Commit Graph

247 Commits

Author SHA1 Message Date
Thomas Stromberg
d5a94b21d1 fpr: Kolide, macOS, nvidia, neko 2023-05-16 10:28:19 -04:00
Thomas Stromberg
9c87838b9f
fpr: Chrome, Kolide 2023-05-12 16:41:17 -04:00
Thomas Stromberg
26b2b9a4c7
fpr: LGHUB, aomshm, Wisdolia, uubyte, eclipse, etc 2023-05-11 11:29:55 -04:00
Thomas Stromberg
41d83350a1
make reformat 2023-05-08 13:20:47 -04:00
Thomas Stromberg
778d53b169
Address merge conflicts 2023-05-08 13:11:24 -04:00
Thomas Stromberg
4856a0e80a
fpr: LogiTune, sharingd, gnome, sparkle, plex 2023-05-08 13:07:57 -04:00
Thomas Stromberg
785b7c2bde
fpr: LogiTune, EndeavourOS, less 2023-05-08 12:19:19 -04:00
Thomas Stromberg
9eed574026
fpr: sharingd, sparkle, golang, Snagit 2023-05-05 15:10:54 -04:00
Thomas Stromberg
61d503db0e
Add Zed binaries dir 2023-05-05 12:55:14 -04:00
Thomas Stromberg
272711ae7a
fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00
Thomas Stromberg
f3fd822a55
Refactor recently-created-executables to fit within complexity limits 2023-05-03 17:57:58 -04:00
Thomas Stromberg
0202e87b73
fpr: libopenblas, snapd, k3d, opera, nix, ssh, cargo, adobe installer 2023-05-03 16:28:00 -04:00
Thomas Stromberg
cc221ae011
sysutils: Add /usr/bin/security (Keychain) 2023-05-03 15:53:33 -04:00
Thomas Stromberg
76cf1006c6
fpr: microbit, i3, Grammarly for Safari, wine 2023-05-02 17:49:53 -04:00
Thomas Stromberg
47124daa01
fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
Thomas Stromberg
1961531adf
fpr: more refactor fallout 2023-04-28 14:40:12 -04:00
Thomas Stromberg
fbdd253d6a
fpr: post-refactor talker reduction 2023-04-28 14:09:57 -04:00
Thomas Stromberg
02337c28f0
fpr: cleanup and new additions 2023-04-27 12:00:08 -04:00
Thomas Stromberg
df925eaa6c
fpr: lghub, brew, pve, chrome exts, etc 2023-04-20 20:45:35 -04:00
Thomas Stromberg
9c3f783491 fpr everything 2023-04-17 16:20:35 -04:00
Thomas Stromberg
0dc6748dff fpr: LGHUB keys, go, Acrobat, code, yum, fwupdatemgr 2023-03-31 06:19:30 -04:00
Thomas Stromberg
d4dd423745
fpr: Grammarly, semodule, docker-compose, xdg, etc 2023-03-30 18:44:01 -04:00
Thomas Stromberg
5ea01eabeb
Exclude .rustup toolchains 2023-03-28 17:02:30 -04:00
Thomas Stromberg
2d6ced6ae5
Remove powershell indicator 2023-03-28 17:02:14 -04:00
Thomas Stromberg
9b0ed09c8e
fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage 2023-03-28 16:25:26 -04:00
Thomas Stromberg
284796b895
fpr: snyk-ls, electron 2023-03-24 11:03:55 -04:00
Thomas Stromberg
570c36dc71
fpr: tilt, electron, cilium, write/read improvements 2023-03-24 10:42:06 -04:00
Thomas Stromberg
7a78199906
fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
Thomas Stromberg
fbab3701c0
fpr: Docker, Zwift, macOS updates, etc 2023-03-20 17:05:02 -04:00
Thomas Strömberg
621967a085
Merge pull request #230 from tstromberg/split-chmod
Add exceptions for Kandji
2023-03-17 15:49:30 -04:00
Thomas Stromberg
13a95a4f41
Add exceptions for Kandji 2023-03-17 15:46:00 -04:00
Thomas Strömberg
1b9e2a6ec1
Merge pull request #229 from tstromberg/split-chmod
unexpected-chmod-exec: Split and Linux/macOS queries
2023-03-17 15:39:26 -04:00
Thomas Stromberg
15c666a170
Fix references to p0.cmdline 2023-03-17 15:38:22 -04:00
Thomas Stromberg
e1db6fc2de
Fix split chmod detector 2023-03-17 15:19:33 -04:00
Thomas Stromberg
feb7c234e7
split unexpected-chmod-exec-event into Linux/macOS 2023-03-17 15:13:36 -04:00
Thomas Stromberg
6ddc478df4
fpr: Brother, Intel OneAPI, k6, firefox 2023-03-17 15:08:22 -04:00
Thomas Stromberg
fb6af4858a
chmod events: broaden snap exception 2023-03-17 10:52:28 -04:00
Thomas Stromberg
2bfd736d37
Use p0_cmd instead of p0.cmdline 2023-03-17 06:37:18 -04:00
Thomas Stromberg
7ceb7b2b19
fpr: NetworkManager, packer, rancher desktop, proxmox, sd 2023-03-17 06:32:54 -04:00
Thomas Stromberg
8154560703
chmod events: Include macOS, improve results 2023-03-17 06:24:26 -04:00
Thomas Stromberg
fbc2b207b4
fpr: Signal, apko, aws, melange, dash, stern 2023-03-16 17:29:11 -04:00
Thomas Stromberg
af9a78236e
New detector: unexpected chmod exec event 2023-03-16 16:53:32 -04:00
Thomas Stromberg
824efa9705
fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws 2023-03-14 19:00:44 -04:00
Thomas Stromberg
09652bd91f
fpr: SA keys, libgtop, haproxy, gvproxy, slirp 2023-03-14 16:05:16 -04:00
Thomas Stromberg
b3825ba2b9
fpr: Canon Universal Installer, melange, GPG, key names 2023-03-06 15:11:11 -05:00
Thomas Stromberg
f25cfe1399
fpr: aws-sdk, melange, Tailscale, Xprotect, etc 2023-03-03 07:24:42 -05:00
Thomas Stromberg
12a5507907
Optimize recently-created-executables-macos 2023-02-24 17:24:09 -05:00
Thomas Stromberg
4150b1ee7c
macOS: Exceptions for TestFlight apps & specifically Kindle 2023-02-24 17:04:34 -05:00
Thomas Stromberg
fb7cd56249
fpr: abrt-dbus, gdm, chrome, ff, etc 2023-02-24 16:30:17 -05:00
Thomas Stromberg
995c1e1104
Fixes so that ODK can run under CI 2023-02-24 12:15:56 -05:00