osquery-defense-kit/detection
Thomas Strömberg 60d66a5e41
Merge pull request #86 from tstromberg/hidden-exec
Add hidden-executable rule
2022-11-16 20:56:14 -05:00
..
c2 Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
collection Add exceptions for terraform, hugo, macOS updates 2022-11-08 14:32:38 -05:00
credentials Complete cleanup phase 1 2022-11-16 11:18:45 -05:00
discovery Allow -sP /usr/sbin/firewalld 2022-11-16 11:03:34 -05:00
evasion Merge pull request #86 from tstromberg/hidden-exec 2022-11-16 20:56:14 -05:00
execution Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
exfil Add exceptions for terraform, hugo, macOS updates 2022-11-08 14:32:38 -05:00
impact Accept strace-log-merge anywhere 2022-11-10 11:31:37 -05:00
initial_access Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
persistence Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00
privesc Begin making use of cgroup_paths, clear more false positives 2022-11-16 16:52:39 -05:00