Thomas Stromberg
|
13a95a4f41
|
Add exceptions for Kandji
|
2023-03-17 15:46:00 -04:00 |
|
Thomas Stromberg
|
824efa9705
|
fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws
|
2023-03-14 19:00:44 -04:00 |
|
Thomas Stromberg
|
b3825ba2b9
|
fpr: Canon Universal Installer, melange, GPG, key names
|
2023-03-06 15:11:11 -05:00 |
|
Thomas Stromberg
|
f25cfe1399
|
fpr: aws-sdk, melange, Tailscale, Xprotect, etc
|
2023-03-03 07:24:42 -05:00 |
|
Thomas Stromberg
|
4150b1ee7c
|
macOS: Exceptions for TestFlight apps & specifically Kindle
|
2023-02-24 17:04:34 -05:00 |
|
Thomas Stromberg
|
fb7cd56249
|
fpr: abrt-dbus, gdm, chrome, ff, etc
|
2023-02-24 16:30:17 -05:00 |
|
Thomas Stromberg
|
d25a89f241
|
execdir events macOS: Fix ambiguous path
|
2023-02-17 12:01:08 -05:00 |
|
Thomas Stromberg
|
cf858d193d
|
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe
|
2023-02-14 20:16:02 -05:00 |
|
Thomas Stromberg
|
d897f0b50d
|
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc
|
2023-02-14 08:33:05 -05:00 |
|
Thomas Stromberg
|
4f4ae0ed38
|
False positive removal and minor query perf improvements
|
2023-02-10 10:21:06 -05:00 |
|
Thomas Strömberg
|
eef833287a
|
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
|
2023-02-08 20:54:45 -05:00 |
|
echunduri
|
e44dc167e9
|
Modified detections explicilty targeted towards macOS to not include cgroup_path fields anymore
|
2023-02-09 10:57:03 +11:00 |
|
Thomas Stromberg
|
e57f03b89f
|
fpr: Opera, TextExpander, socket_vmnet, elive, etc
|
2023-02-08 15:12:10 -05:00 |
|
Thomas Stromberg
|
2634e9d45b
|
Monday morning false-positive purge
|
2023-02-08 14:37:09 -05:00 |
|
Thomas Stromberg
|
bb3e1f964e
|
Run make reformat, update max rows for incident response
|
2023-02-02 17:58:19 -05:00 |
|
Thomas Stromberg
|
2093a26423
|
Fix broken macOS queries
|
2023-02-02 15:33:25 -05:00 |
|
Thomas Stromberg
|
cdcb2d48f3
|
Slow queries down, minor improvements
|
2023-02-01 16:17:36 -05:00 |
|
Thomas Stromberg
|
e6824d87e9
|
Run 'make reformat'
|
2023-01-20 09:24:24 -05:00 |
|
Thomas Stromberg
|
d415b36b57
|
FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc
|
2023-01-16 12:56:39 -05:00 |
|
Thomas Stromberg
|
e3401a07c6
|
Weekend false-positive flush
|
2023-01-14 08:19:26 -05:00 |
|
Thomas Stromberg
|
cb896b9e10
|
Filter out new false positives
|
2023-01-13 15:24:18 -05:00 |
|
Thomas Stromberg
|
1b79359b68
|
Friday False Positive Flush
|
2023-01-13 14:10:43 -05:00 |
|
Thomas Stromberg
|
27dfda38ed
|
Remove whitelist for ~/Library and ~/.local
|
2023-01-13 13:54:04 -05:00 |
|
Thomas Stromberg
|
5735d87453
|
Add execdir exception for ~/%packages
|
2023-01-04 11:09:20 -05:00 |
|
Thomas Stromberg
|
ba23df1fef
|
Catch up to other false positives over winter break
|
2023-01-04 11:03:38 -05:00 |
|
Thomas Stromberg
|
a8b95a2c9e
|
New Years cleanup: monitorix, snap-confine, steam, spotify, etc
|
2023-01-03 08:50:19 -05:00 |
|
Thomas Stromberg
|
404adf3e1f
|
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc
|
2022-12-15 16:51:58 -05:00 |
|
Thomas Stromberg
|
16f9b2f3ee
|
Remove more false positives: kind, gopls, docker.socket, etc
|
2022-12-15 10:20:16 -05:00 |
|
Thomas Stromberg
|
b9e0ad34a3
|
Post-Thanksgiving false positive flush
|
2022-11-28 16:06:07 -05:00 |
|
Thomas Stromberg
|
4c242773a2
|
Add ~/Code exception, widen pnpm exception
|
2022-11-22 16:30:09 -05:00 |
|
Thomas Stromberg
|
6a7c4b6668
|
Pre-Thanksgiving False Positive cleanup, including Pop!OS support
|
2022-11-22 09:21:03 -05:00 |
|
Thomas Stromberg
|
8e3d6a1614
|
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc
|
2022-11-18 10:27:43 -05:00 |
|
Thomas Stromberg
|
3d7bc8363e
|
More false positive management
|
2022-11-16 14:49:36 -05:00 |
|
Thomas Stromberg
|
8047c88374
|
Run 'make reformat'
|
2022-11-16 11:02:29 -05:00 |
|
Thomas Stromberg
|
4a9a967b47
|
execdir: Add ~/go and ~/bin exceptions
|
2022-11-10 12:55:09 -05:00 |
|
Thomas Stromberg
|
c9605d1c98
|
Add exceptions for terraform, hugo, macOS updates
|
2022-11-08 14:32:38 -05:00 |
|
Thomas Stromberg
|
f93a18d112
|
Refactor execdir, remove false positives
|
2022-11-07 20:36:37 -05:00 |
|
Thomas Stromberg
|
213e29afcc
|
Simplify macos-execdir, reduce false positives
|
2022-11-07 10:03:43 -05:00 |
|
Thomas Stromberg
|
a544ab1f7e
|
Add exception for vs-kubernetes, add child hash, fix time interval
|
2022-11-04 10:32:45 -04:00 |
|
Thomas Stromberg
|
87f727fc36
|
Add Python exception (signed by Ned Deily)
|
2022-11-04 10:22:35 -04:00 |
|
Thomas Stromberg
|
f2a9e785fe
|
Refactor unexpected-execdir events for fewer false-positives
|
2022-11-03 16:00:19 -04:00 |
|
Thomas Stromberg
|
e7e714c9db
|
Make another stab at reducing false positives across the map
|
2022-11-03 11:51:54 -04:00 |
|
Thomas Stromberg
|
a00af6c1fa
|
Merge another day worth of false positives
|
2022-10-27 10:23:15 -04:00 |
|
Thomas Stromberg
|
d2bdffe89e
|
Add support for interval tags
|
2022-10-14 14:19:13 -04:00 |
|
Thomas Stromberg
|
20452b128b
|
Migrate query strings from double to single apostrophes
|
2022-10-13 14:59:32 -04:00 |
|
Thomas Stromberg
|
26ee658c4a
|
Initial re-organization around the MITRE ATT&CK framework
|
2022-10-11 21:53:36 -04:00 |
|