osquery-defense-kit/detection
2023-02-20 13:10:07 -05:00
..
c2 Add additional talkers 2023-02-19 11:11:13 -08:00
collection More osquery matches 2023-02-19 11:24:54 -08:00
credentials macos sniffers: back out osquery change until we understand it better, sort exceptions 2023-02-20 11:58:43 -05:00
discovery fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
evasion fpr: Fujitsu, vmware, objective-see, paragon, etc 2023-02-18 12:02:40 -08:00
execution Rewrite exotic-command-events-linux with INSTR to decrease CPU time 2023-02-17 16:39:52 -05:00
exfil fpr: New Chrome etxensions, vbox, chrome, gcloud, gdm3, yay, etc 2023-01-30 14:58:47 -05:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
persistence systemd units: increase size bucket from 100 to 225 2023-02-20 13:10:07 -05:00
privesc Missed one 2023-02-18 16:10:48 -08:00