osquery-defense-kit/detection/privesc
Thomas Stromberg f16c3cdf53 fpr: sourcegraph, nginx, factorio, fan control, emacs, nushell 2023-09-14 17:13:12 -04:00
..
docker-container-mounting-root.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
setxid-cmdline-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
setxid-env-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
sketchy-docker-image-creator.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-elevated-children-events_linux.sql Remove file sizes from systemd exception key 2023-06-08 18:26:57 -04:00
unexpected-elevated-children-events_macos.sql fpr: Slack, Gnome, Sigstore, Logitune, etc 2023-06-12 10:10:57 -04:00
unexpected-privilege-escalation_linux.sql make reformat 2023-05-08 13:20:47 -04:00
unexpected-privilege-escalation_macos.sql Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
unexpected-privileged-containers.sql fpr: sourcegraph, nginx, factorio, fan control, emacs, nushell 2023-09-14 17:13:12 -04:00
unexpected-setxid-process.sql fpr: Brave, Adobe, Signal, Kandji, SteelSeries, etc 2023-06-30 16:38:31 -04:00