osquery-defense-kit/detection/initial_access
Thomas Stromberg 2bbc2f6c97
split detection pack into subpacks
2023-09-20 17:43:39 -04:00
..
sketchy-download-name.sql fpr: RSA keys, tcpdump, login, crane, souregraph, etc 2023-09-20 09:30:46 -04:00
sketchy-mounted-diskimage.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00
unexpected-diskimage-name-macos.sql fpr: Github Absolute Date, Snagit, Figma, Seagate, aws, etc 2023-01-26 16:30:14 -05:00
unexpected-diskimage-source-macos.sql fpr: RSA keys, tcpdump, login, crane, souregraph, etc 2023-09-20 09:30:46 -04:00
unexpected-shell-parent-events.sql fpr: RSA keys, tcpdump, login, crane, souregraph, etc 2023-09-20 09:30:46 -04:00
unexpected-shell-parents.sql fpr: RSA keys, tcpdump, login, crane, souregraph, etc 2023-09-20 09:30:46 -04:00
unexpected-volume-contents.sql Merge to master 2023-09-01 17:34:36 -04:00
unexpected-webmail-downloads.sql fpr: Brave, Adobe, Signal, Kandji, SteelSeries, etc 2023-06-30 16:38:31 -04:00
yara-recently-downloaded-miner.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00
yara-recently-downloaded-ransom.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00
yara-recently-downloaded-rust-http-exec.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00
yara-recently-downloaded-stealer.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00
yara-recently-downloaded-upx.sql YARA rules everywhere! 2023-09-20 17:03:21 -04:00