Commit Graph

45 Commits

Author SHA1 Message Date
Thomas Stromberg a8b95a2c9e
New Years cleanup: monitorix, snap-confine, steam, spotify, etc 2023-01-03 08:50:19 -05:00
Thomas Stromberg 15d3251120
False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
Thomas Stromberg 49a19a6fd5
Sort out more false positives 2022-12-16 17:37:32 -05:00
Thomas Stromberg 404adf3e1f
Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
Thomas Stromberg 16f9b2f3ee
Remove more false positives: kind, gopls, docker.socket, etc 2022-12-15 10:20:16 -05:00
Thomas Stromberg 685a79d3e1
Add Vimium 2022-12-15 09:11:14 -05:00
Thomas Stromberg b9e0ad34a3
Post-Thanksgiving false positive flush 2022-11-28 16:06:07 -05:00
Thomas Stromberg 6a7c4b6668
Pre-Thanksgiving False Positive cleanup, including Pop!OS support 2022-11-22 09:21:03 -05:00
Thomas Stromberg 8e3d6a1614
False positives: melange, ~/dev, debian-sa1, AdBlock, cover, kubelr, etc 2022-11-18 10:27:43 -05:00
Thomas Stromberg 9f63e3b21d
Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
Thomas Stromberg 3d7bc8363e
More false positive management 2022-11-16 14:49:36 -05:00
Thomas Stromberg 18f17bbee8
Complete cleanup phase 1 2022-11-16 11:18:45 -05:00
Thomas Stromberg 8047c88374
Run 'make reformat' 2022-11-16 11:02:29 -05:00
Thomas Stromberg 398cbde41f
Add more exception for local webhook development 2022-11-16 10:40:46 -05:00
Thomas Stromberg f36b74c487
Fix ko-app allowance 2022-11-16 10:38:22 -05:00
Thomas Stromberg 7527e11a3b
Add systemd-fsckd, blueman-mechanism 2022-11-16 10:37:38 -05:00
Thomas Stromberg f1a3354495
Address false positives: nginx-ingress-controller, dbus, etc 2022-11-10 11:04:48 -05:00
Thomas Stromberg f93a18d112
Refactor execdir, remove false positives 2022-11-07 20:36:37 -05:00
Thomas Stromberg 213e29afcc
Simplify macos-execdir, reduce false positives 2022-11-07 10:03:43 -05:00
Thomas Stromberg 4bf5be2960
Add exception for Wireshark usbmon 2022-11-04 11:52:52 -04:00
Thomas Stromberg b3fdde9ed7
Add PlayTo for Chromecast 2022-11-04 08:11:33 -04:00
Thomas Stromberg e7e714c9db
Make another stab at reducing false positives across the map 2022-11-03 11:51:54 -04:00
Thomas Stromberg caab2a6c82
Loads of fresh new false-positives removal 2022-10-31 17:40:37 -04:00
Thomas Stromberg 6c78695b73
Final KubeCon 2022 false-positive cleanup 2022-10-28 19:24:00 -04:00
Thomas Stromberg 897c96bd33
Remove more in-the-wild false positives 2022-10-27 16:55:00 -04:00
Thomas Stromberg a00af6c1fa
Merge another day worth of false positives 2022-10-27 10:23:15 -04:00
Thomas Stromberg 23351973ea
detection: Reduce Linux desktop false positives 2022-10-25 11:39:51 -04:00
Thomas Stromberg 2f7e76d23c
Add exception for User-Agent Switcher 2022-10-24 11:09:07 -04:00
Thomas Stromberg 9f2423a51e
Add exception for Fumihiko Takayama (Karabiner-Elements) 2022-10-21 11:50:52 -04:00
Thomas Stromberg ffead2f717
Add Google Chat, Youtube, Bardeen, Leadjet 2022-10-21 11:49:54 -04:00
Thomas Stromberg f6317c2af8
Further reduction of false positives 2022-10-19 17:07:52 -04:00
Thomas Stromberg ab94de7770
Add a lot more mitre data 2022-10-19 16:56:32 -04:00
Thomas Stromberg 61294aa8a8
Add dnf 2022-10-19 14:51:33 -04:00
Thomas Stromberg 9bf85e3137
Flush out more false positives 2022-10-17 20:37:44 -04:00
Thomas Stromberg 2b5ea76729
Apply 'npx sql-formatter -l sqlite' 2022-10-17 19:06:17 -04:00
Thomas Stromberg 984f754990
Add more false positive filters 2022-10-17 19:01:16 -04:00
Thomas Stromberg f2023c0021
Update interval tags, mostly for persistence 2022-10-14 14:26:49 -04:00
Thomas Stromberg d2bdffe89e
Add support for interval tags 2022-10-14 14:19:13 -04:00
Thomas Stromberg b9a64e8b99
Janitorial maintenance 2022-10-14 10:18:01 -04:00
Thomas Stromberg b2f0c1ca54
Add kernel modules seen on Fedora 2022-10-14 09:30:44 -04:00
Thomas Stromberg d6ae20a73e
Add ipheth, resort. 2022-10-13 18:14:50 -04:00
Thomas Stromberg 9bbc043953
Add CoLab, remove trailing spaces 2022-10-13 18:05:05 -04:00
Thomas Stromberg 077c8f36fc
Filter out vaikas dev hostnames 2022-10-13 17:58:29 -04:00
Thomas Stromberg 20452b128b
Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
Thomas Stromberg 26ee658c4a
Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00