osquery-defense-kit/detection
Dave Smith 76357a17f0 small fpr push: chainlink, spotify, pycharm, and goland 2024-11-22 08:45:03 -05:00
..
c2 small fpr push: chainlink, spotify, pycharm, and goland 2024-11-22 08:45:03 -05:00
collection
credentials
discovery
evasion Add elastic-endpoint 2024-11-20 14:02:05 -06:00
execution fpr: mark exotic queries as extra, add flatpak/pop-os uid0 procs 2024-11-19 15:49:30 -05:00
exfil
impact
initial_access Add exceptions for Autodesk, cloud_sql_proxy, .md downloads, TF providers in /tmp/, and more 2024-11-20 13:45:50 -06:00
persistence Add exceptions for Autodesk, cloud_sql_proxy, .md downloads, TF providers in /tmp/, and more 2024-11-20 13:45:50 -06:00
privesc Add exceptions for Autodesk, cloud_sql_proxy, .md downloads, TF providers in /tmp/, and more 2024-11-20 13:45:50 -06:00