Commit Graph

513 Commits

Author SHA1 Message Date
Thomas Stromberg
41e68657e9
Include more commands 2023-01-13 13:49:41 -05:00
Thomas Stromberg
4ec1581cc3
Also include binaries running from a hidden directory (1 deep) 2023-01-13 13:48:47 -05:00
Thomas Stromberg
00872b28bb
Speed query up by first referencing processes table 2023-01-13 13:48:22 -05:00
Thomas Stromberg
7073cde5f0
Allow chmod 0777 to match 2023-01-13 13:48:02 -05:00
Thomas Stromberg
1084843ed4
Add header metadata 2023-01-13 13:47:33 -05:00
Thomas Stromberg
c045daa8f9
Remove Python whitelist, see pymafka 2023-01-13 13:47:19 -05:00
Thomas Stromberg
dd3149a34b
Add support for .pkg files 2023-01-13 13:47:02 -05:00
Thomas Strömberg
1bd030a2f2
Merge pull request #114 from tstromberg/sysctl
new detector: unexpected sysctl calls
2023-01-09 09:36:01 -05:00
Thomas Stromberg
c495bfccac
new detector: unexpected sysctl calls 2023-01-09 09:35:17 -05:00
Thomas Strömberg
05721ed5c5
Merge pull request #113 from tstromberg/less-false
false positives + hashes: dots, ipn, apport-gtk, homebrew, hyperkey, contexts
2023-01-09 09:35:02 -05:00
Thomas Stromberg
e8af31a348
false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
Thomas Stromberg
a1fa72b1ba
Merge branch 'main' into less-false 2023-01-09 09:04:44 -05:00
Thomas Stromberg
2bcf9316cf
Add some hash fields, fix some false positives 2023-01-09 09:04:38 -05:00
Thomas Strömberg
7ce1e267f5
Merge pull request #112 from tstromberg/less-false
Catch up to some older false positives we ran into
2023-01-06 17:11:54 -05:00
Thomas Stromberg
4eb6993272
Catch up to some older false positives we ran into 2023-01-06 17:11:24 -05:00
Thomas Strömberg
ab17febfee
Merge pull request #111 from tstromberg/less-false
A few less false positives
2023-01-06 16:02:05 -05:00
Thomas Stromberg
1aefbe5e91
More false positive removal 2023-01-06 16:01:35 -05:00
Thomas Strömberg
a378f9a05f
Merge pull request #110 from tstromberg/shell-parent-events
Rewrite unexpected-osascript-calls for simplicity
2023-01-06 15:31:57 -05:00
Thomas Stromberg
cd0b7872c1
Rewrite unexpected-osascript-calls for simplicity 2023-01-06 15:31:08 -05:00
Thomas Strömberg
84711209a9
Merge pull request #109 from tstromberg/shell-parent-events
Fix more false positives, particularly in newer queries
2023-01-06 10:37:37 -05:00
Thomas Stromberg
05a39a78d3
Flush out more false positives across the stack 2023-01-06 10:36:48 -05:00
Thomas Stromberg
7455c22e3c
Fix missing / 2023-01-06 10:19:33 -05:00
Thomas Stromberg
9843def319
Fix more false positives, particularly in shell/fetcher parents 2023-01-06 10:18:19 -05:00
Thomas Strömberg
3db3559a7f
Merge pull request #108 from tstromberg/shell-parent-events
new detectors: unexpected shell & fetcher events
2023-01-04 15:49:36 -05:00
Thomas Stromberg
02881f7a0c
Remove empty line 2023-01-04 15:49:21 -05:00
Thomas Stromberg
9c512c5fd7
new detector: unexpected fetcher parents 2023-01-04 15:48:13 -05:00
Thomas Stromberg
1dbd98c57e
Add enough exceptions to make this useful 2023-01-04 11:58:54 -05:00
Thomas Stromberg
0ad0b3be8c
detection/initial_access/unexpected-shell-parent-events.sql
new detector: unexpected shell parent events
2023-01-04 11:43:26 -05:00
Thomas Strömberg
88e0e5fb57
Merge pull request #107 from tstromberg/root-signers
new detector: unexpected root process signer on macOS
2023-01-04 11:20:27 -05:00
Thomas Stromberg
64ed2bba02
new detector: software running as root on macOS with an unexpected authority 2023-01-04 11:19:44 -05:00
Thomas Strömberg
6f160c686d
Merge pull request #106 from tstromberg/relative-exec
New detector: relative exec low uid
2023-01-04 11:15:09 -05:00
Thomas Stromberg
ef3653216e
New detector: relative exec low uid 2023-01-04 11:14:04 -05:00
Thomas Strömberg
8c35d9c14a
Merge pull request #105 from tstromberg/bmw-of-greensboro
Catch up to other winter-break false positives
2023-01-04 11:09:59 -05:00
Thomas Stromberg
5735d87453
Add execdir exception for ~/%packages 2023-01-04 11:09:20 -05:00
Thomas Stromberg
71cda72dc1
Add exception for dmesg reading /dev/kmsg 2023-01-04 11:08:05 -05:00
Thomas Stromberg
aa7d9d21f7
Fix firefox typo 2023-01-04 11:05:03 -05:00
Thomas Stromberg
ba23df1fef
Catch up to other false positives over winter break 2023-01-04 11:03:38 -05:00
Thomas Strömberg
12acae7250
Merge pull request #104 from tstromberg/new-years
New Years FP cleanup: monitorix, snap-confine, steam, spotify, etc
2023-01-03 08:50:59 -05:00
Thomas Stromberg
a8b95a2c9e
New Years cleanup: monitorix, snap-confine, steam, spotify, etc 2023-01-03 08:50:19 -05:00
Thomas Strömberg
fd2b240344
Merge pull request #103 from tstromberg/sketchy-fetcher-refactor
sketchy fetchers: Remove trailing commas
2022-12-20 08:03:54 -05:00
Thomas Stromberg
44ca59c9d6
sketchy fetchers: Remove trailing commas 2022-12-20 08:03:14 -05:00
Thomas Strömberg
a6a8c28448
Merge pull request #102 from tstromberg/sketchy-fetcher-refactor
sketchy fetcher: Add grandparents and TLD detector
2022-12-20 07:54:17 -05:00
Thomas Strömberg
45cbb3e731
Merge pull request #101 from tstromberg/parent-missing
parent-missing-from-disk: Filter out Docker children too
2022-12-20 07:54:10 -05:00
Thomas Strömberg
ddd238e4de
Merge pull request #100 from tstromberg/k3s
Add k3s /dev/kmsg exception, add parent info
2022-12-20 07:54:03 -05:00
Thomas Stromberg
40c20825e6
sketchy fetcher: Add grandparents and TLD detector 2022-12-20 07:53:29 -05:00
Thomas Stromberg
6ca3d92243
Filter out Docker children too 2022-12-20 07:52:04 -05:00
Thomas Stromberg
350b0d8970
Add k3s /dev/kmsg exception, add parent info 2022-12-20 07:51:29 -05:00
Thomas Strömberg
06e5d15e72
Merge pull request #99 from tstromberg/dec19
False-positive flush: mount.ntfs, docker-credential-desktop, exotic s…
2022-12-19 18:06:37 -05:00
Thomas Stromberg
15d3251120
False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
Thomas Strömberg
a3fcc44e08
Merge pull request #98 from tstromberg/dec15
Sort out more false positives
2022-12-16 17:38:12 -05:00