osquery-defense-kit/detection/privesc
egibs a24c3d2333
Add exceptions for Autodesk, cloud_sql_proxy, .md downloads, TF providers in /tmp/, and more
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
2024-11-20 13:45:50 -06:00
..
docker-container-mounting-root.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
setxid-cmdline-overflow-attempt.sql add extra tag to setxid-cmdline-overflow-attempt.sql 2024-10-24 18:42:46 -04:00
setxid-env-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
sketchy-docker-image-creator.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-elevated-children-events_linux.sql Remove file sizes from systemd exception key 2023-06-08 18:26:57 -04:00
unexpected-elevated-children-events_macos.sql fpr: Slack, Gnome, Sigstore, Logitune, etc 2023-06-12 10:10:57 -04:00
unexpected-privilege-escalation_linux.sql fpr: Docker Desktop, code-oss, incus, etc 2024-02-26 17:26:56 -05:00
unexpected-privilege-escalation_macos.sql Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
unexpected-privileged-containers.sql fpr: kubectl, zoom, /opt, chrome, Autodesk Fusion 2024-10-25 11:29:40 -04:00
unexpected-setxid-process.sql Add exceptions for Autodesk, cloud_sql_proxy, .md downloads, TF providers in /tmp/, and more 2024-11-20 13:45:50 -06:00