osquery-defense-kit/detection/privesc
2022-12-15 16:51:58 -05:00
..
docker-container-mounting-root.sql Add spacing (sqlformat) 2022-10-21 17:39:53 -04:00
setxid-cmdline-overflow-attempt.sql Add setxid-cmdline-overflow-attempt.sql 2022-10-29 19:58:59 -04:00
setxid-env-overflow-attempt.sql Refactor execdir, remove false positives 2022-11-07 20:36:37 -05:00
sketchy-docker-image-creator.sql Apply 'npx sql-formatter -l sqlite' 2022-10-17 19:06:17 -04:00
unexpected-elevated-children-events_linux.sql Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
unexpected-elevated-children-events_macos.sql Remove more false positives: kind, gopls, docker.socket, etc 2022-12-15 10:20:16 -05:00
unexpected-privilege-escalation_linux.sql Refactor execdir, remove false positives 2022-11-07 20:36:37 -05:00
unexpected-privilege-escalation_macos.sql Pre-Thanksgiving False Positive cleanup, including Pop!OS support 2022-11-22 09:21:03 -05:00
unexpected-privileged-containers.sql Resolve latest reported false positives 2022-12-02 11:20:18 -05:00
unexpected-setxid-process.sql More false positive management 2022-11-16 14:49:36 -05:00