osquery-defense-kit/detection
Thomas Stromberg 99f8793169
Remove com.docker.backend (macOS specific)
2023-02-10 10:32:14 -05:00
..
c2 Purge observed false positives 2023-02-09 17:54:41 -05:00
collection Massive reduction of false positives across the board 2023-02-08 20:06:26 -05:00
credentials Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
discovery Purge observed false positives 2023-02-09 17:54:41 -05:00
evasion False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
execution Increase polling interval to 15 min 2023-02-10 10:24:20 -05:00
exfil fpr: New Chrome etxensions, vbox, chrome, gcloud, gdm3, yay, etc 2023-01-30 14:58:47 -05:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
persistence Remove com.docker.backend (macOS specific) 2023-02-10 10:32:14 -05:00
privesc Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00