Thomas Stromberg
|
7455c22e3c
|
Fix missing /
|
2023-01-06 10:19:33 -05:00 |
|
Thomas Stromberg
|
9843def319
|
Fix more false positives, particularly in shell/fetcher parents
|
2023-01-06 10:18:19 -05:00 |
|
Thomas Strömberg
|
3db3559a7f
|
Merge pull request #108 from tstromberg/shell-parent-events
new detectors: unexpected shell & fetcher events
|
2023-01-04 15:49:36 -05:00 |
|
Thomas Stromberg
|
02881f7a0c
|
Remove empty line
|
2023-01-04 15:49:21 -05:00 |
|
Thomas Stromberg
|
9c512c5fd7
|
new detector: unexpected fetcher parents
|
2023-01-04 15:48:13 -05:00 |
|
Thomas Stromberg
|
1dbd98c57e
|
Add enough exceptions to make this useful
|
2023-01-04 11:58:54 -05:00 |
|
Thomas Stromberg
|
0ad0b3be8c
|
detection/initial_access/unexpected-shell-parent-events.sql
new detector: unexpected shell parent events
|
2023-01-04 11:43:26 -05:00 |
|
Thomas Strömberg
|
88e0e5fb57
|
Merge pull request #107 from tstromberg/root-signers
new detector: unexpected root process signer on macOS
|
2023-01-04 11:20:27 -05:00 |
|
Thomas Stromberg
|
64ed2bba02
|
new detector: software running as root on macOS with an unexpected authority
|
2023-01-04 11:19:44 -05:00 |
|
Thomas Strömberg
|
6f160c686d
|
Merge pull request #106 from tstromberg/relative-exec
New detector: relative exec low uid
|
2023-01-04 11:15:09 -05:00 |
|
Thomas Stromberg
|
ef3653216e
|
New detector: relative exec low uid
|
2023-01-04 11:14:04 -05:00 |
|
Thomas Strömberg
|
8c35d9c14a
|
Merge pull request #105 from tstromberg/bmw-of-greensboro
Catch up to other winter-break false positives
|
2023-01-04 11:09:59 -05:00 |
|
Thomas Stromberg
|
5735d87453
|
Add execdir exception for ~/%packages
|
2023-01-04 11:09:20 -05:00 |
|
Thomas Stromberg
|
71cda72dc1
|
Add exception for dmesg reading /dev/kmsg
|
2023-01-04 11:08:05 -05:00 |
|
Thomas Stromberg
|
aa7d9d21f7
|
Fix firefox typo
|
2023-01-04 11:05:03 -05:00 |
|
Thomas Stromberg
|
ba23df1fef
|
Catch up to other false positives over winter break
|
2023-01-04 11:03:38 -05:00 |
|
Thomas Strömberg
|
12acae7250
|
Merge pull request #104 from tstromberg/new-years
New Years FP cleanup: monitorix, snap-confine, steam, spotify, etc
|
2023-01-03 08:50:59 -05:00 |
|
Thomas Stromberg
|
a8b95a2c9e
|
New Years cleanup: monitorix, snap-confine, steam, spotify, etc
|
2023-01-03 08:50:19 -05:00 |
|
Thomas Strömberg
|
fd2b240344
|
Merge pull request #103 from tstromberg/sketchy-fetcher-refactor
sketchy fetchers: Remove trailing commas
|
2022-12-20 08:03:54 -05:00 |
|
Thomas Stromberg
|
44ca59c9d6
|
sketchy fetchers: Remove trailing commas
|
2022-12-20 08:03:14 -05:00 |
|
Thomas Strömberg
|
a6a8c28448
|
Merge pull request #102 from tstromberg/sketchy-fetcher-refactor
sketchy fetcher: Add grandparents and TLD detector
|
2022-12-20 07:54:17 -05:00 |
|
Thomas Strömberg
|
45cbb3e731
|
Merge pull request #101 from tstromberg/parent-missing
parent-missing-from-disk: Filter out Docker children too
|
2022-12-20 07:54:10 -05:00 |
|
Thomas Strömberg
|
ddd238e4de
|
Merge pull request #100 from tstromberg/k3s
Add k3s /dev/kmsg exception, add parent info
|
2022-12-20 07:54:03 -05:00 |
|
Thomas Stromberg
|
40c20825e6
|
sketchy fetcher: Add grandparents and TLD detector
|
2022-12-20 07:53:29 -05:00 |
|
Thomas Stromberg
|
6ca3d92243
|
Filter out Docker children too
|
2022-12-20 07:52:04 -05:00 |
|
Thomas Stromberg
|
350b0d8970
|
Add k3s /dev/kmsg exception, add parent info
|
2022-12-20 07:51:29 -05:00 |
|
Thomas Strömberg
|
06e5d15e72
|
Merge pull request #99 from tstromberg/dec19
False-positive flush: mount.ntfs, docker-credential-desktop, exotic s…
|
2022-12-19 18:06:37 -05:00 |
|
Thomas Stromberg
|
15d3251120
|
False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor
|
2022-12-19 18:06:06 -05:00 |
|
Thomas Strömberg
|
a3fcc44e08
|
Merge pull request #98 from tstromberg/dec15
Sort out more false positives
|
2022-12-16 17:38:12 -05:00 |
|
Thomas Stromberg
|
49a19a6fd5
|
Sort out more false positives
|
2022-12-16 17:37:32 -05:00 |
|
Thomas Strömberg
|
0522965140
|
Merge pull request #97 from tstromberg/dec15
False positive flush: Capital One, tailscaled, agetty, snap, Jetbrains
|
2022-12-16 08:24:01 -05:00 |
|
Thomas Stromberg
|
404adf3e1f
|
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc
|
2022-12-15 16:51:58 -05:00 |
|
Thomas Stromberg
|
0b8a67a48f
|
Add exception for JetBrains Toolbox
|
2022-12-15 10:25:35 -05:00 |
|
Thomas Strömberg
|
26a800d52b
|
Merge pull request #96 from tstromberg/dec15
Clear more false positives: Signal, Kitty, KIND, Acrobat, etc
|
2022-12-15 10:21:49 -05:00 |
|
Thomas Stromberg
|
16f9b2f3ee
|
Remove more false positives: kind, gopls, docker.socket, etc
|
2022-12-15 10:20:16 -05:00 |
|
Thomas Stromberg
|
60e5435ed4
|
Allow mount-product-files and / (bad data), add cgroup_path
|
2022-12-15 09:20:41 -05:00 |
|
Thomas Stromberg
|
47b208eb71
|
Allow gcloud auth application-default login
|
2022-12-15 09:12:30 -05:00 |
|
Thomas Stromberg
|
685a79d3e1
|
Add Vimium
|
2022-12-15 09:11:14 -05:00 |
|
Thomas Stromberg
|
2731759d9b
|
Add Signal Helper
|
2022-12-15 09:07:11 -05:00 |
|
Thomas Stromberg
|
76d5c8564b
|
Resolve latest reported false positives
|
2022-12-02 11:20:18 -05:00 |
|
Thomas Strömberg
|
b40eb32d0f
|
Merge pull request #95 from tstromberg/post-tgiving
Post-Thanksgiving false positive flush
|
2022-11-28 16:08:37 -05:00 |
|
Thomas Stromberg
|
b9e0ad34a3
|
Post-Thanksgiving false positive flush
|
2022-11-28 16:06:07 -05:00 |
|
Thomas Strömberg
|
7e038c7e2a
|
Merge pull request #94 from tstromberg/makefile-fixes
Add IR no-wifi ruleset
|
2022-11-23 07:33:39 -05:00 |
|
Thomas Stromberg
|
09962c8dca
|
Add IR no-wifi ruleset
|
2022-11-23 07:32:52 -05:00 |
|
Thomas Strömberg
|
f99109d962
|
Merge pull request #93 from tstromberg/makefile-fixes
Makefile: Rename .sql targets to .conf, extend max-duration for IR
|
2022-11-23 07:15:17 -05:00 |
|
Thomas Stromberg
|
724e2fbc84
|
Makefile: Rename .sql targets to .conf, extend max-duration for IR
|
2022-11-23 07:14:53 -05:00 |
|
Thomas Strömberg
|
9e0e618070
|
Merge pull request #92 from tstromberg/pre-turkey-day
Split parent-missing-from-disk, add more explicit name to long-uptime, address fps
|
2022-11-23 07:12:21 -05:00 |
|
Thomas Stromberg
|
546d1367eb
|
Rename unusually-long-uptime
|
2022-11-23 07:10:41 -05:00 |
|
Thomas Stromberg
|
39e9aee6eb
|
Split parent-missing-from-disk, address false positives
|
2022-11-23 07:10:03 -05:00 |
|
Thomas Strömberg
|
9e321d022b
|
Merge pull request #91 from tstromberg/pre-turkey-day
Pre-Thanksgiving False Positive cleanup, including Pop!OS support
|
2022-11-22 16:35:26 -05:00 |
|