osquery-defense-kit/detection/execution
2022-10-11 21:53:36 -04:00
..
exotic-cmdline.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
exotic-command-events.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
recently-created-executables.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
reverse-shell-socket.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
sketchy-fetcher-events.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
sketchy-fetcher.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
tiny-executable-events.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
tiny-executable.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-env-values.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-execdir-events-linux.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-execdir-events-macos.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-executable-directory-linux.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-executable-directory-macos.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-executable-permissions.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-gatekeeper-approvals-macos.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-mounts.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-osascript-calls.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-raw-socket.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-setuid-binaries.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
unexpected-tmp-executables.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00
xprotect-reports.sql Initial re-organization around the MITRE ATT&CK framework 2022-10-11 21:53:36 -04:00