-10 10:32:14 -05:00
Thomas Stromberg
e8d86af906
Make sure caddy & kubectl are in the wider listening range 2023-02-10 10:31:19 -05:00
Thomas Stromberg
34282eacec
Increase polling interval to 15 min 2023-02-10 10:24:20 -05:00
Thomas Stromberg
0b6e503627
New check: Launch Constraint Violation (macOS) 2023-02-10 10:22:13 -05:00
Thomas Stromberg
4f4ae0ed38
False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
Thomas Stromberg
593991adb8
Purge observed false positives 2023-02-09 17:54:41 -05:00
Thomas Stromberg
a1105fec93
Fix broken updates to exotic-commands-macos 2023-02-09 17:06:09 -05:00
Thomas Stromberg
a8ed058d4d
Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
Thomas Strömberg
ca316a0420
Merge pull request #166 from tstromberg/fpr-catch-up
Add exclusions for google-cloud-sdk & Blackmagic firmware
2023-02-08 20:55:53 -05:00
Thomas Strömberg
eef833287a
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
2023-02-08 20:54:45 -05:00
Thomas Stromberg
209a5e08af
Add /Library/ThunderboltAcessoryFirmwareUpdates 2023-02-08 20:53:39 -05:00
Thomas Stromberg
eddefaae48
Fix gcloud exclusion, sort queries 2023-02-08 20:53:19 -05:00
Thomas Stromberg
3eb2c80d92
Add kubectl from google-cloud-sdk 2023-02-08 20:53:03 -05:00
Thomas Stromberg
72326c3b5c
Massive reduction of false positives across the board 2023-02-08 20:06:26 -05:00
Thomas Stromberg
51151290fb
Refactor unexpected tmp executables for speed & decreased hits 2023-02-08 20:06:10 -05:00
echunduri
e44dc167e9 Modified detections explicilty targeted towards macOS to not include cgroup_path fields anymore 2023-02-09 10:57:03 +11:00
Thomas Stromberg
e57f03b89f
fpr: Opera, TextExpander, socket_vmnet, elive, etc 2023-02-08 15:12:10 -05:00