osquery-defense-kit/detection/initial_access
Thomas Stromberg 9b0ed09c8e
fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage
2023-03-28 16:25:26 -04:00
..
sketchy-mounted-diskimage.sql fpr: Signal, apko, aws, melange, dash, stern 2023-03-16 17:29:11 -04:00
unexpected-diskimage-name-macos.sql fpr: Github Absolute Date, Snagit, Figma, Seagate, aws, etc 2023-01-26 16:30:14 -05:00
unexpected-diskimage-source-macos.sql fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage 2023-03-28 16:25:26 -04:00
unexpected-shell-parent-events.sql fpr: Docker, Zwift, macOS updates, etc 2023-03-20 17:05:02 -04:00
unexpected-shell-parents.sql fpr: xdg, docker, dbus, bpfilter_umh, docker, spotify, mage 2023-03-28 16:25:26 -04:00
unexpected-volume-contents.sql fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
unexpected-webmail-downloads.sql fpr: yum, systemd, cloud-sql-proxy, image-automation-controller, helm, bom, aws 2023-03-14 19:00:44 -04:00