osquery-defense-kit/process
2022-10-03 16:27:56 -04:00
..
empty_environ.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
executables-from-the-future.sql New query: executables from the future! 2022-10-03 15:45:08 -04:00
exotic-cmdline.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
hidden-cwd.sql Fix constraint failure 2022-09-30 14:12:24 -04:00
hidden-parent-pid.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
high_disk_bytes_read.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
high-disk-bytes-written.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
missing-from-disk-linux.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
missing-from-disk-macos.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
name_path_mismatch.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
old-binaries-running.sql Overdue false positive removal 2022-09-29 15:42:27 -04:00
parent-missing-from-disk.sql Add kworker->modprobe exception 2022-09-30 11:14:20 -04:00
recently-created-executables.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
reverse-shell-socket.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
sketchy-fetcher.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
unexpected-env-values.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
unexpected-executable-directory-linux.sql New exfil detector, exception improvements 2022-09-30 12:10:18 -04:00
unexpected-executable-directory-macos.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
unexpected-executable-permissions.sql New exfil detector, exception improvements 2022-09-30 12:10:18 -04:00
unexpected-privilege-escalation.sql Format everything with 'npx sql-formatter -l sqlite' 2022-09-24 11:12:23 -04:00
unexpected-setxid-process.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
unexpected-shell-parents.sql False positive purge, including Ventura additions 2022-10-03 16:27:56 -04:00
unexpected-uid0-daemon-linux.sql New exfil detector, exception improvements 2022-09-30 12:10:18 -04:00
unexpected-uid0-daemon-macos.sql Add experimental queries for daemon detection 2022-09-29 16:04:07 -04:00