Commit Graph

46 Commits

Author SHA1 Message Date
Thomas Stromberg
13a95a4f41
Add exceptions for Kandji 2023-03-17 15:46:00 -04:00
Thomas Stromberg
824efa9705
fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws 2023-03-14 19:00:44 -04:00
Thomas Stromberg
b3825ba2b9
fpr: Canon Universal Installer, melange, GPG, key names 2023-03-06 15:11:11 -05:00
Thomas Stromberg
f25cfe1399
fpr: aws-sdk, melange, Tailscale, Xprotect, etc 2023-03-03 07:24:42 -05:00
Thomas Stromberg
4150b1ee7c
macOS: Exceptions for TestFlight apps & specifically Kindle 2023-02-24 17:04:34 -05:00
Thomas Stromberg
fb7cd56249
fpr: abrt-dbus, gdm, chrome, ff, etc 2023-02-24 16:30:17 -05:00
Thomas Stromberg
d25a89f241
execdir events macOS: Fix ambiguous path 2023-02-17 12:01:08 -05:00
Thomas Stromberg
cf858d193d
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe 2023-02-14 20:16:02 -05:00
Thomas Stromberg
d897f0b50d
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
Thomas Stromberg
4f4ae0ed38
False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
Thomas Strömberg
eef833287a
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
2023-02-08 20:54:45 -05:00
echunduri
e44dc167e9 Modified detections explicilty targeted towards macOS to not include cgroup_path fields anymore 2023-02-09 10:57:03 +11:00
Thomas Stromberg
e57f03b89f
fpr: Opera, TextExpander, socket_vmnet, elive, etc 2023-02-08 15:12:10 -05:00
Thomas Stromberg
2634e9d45b
Monday morning false-positive purge 2023-02-08 14:37:09 -05:00
Thomas Stromberg
bb3e1f964e
Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00
Thomas Stromberg
2093a26423
Fix broken macOS queries 2023-02-02 15:33:25 -05:00
Thomas Stromberg
cdcb2d48f3
Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
Thomas Stromberg
e6824d87e9
Run 'make reformat' 2023-01-20 09:24:24 -05:00
Thomas Stromberg
d415b36b57
FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc 2023-01-16 12:56:39 -05:00
Thomas Stromberg
e3401a07c6
Weekend false-positive flush 2023-01-14 08:19:26 -05:00
Thomas Stromberg
cb896b9e10
Filter out new false positives 2023-01-13 15:24:18 -05:00
Thomas Stromberg
1b79359b68
Friday False Positive Flush 2023-01-13 14:10:43 -05:00
Thomas Stromberg
27dfda38ed
Remove whitelist for ~/Library and ~/.local 2023-01-13 13:54:04 -05:00
Thomas Stromberg
5735d87453
Add execdir exception for ~/%packages 2023-01-04 11:09:20 -05:00
Thomas Stromberg
ba23df1fef
Catch up to other false positives over winter break 2023-01-04 11:03:38 -05:00
Thomas Stromberg
a8b95a2c9e
New Years cleanup: monitorix, snap-confine, steam, spotify, etc 2023-01-03 08:50:19 -05:00
Thomas Stromberg
404adf3e1f
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
Thomas Stromberg
16f9b2f3ee
Remove more false positives: kind, gopls, docker.socket, etc 2022-12-15 10:20:16 -05:00
Thomas Stromberg
b9e0ad34a3
Post-Thanksgiving false positive flush 2022-11-28 16:06:07 -05:00
Thomas Stromberg
4c242773a2
Add ~/Code exception, widen pnpm exception 2022-11-22 16:30:09 -05:00
Thomas Stromberg
6a7c4b6668
Pre-Thanksgiving False Positive cleanup, including Pop!OS support 2022-11-22 09:21:03 -05:00
Thomas Stromberg
8e3d6a1614
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc 2022-11-18 10:27:43 -05:00
Thomas Stromberg
3d7bc8363e
More false positive management 2022-11-16 14:49:36 -05:00
Thomas Stromberg
8047c88374
Run 'make reformat' 2022-11-16 11:02:29 -05:00
Thomas Stromberg
4a9a967b47
execdir: Add ~/go and ~/bin exceptions 2022-11-10 12:55:09 -05:00
Thomas Stromberg
c9605d1c98
Add exceptions for terraform, hugo, macOS updates 2022-11-08 14:32:38 -05:00
Thomas Stromberg
f93a18d112
Refactor execdir, remove false positives 2022-11-07 20:36:37 -05:00
Thomas Stromberg
213e29afcc
Simplify macos-execdir, reduce false positives 2022-11-07 10:03:43 -05:00
Thomas Stromberg
a544ab1f7e
Add exception for vs-kubernetes, add child hash, fix time interval 2022-11-04 10:32:45 -04:00
Thomas Stromberg
87f727fc36
Add Python exception (signed by Ned Deily) 2022-11-04 10:22:35 -04:00
Thomas Stromberg
f2a9e785fe
Refactor unexpected-execdir events for fewer false-positives 2022-11-03 16:00:19 -04:00
Thomas Stromberg
e7e714c9db
Make another stab at reducing false positives across the map 2022-11-03 11:51:54 -04:00
Thomas Stromberg
a00af6c1fa
Merge another day worth of false positives 2022-10-27 10:23:15 -04:00
Thomas Stromberg
d2bdffe89e
Add support for interval tags 2022-10-14 14:19:13 -04:00
Thomas Stromberg
20452b128b
Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
Thomas Stromberg
26ee658c4a
Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00