Commit Graph

58 Commits

Author SHA1 Message Date
Thomas Stromberg fbc2b207b4
fpr: Signal, apko, aws, melange, dash, stern 2023-03-16 17:29:11 -04:00
Thomas Stromberg fb7cd56249
fpr: abrt-dbus, gdm, chrome, ff, etc 2023-02-24 16:30:17 -05:00
Ian Brown 737eb93b48
Add osquery to keyboard_sniffer
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-21 22:07:08 -08:00
Thomas Stromberg d3780c0a6c
Remove ubuntu-lts false-positives on lima 2023-02-20 19:10:12 -05:00
Thomas Stromberg e8cf7ecbe3
fpr: exceptions for pacman, StreamDeck, gcloud, Rocket, thunderbird 2023-02-20 18:04:17 -05:00
Thomas Stromberg 75b7ec5552
macos sniffers: back out osquery change until we understand it better, sort exceptions 2023-02-20 11:58:43 -05:00
Ian Brown d64fd44604
fix
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-19 19:44:31 -08:00
Ian Brown 96e95a7f37
Add additional talkers
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-19 11:11:13 -08:00
Ian Brown 551d7dbb8c
fpr: Fujitsu, vmware, objective-see, paragon, etc
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 12:02:40 -08:00
Thomas Stromberg cf858d193d
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe 2023-02-14 20:16:02 -05:00
Thomas Stromberg 8d4531198f
fpr: My ORA, Ecamm, setroubleshootd, etc 2023-02-14 19:46:36 -05:00
Thomas Stromberg a8ed058d4d
Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
Thomas Strömberg eef833287a
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
2023-02-08 20:54:45 -05:00
Thomas Stromberg 72326c3b5c
Massive reduction of false positives across the board 2023-02-08 20:06:26 -05:00
echunduri e44dc167e9 Modified detections explicilty targeted towards macOS to not include cgroup_path fields anymore 2023-02-09 10:57:03 +11:00
Thomas Stromberg e57f03b89f
fpr: Opera, TextExpander, socket_vmnet, elive, etc 2023-02-08 15:12:10 -05:00
Thomas Stromberg 2634e9d45b
Monday morning false-positive purge 2023-02-08 14:37:09 -05:00
Thomas Stromberg d302a9ff55
Purge false positives, again and again 2023-02-02 21:46:53 -05:00
Thomas Stromberg 2093a26423
Fix broken macOS queries 2023-02-02 15:33:25 -05:00
Thomas Stromberg f9dce0a72d
Include more process information across queries 2023-02-01 13:55:55 -05:00
Thomas Stromberg d51bd731a1
fpr: Parallels, nerdctl, Xorg, nvidia, Stream, etc 2023-01-26 20:40:47 -05:00
Thomas Stromberg f5fe9a4aac
Refactor process_events queries for more accurate parenting 2023-01-26 11:40:54 -05:00
Thomas Stromberg 83cc38207e
fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
Thomas Stromberg e6824d87e9
Run 'make reformat' 2023-01-20 09:24:24 -05:00
Thomas Stromberg dc154a6199
FPR: Meta Pixel Helper, systemctl, pia-daemon, 1Passwd, iTerm, Brave 2023-01-20 09:04:00 -05:00
Thomas Stromberg d415b36b57
FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc 2023-01-16 12:56:39 -05:00
Thomas Stromberg e3401a07c6
Weekend false-positive flush 2023-01-14 08:19:26 -05:00
Thomas Stromberg 1b79359b68
Friday False Positive Flush 2023-01-13 14:10:43 -05:00
Thomas Stromberg e8af31a348
false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
Thomas Stromberg 71cda72dc1
Add exception for dmesg reading /dev/kmsg 2023-01-04 11:08:05 -05:00
Thomas Stromberg aa7d9d21f7
Fix firefox typo 2023-01-04 11:05:03 -05:00
Thomas Stromberg ba23df1fef
Catch up to other false positives over winter break 2023-01-04 11:03:38 -05:00
Thomas Strömberg 12acae7250
Merge pull request #104 from tstromberg/new-years
New Years FP cleanup: monitorix, snap-confine, steam, spotify, etc
2023-01-03 08:50:59 -05:00
Thomas Stromberg a8b95a2c9e
New Years cleanup: monitorix, snap-confine, steam, spotify, etc 2023-01-03 08:50:19 -05:00
Thomas Stromberg 350b0d8970
Add k3s /dev/kmsg exception, add parent info 2022-12-20 07:51:29 -05:00
Thomas Stromberg 15d3251120
False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
Thomas Stromberg 49a19a6fd5
Sort out more false positives 2022-12-16 17:37:32 -05:00
Thomas Stromberg 404adf3e1f
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
Thomas Stromberg 16f9b2f3ee
Remove more false positives: kind, gopls, docker.socket, etc 2022-12-15 10:20:16 -05:00
Thomas Stromberg b9e0ad34a3
Post-Thanksgiving false positive flush 2022-11-28 16:06:07 -05:00
Thomas Stromberg 6a7c4b6668
Pre-Thanksgiving False Positive cleanup, including Pop!OS support 2022-11-22 09:21:03 -05:00
Thomas Stromberg 18f17bbee8
Complete cleanup phase 1 2022-11-16 11:18:45 -05:00
Thomas Stromberg e7e714c9db
Make another stab at reducing false positives across the map 2022-11-03 11:51:54 -04:00
Thomas Stromberg 3d75593c76
Add exceptions for Jetbrains/Delve, more for Steam 2022-10-30 12:00:43 -04:00
Thomas Stromberg a00af6c1fa
Merge another day worth of false positives 2022-10-27 10:23:15 -04:00
Thomas Stromberg 770496edea
dev opener: Add bluetoothd 2022-10-21 11:27:42 -04:00
Thomas Stromberg ab94de7770
Add a lot more mitre data 2022-10-19 16:56:32 -04:00
Thomas Stromberg 9bf85e3137
Flush out more false positives 2022-10-17 20:37:44 -04:00
Thomas Stromberg 2b5ea76729
Apply 'npx sql-formatter -l sqlite' 2022-10-17 19:06:17 -04:00
Thomas Stromberg 984f754990
Add more false positive filters 2022-10-17 19:01:16 -04:00