osquery-defense-kit/detection
2023-03-21 14:07:06 -04:00
..
c2 fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
collection modernize high-disk-bytes queries 2023-03-17 10:48:17 -04:00
credentials fpr: Signal, apko, aws, melange, dash, stern 2023-03-16 17:29:11 -04:00
discovery
evasion fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
execution fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
exfil fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
impact
initial_access fpr: traceroute, thunderbird, garmin installer, chainctl, etc 2023-03-21 14:07:06 -04:00
persistence fpr: Docker, Zwift, macOS updates, etc 2023-03-20 17:05:02 -04:00
privesc fpr: Docker, Zwift, macOS updates, etc 2023-03-20 17:05:02 -04:00