osquery-defense-kit/detection/initial_access
2023-01-18 10:57:43 -05:00
..
unexpected-diskimage-source-macos.sql False positive reduction: Messenger, Chrome, Final Cut Pro, etc 2023-01-18 09:49:56 -05:00
unexpected-shell-parent-events.sql FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc 2023-01-16 12:56:39 -05:00
unexpected-shell-parents.sql False positives: homekit, setxid overflows, buildx, tmp files 2023-01-18 10:57:43 -05:00
unexpected-volume-contents.sql Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
unexpected-webmail-downloads.sql webmail: Add JFIF, remove BZ2, TAR, GZ from expectations list 2022-10-27 16:26:43 -04:00