osquery-defense-kit/detection
2023-01-09 10:46:30 -05:00
..
c2 Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00
collection Flush out more false positives across the stack 2023-01-06 10:36:48 -05:00
credentials false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
discovery Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
evasion Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00
execution Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00
exfil Add some hash fields, fix some false positives 2023-01-09 09:04:38 -05:00
impact Resolve latest reported false positives 2022-12-02 11:20:18 -05:00
initial_access Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00
persistence Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00
privesc Remove false positives, fix some queries that failed to show a parent pid 2023-01-09 10:46:30 -05:00