osquery-defense-kit/detection
2023-12-15 17:19:38 -05:00
..
c2 fpr: kind of everything 2023-12-15 17:10:06 -05:00
collection fpr: Capture One, Grammarly, Mullvad, etc 2023-12-08 17:12:27 -05:00
credentials fpr: Kolide, qemu, bash, monday, macOS 2023-10-24 18:01:36 -04:00
discovery fpr: RSA keys, tcpdump, login, crane, souregraph, etc 2023-09-20 09:30:46 -04:00
evasion Ignore syncthing, nuclei, fix typos 2023-12-15 17:19:38 -05:00
execution Ignore syncthing, nuclei, fix typos 2023-12-15 17:19:38 -05:00
exfil filter out CSV from yara 2023-12-15 17:12:50 -05:00
impact fpr: Capture One, Grammarly, Mullvad, etc 2023-12-08 17:12:27 -05:00
initial_access filter out CSV from yara 2023-12-15 17:12:50 -05:00
persistence Ignore syncthing, nuclei, fix typos 2023-12-15 17:19:38 -05:00
privesc fpr: sourcegraph, nginx, factorio, fan control, emacs, nushell 2023-09-14 17:13:12 -04:00