osquery-defense-kit/detection/privesc
Thomas Stromberg 2d81061df3
Update for osqtool v1.0
2023-02-02 12:04:26 -05:00
..
docker-container-mounting-root.sql Add spacing (sqlformat) 2022-10-21 17:39:53 -04:00
setxid-cmdline-overflow-attempt.sql Include more process information across queries 2023-02-01 13:55:55 -05:00
setxid-env-overflow-attempt.sql Update for osqtool v1.0 2023-02-02 12:04:26 -05:00
sketchy-docker-image-creator.sql Apply 'npx sql-formatter -l sqlite' 2022-10-17 19:06:17 -04:00
unexpected-elevated-children-events_linux.sql Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
unexpected-elevated-children-events_macos.sql Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
unexpected-privilege-escalation_linux.sql Include more process information across queries 2023-02-01 13:55:55 -05:00
unexpected-privilege-escalation_macos.sql Include more process information across queries 2023-02-01 13:55:55 -05:00
unexpected-privileged-containers.sql fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
unexpected-setxid-process.sql FP removal: Selenium, PolKit helper, gephi, docker-credential-gcloud, firejail, etc 2023-01-16 12:56:39 -05:00