osquery-defense-kit/detection/initial_access
Thomas Stromberg 47124daa01
fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc
2023-05-02 15:25:36 -04:00
..
sketchy-mounted-diskimage.sql fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
unexpected-diskimage-name-macos.sql fpr: Github Absolute Date, Snagit, Figma, Seagate, aws, etc 2023-01-26 16:30:14 -05:00
unexpected-diskimage-source-macos.sql fpr: lghub, brew, pve, chrome exts, etc 2023-04-20 20:45:35 -04:00
unexpected-shell-parent-events.sql fpr: cleanup and new additions 2023-04-27 12:00:08 -04:00
unexpected-shell-parents.sql fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
unexpected-volume-contents.sql fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
unexpected-webmail-downloads.sql fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws 2023-03-14 19:00:44 -04:00