osquery-defense-kit/detection/privesc
2024-10-21 10:15:59 -04:00
..
docker-container-mounting-root.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
setxid-cmdline-overflow-attempt.sql fpr: bwrap, malcontent, ld, metallb 2024-10-21 10:15:59 -04:00
setxid-env-overflow-attempt.sql Make process times broadly available, minor opts 2023-05-16 17:18:39 -04:00
sketchy-docker-image-creator.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-elevated-children-events_linux.sql Remove file sizes from systemd exception key 2023-06-08 18:26:57 -04:00
unexpected-elevated-children-events_macos.sql fpr: Slack, Gnome, Sigstore, Logitune, etc 2023-06-12 10:10:57 -04:00
unexpected-privilege-escalation_linux.sql fpr: Docker Desktop, code-oss, incus, etc 2024-02-26 17:26:56 -05:00
unexpected-privilege-escalation_macos.sql Query tuning after Geacon testing 2023-05-17 10:54:16 -04:00
unexpected-privileged-containers.sql fpr: lima, rpm-ostree, gitsign, kde, python, etc 2024-07-01 21:56:28 -04:00
unexpected-setxid-process.sql fpr: sequoia, osquery, cups, atops, transmission, etc 2024-09-23 11:07:53 -04:00