osquery-defense-kit/detection/privesc
Thomas Stromberg 4df51743d0
fpr: lima, rpm-ostree, gitsign, kde, python, etc
2024-07-01 21:56:28 -04:00
..
docker-container-mounting-root.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
setxid-cmdline-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
setxid-env-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
sketchy-docker-image-creator.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-elevated-children-events_linux.sql Remove file sizes from systemd exception key 2023-06-08 18:26:57 -04:00
unexpected-elevated-children-events_macos.sql fpr: Slack, Gnome, Sigstore, Logitune, etc 2023-06-12 10:10:57 -04:00
unexpected-privilege-escalation_linux.sql fpr: Docker Desktop, code-oss, incus, etc 2024-02-26 17:26:56 -05:00
unexpected-privilege-escalation_macos.sql Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
unexpected-privileged-containers.sql fpr: lima, rpm-ostree, gitsign, kde, python, etc 2024-07-01 21:56:28 -04:00
unexpected-setxid-process.sql massive fpr: Rapid7, Elastic, everything 2024-01-26 14:07:37 -05:00