osquery-defense-kit/detection
2023-06-07 15:15:02 -04:00
..
c2 fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00
collection fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00
credentials Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
discovery Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
evasion Add ~/.config/.* to search criteria 2023-06-07 15:15:02 -04:00
execution fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00
exfil fpr: FleetDM, Edge, VSCode, dnf, Steam, etc 2023-06-01 11:52:20 -04:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00
persistence fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00
privesc fpr: macOS, Signal, Creative Labs, node, etc 2023-06-07 09:55:17 -04:00