Thomas Stromberg
|
593991adb8
|
Purge observed false positives
|
2023-02-09 17:54:41 -05:00 |
|
Thomas Strömberg
|
eef833287a
|
Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility
Modified detections explicitly targeted towards macOS to not include cgroup field
|
2023-02-08 20:54:45 -05:00 |
|
echunduri
|
e44dc167e9
|
Modified detections explicilty targeted towards macOS to not include cgroup_path fields anymore
|
2023-02-09 10:57:03 +11:00 |
|
Thomas Stromberg
|
e57f03b89f
|
fpr: Opera, TextExpander, socket_vmnet, elive, etc
|
2023-02-08 15:12:10 -05:00 |
|
Thomas Stromberg
|
2634e9d45b
|
Monday morning false-positive purge
|
2023-02-08 14:37:09 -05:00 |
|
Thomas Stromberg
|
2093a26423
|
Fix broken macOS queries
|
2023-02-02 15:33:25 -05:00 |
|
Thomas Stromberg
|
8e3d6a1614
|
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc
|
2022-11-18 10:27:43 -05:00 |
|
Thomas Stromberg
|
f2023c0021
|
Update interval tags, mostly for persistence
|
2022-10-14 14:26:49 -04:00 |
|
Thomas Stromberg
|
d2bdffe89e
|
Add support for interval tags
|
2022-10-14 14:19:13 -04:00 |
|
Thomas Stromberg
|
20452b128b
|
Migrate query strings from double to single apostrophes
|
2022-10-13 14:59:32 -04:00 |
|
Thomas Stromberg
|
26ee658c4a
|
Initial re-organization around the MITRE ATT&CK framework
|
2022-10-11 21:53:36 -04:00 |
|