osquery-defense-kit/process
Thomas Stromberg 007332ead4
More false positives removal
2022-09-29 16:19:30 -04:00
..
empty_environ.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
exotic-cmdline.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
hidden-cwd.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
hidden-parent-pid.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
high-disk-bytes-written.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
high_disk_bytes_read.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
low_start_time_ctime_delta.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
missing-from-disk-linux.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
missing-from-disk-macos.sql Be more leniant with lack-of-info filter 2022-09-29 12:29:55 -04:00
name_path_mismatch.sql More false-positive removal 2022-09-27 11:54:17 -04:00
old-binaries-running.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
parent-missing-from-disk.sql More false positives removal 2022-09-29 16:19:30 -04:00
reverse-shell-socket.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
sketchy-fetcher.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
unexpected-env-values.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
unexpected-executable-directory.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
unexpected-executable-permissions.sql Remove numerous false positives 2022-09-26 18:27:43 -04:00
unexpected-privilege-escalation.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
unexpected-shell-parents.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
unexpected-uid0-daemon-linux.sql Add experimental queries for daemon detection 2022-09-29 16:04:07 -04:00
unexpected-uid0-daemon-macos.sql Add experimental queries for daemon detection 2022-09-29 16:04:07 -04:00