Commit Graph

199 Commits

Author SHA1 Message Date
Thomas Stromberg
76cf1006c6
fpr: microbit, i3, Grammarly for Safari, wine 2023-05-02 17:49:53 -04:00
Thomas Stromberg
47124daa01
fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
Thomas Stromberg
1961531adf
fpr: more refactor fallout 2023-04-28 14:40:12 -04:00
Thomas Stromberg
fbdd253d6a
fpr: post-refactor talker reduction 2023-04-28 14:09:57 -04:00
Thomas Stromberg
ef7b7e7fa1
new detector: hidden ~/Library/Application Support 2023-04-27 15:07:49 -04:00
Thomas Stromberg
02337c28f0
fpr: cleanup and new additions 2023-04-27 12:00:08 -04:00
Thomas Stromberg
df925eaa6c
fpr: lghub, brew, pve, chrome exts, etc 2023-04-20 20:45:35 -04:00
Thomas Stromberg
9c3f783491 fpr everything 2023-04-17 16:20:35 -04:00
Thomas Stromberg
0dc6748dff fpr: LGHUB keys, go, Acrobat, code, yum, fwupdatemgr 2023-03-31 06:19:30 -04:00
Thomas Stromberg
d4dd423745
fpr: Grammarly, semodule, docker-compose, xdg, etc 2023-03-30 18:44:01 -04:00
Thomas Stromberg
eceb9c5dec
Mask all descendants of .github/ 2023-03-28 17:02:01 -04:00
Thomas Stromberg
9b0ed09c8e
fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage 2023-03-28 16:25:26 -04:00
Thomas Stromberg
570c36dc71
fpr: tilt, electron, cilium, write/read improvements 2023-03-24 10:42:06 -04:00
Thomas Stromberg
7a78199906
fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
Thomas Stromberg
fbab3701c0
fpr: Docker, Zwift, macOS updates, etc 2023-03-20 17:05:02 -04:00
Thomas Stromberg
6ddc478df4
fpr: Brother, Intel OneAPI, k6, firefox 2023-03-17 15:08:22 -04:00
Thomas Stromberg
fbc2b207b4
fpr: Signal, apko, aws, melange, dash, stern 2023-03-16 17:29:11 -04:00
Thomas Stromberg
824efa9705
fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws 2023-03-14 19:00:44 -04:00
Thomas Stromberg
09652bd91f
fpr: SA keys, libgtop, haproxy, gvproxy, slirp 2023-03-14 16:05:16 -04:00
Thomas Strömberg
2f16dda2a7
Merge pull request #217 from tstromberg/mismatch
Rewrite name/path mismatch for lower maintenance
2023-03-14 15:25:24 -04:00
Thomas Stromberg
0c03324296
Reduce fuziness of matching 2023-03-14 15:11:33 -04:00
Thomas Stromberg
e23b34dc7b
Rewrite name/path mismatch for lower maintenance 2023-03-09 21:11:24 -05:00
Thomas Stromberg
b3825ba2b9
fpr: Canon Universal Installer, melange, GPG, key names 2023-03-06 15:11:11 -05:00
Thomas Stromberg
81b09ae711
fpr: aws certs, AdobePIM, slack 2023-03-04 12:20:53 -05:00
Thomas Stromberg
f25cfe1399
fpr: aws-sdk, melange, Tailscale, Xprotect, etc 2023-03-03 07:24:42 -05:00
Thomas Stromberg
fb7cd56249
fpr: abrt-dbus, gdm, chrome, ff, etc 2023-02-24 16:30:17 -05:00
Thomas Stromberg
995c1e1104
Fixes so that ODK can run under CI 2023-02-24 12:15:56 -05:00
Thomas Stromberg
a7c2ef97e1
Add detectors for the reveng_rtkit rootkit 2023-02-23 17:05:11 -05:00
Thomas Stromberg
d904ca60cf
Add exceptions for Debian running under lima 2023-02-23 10:33:10 -05:00
Thomas Stromberg
d3780c0a6c
Remove ubuntu-lts false-positives on lima 2023-02-20 19:10:12 -05:00
Ian Brown
551d7dbb8c
fpr: Fujitsu, vmware, objective-see, paragon, etc
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 12:02:40 -08:00
Thomas Stromberg
5949ad1551
overwritten memory: filter out pathless kernel bits 2023-02-17 17:20:20 -05:00
Thomas Stromberg
504ef2c8dd
gcloud: filter out last_update_check, last_survey_prompt 2023-02-17 12:03:36 -05:00
Thomas Stromberg
f87541c945
False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
Thomas Strömberg
8976bfecf2
Merge pull request #179 from tstromberg/ddexec
New detector: overwritten memory map
2023-02-17 10:49:57 -05:00
Thomas Stromberg
2e95606d9c
New detector: overwritten memory map 2023-02-17 10:49:19 -05:00
Thomas Stromberg
a655122eec
name path mismatch: only whitelist shells with same cmdlines 2023-02-17 10:47:49 -05:00
Thomas Stromberg
3d13d4995a
hidden system paths: include inode 2023-02-17 10:41:42 -05:00
Thomas Stromberg
cf858d193d
fpr: ACE, Prusa, steam, pacman, Xcode, Adobe 2023-02-14 20:16:02 -05:00
Thomas Stromberg
8d4531198f
fpr: My ORA, Ecamm, setroubleshootd, etc 2023-02-14 19:46:36 -05:00
Thomas Stromberg
d897f0b50d
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
Thomas Stromberg
4f4ae0ed38
False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
Thomas Stromberg
593991adb8
Purge observed false positives 2023-02-09 17:54:41 -05:00
Thomas Stromberg
a8ed058d4d
Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
Thomas Strömberg
ca316a0420
Merge pull request #166 from tstromberg/fpr-catch-up
Add exclusions for google-cloud-sdk & Blackmagic firmware
2023-02-08 20:55:53 -05:00
Thomas Strömberg
eef833287a
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
2023-02-08 20:54:45 -05:00
Thomas Stromberg
209a5e08af
Add /Library/ThunderboltAcessoryFirmwareUpdates 2023-02-08 20:53:39 -05:00
Thomas Stromberg
3eb2c80d92
Add kubectl from google-cloud-sdk 2023-02-08 20:53:03 -05:00
Thomas Stromberg
72326c3b5c
Massive reduction of false positives across the board 2023-02-08 20:06:26 -05:00
Thomas Stromberg
51151290fb
Refactor unexpected tmp executables for speed & decreased hits 2023-02-08 20:06:10 -05:00