osquery-defense-kit/detection
Thomas Stromberg 9eed574026
fpr: sharingd, sparkle, golang, Snagit
2023-05-05 15:10:54 -04:00
..
c2 fpr: sharingd, sparkle, golang, Snagit 2023-05-05 15:10:54 -04:00
collection fpr: RetailMeNot, LogiTune, macOS, mediawriter, etc 2023-05-02 15:25:36 -04:00
credentials fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00
discovery fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00
evasion fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00
execution fpr: sharingd, sparkle, golang, Snagit 2023-05-05 15:10:54 -04:00
exfil fpr: libopenblas, snapd, k3d, opera, nix, ssh, cargo, adobe installer 2023-05-03 16:28:00 -04:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00
persistence fpr: sharingd, sparkle, golang, Snagit 2023-05-05 15:10:54 -04:00
privesc fpr: node, nc, busybox, libvirt, etc 2023-05-05 12:44:46 -04:00