osquery-defense-kit/detection/execution
Thomas Stromberg 10a7091e62
Decrease exotic-events complexity by splitting & simplifying
2022-10-13 18:31:59 -04:00
..
exotic-cmdline.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
exotic-command-events-linux.sql Decrease exotic-events complexity by splitting & simplifying 2022-10-13 18:31:59 -04:00
exotic-command-events-macos.sql Decrease exotic-events complexity by splitting & simplifying 2022-10-13 18:31:59 -04:00
recently-created-executables.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
reverse-shell-socket.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
sketchy-fetcher-events.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
sketchy-fetcher.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
tiny-executable-events.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
tiny-executable.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-env-values.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-execdir-events-linux.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-execdir-events-macos.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-executable-directory-linux.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-executable-directory-macos.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-executable-permissions.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-gatekeeper-approvals-macos.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-mounts.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-osascript-calls.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-raw-socket.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-setuid-binaries.sql Migrate query strings from double to single apostrophes 2022-10-13 14:59:32 -04:00
unexpected-tmp-executables.sql Add markupsafe exception 2022-10-13 18:16:12 -04:00
xprotect-reports.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00