osquery-defense-kit/detection/execution
Thomas Stromberg d897f0b50d
fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc
2023-02-14 08:33:05 -05:00
..
exotic-command-events-linux.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
exotic-command-events-macos.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
exotic-commands-linux.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
exotic-commands-macos.sql Fix broken updates to exotic-commands-macos 2023-02-09 17:06:09 -05:00
launch-constraint-violation.sql Increase polling interval to 15 min 2023-02-10 10:24:20 -05:00
recently-created-executables-linux.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
recently-created-executables-macos.sql False positive removal and minor query perf improvements 2023-02-10 10:21:06 -05:00
relative-exec-low-uid-events.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
relative-exec-low-uid.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
reverse-shell-socket.sql Add local port and address to network queries 2023-02-08 10:12:44 -05:00
sketchy-fetcher-events.sql Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00
sketchy-fetcher.sql fpr: Parallels, nerdctl, Xorg, nvidia, Stream, etc 2023-01-26 20:40:47 -05:00
tiny-executable-events.sql Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
tiny-executable.sql Simplify macos-execdir, reduce false positives 2022-11-07 10:03:43 -05:00
unexpected-env-values-linux.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-env-values-macos.sql Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
unexpected-execdir-events-linux.sql Slow queries down, minor improvements 2023-02-01 16:17:36 -05:00
unexpected-execdir-events-macos.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-execdir-linux.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-execdir-macos.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-executable-permissions.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-fetcher-parent-events.sql Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00
unexpected-fetcher-parents.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-file-made-executable.sql Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00
unexpected-gatekeeper-approvals-macos.sql Massive reduction of false positives across the board 2023-02-08 20:06:26 -05:00
unexpected-mounts.sql Remove unused active fields, add WhatsApp ioreg exception 2023-01-27 08:46:48 -05:00
unexpected-osascript-calls.sql Purge false positives, again and again 2023-02-02 21:46:53 -05:00
unexpected-raw-socket.sql Query performance improvements, add pids, decrease frequency 2023-02-09 17:01:29 -05:00
unexpected-root-signer-macos.sql Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility 2023-02-08 20:54:45 -05:00
unexpected-security-framework-program-macos.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-setuid-binaries.sql FP removal: plymouth, 1Password, firejail, systemd 2023-01-16 13:55:53 -05:00
unexpected-sysutils-linux.sql Run make reformat, update max rows for incident response 2023-02-02 17:58:19 -05:00
unexpected-sysutils-macos.sql fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
unexpected-xattr-calls-macos.sql Merge pull request #164 from NACHOSWITHCHEESE/fixing-macos-detection-compatibility 2023-02-08 20:54:45 -05:00
xprotect-reports.sql Add support for interval tags 2022-10-14 14:19:13 -04:00