osquery-defense-kit/detection/initial_access
Thomas Stromberg 00a9f6450b
fpr: sddm-helper, smartd, Xorg, elastic, WebEx, BambuStudio, keepass, etc
2024-07-26 13:26:37 -04:00
..
sketchy-download-name.sql
sketchy-mounted-diskimage.sql fpr: lima, rpm-ostree, gitsign, kde, python, etc 2024-07-01 21:56:28 -04:00
unexpected-diskimage-name-macos.sql
unexpected-diskimage-source-macos.sql More SilverBlue/Elastic allows 2024-05-23 21:22:59 -04:00
unexpected-shell-parent-events.sql fpr: kas, bitnami, redis, bincapz, kolide, docker, whatsapp 2024-07-12 16:55:49 -04:00
unexpected-shell-parents.sql fpr: sddm-helper, smartd, Xorg, elastic, WebEx, BambuStudio, keepass, etc 2024-07-26 13:26:37 -04:00
unexpected-volume-contents.sql
unexpected-webmail-downloads.sql
yara-recently-downloaded-miner.sql fpr: MHLink, k3d, BlueFin, query tuning 2024-04-26 16:14:02 -04:00
yara-recently-downloaded-ransom.sql fpr: MHLink, k3d, BlueFin, query tuning 2024-04-26 16:14:02 -04:00
yara-recently-downloaded-stealer.sql fpr: MHLink, k3d, BlueFin, query tuning 2024-04-26 16:14:02 -04:00