osquery-defense-kit/detection
Thomas Stromberg 5949ad1551
overwritten memory: filter out pathless kernel bits
2023-02-17 17:20:20 -05:00
..
c2 False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
collection False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
credentials fpr: ACE, Prusa, steam, pacman, Xcode, Adobe 2023-02-14 20:16:02 -05:00
discovery fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
evasion overwritten memory: filter out pathless kernel bits 2023-02-17 17:20:20 -05:00
execution Rewrite exotic-command-events-linux with INSTR to decrease CPU time 2023-02-17 16:39:52 -05:00
exfil fpr: New Chrome etxensions, vbox, chrome, gcloud, gdm3, yay, etc 2023-01-30 14:58:47 -05:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
persistence False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
privesc False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00