osquery-defense-kit/detection/credentials
2025-05-06 08:09:52 -04:00
..
1-unexpected-dev-opener-linux.sql fpr: lima, git, firefox, vmware 2025-05-06 08:09:52 -04:00
1-unexpected-dev-opener-macos.sql fpr: datadog, nordvpn, claude, minecraftlauncher, eksctl 2025-02-25 16:53:31 -05:00
2-macos_keyboard_sniffer.sql fpr: DDPM, nwg-bar, diskimage domains, touched exec 2025-02-24 13:54:45 -05:00
2-unexpected-sensitive-file-access-linux.sql add 1-3 (low,medium,high) prefix to alert names 2025-02-19 10:47:16 -05:00
2-unexpected-sensitive-file-access-macos.sql add 1-3 (low,medium,high) prefix to alert names 2025-02-19 10:47:16 -05:00
3-yara-mounted-stealer.sql fpr: iris, go, solaar, surfshark, ubuntu, geocomply, etc 2025-04-21 21:40:24 -04:00