osquery-defense-kit/detection
2023-02-08 10:14:32 -05:00
..
c2 Add local port and address to network queries 2023-02-08 10:12:44 -05:00
collection Purge false positives, again and again 2023-02-02 21:46:53 -05:00
credentials Purge false positives, again and again 2023-02-02 21:46:53 -05:00
discovery Purge false positives, again and again 2023-02-02 21:46:53 -05:00
evasion Purge false positives, again and again 2023-02-02 21:46:53 -05:00
execution Add local port and address to network queries 2023-02-08 10:12:44 -05:00
exfil fpr: New Chrome etxensions, vbox, chrome, gcloud, gdm3, yay, etc 2023-01-30 14:58:47 -05:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access Replace unexpected-vol-names with sketchy-mounted-diskimage 2023-02-08 10:14:32 -05:00
persistence Purge false positives, again and again 2023-02-02 21:46:53 -05:00
privesc Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00