osquery-defense-kit/detection/c2
Dave Smith ca768ca4fa fpr: mostly uid0 things 2024-11-12 07:37:29 -05:00
..
unexpected-dns-traffic-events.sql fpr: zypper, bambu, terraform, etc 2024-11-08 07:34:33 -05:00
unexpected-dns-traffic.sql Add rules for bambu-studio, extensions, firefox-bin, goland, xdg, and more 2024-11-01 14:27:33 -05:00
unexpected-https-linux.sql widen query scope 2024-10-16 09:32:00 -04:00
unexpected-https-macos.sql fpr: framework nix, etc 2024-10-30 08:30:43 -04:00
unexpected-icmp-socket-events.sql
unexpected-icmp-socket.sql
unexpected-root-libcurl-proc-linux.sql
unexpected-root-libcurl-proc-macos.sql fpr: prosoft, ujust, kandji-library-manager, etc 2024-09-26 12:40:04 -04:00
unexpected-talker-events.sql
unexpected-talkers-linux.sql fpr: mostly uid0 things 2024-11-12 07:37:29 -05:00
unexpected-talkers-macos.sql false positive reduction: apt, auditd, dockerd, etc. 2024-11-07 10:00:40 -05:00