osquery-defense-kit/detection
2023-01-13 13:47:02 -05:00
..
c2 false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
collection Flush out more false positives across the stack 2023-01-06 10:36:48 -05:00
credentials false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
discovery Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
evasion false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
execution Merge pull request #114 from tstromberg/sysctl 2023-01-09 09:36:01 -05:00
exfil Add some hash fields, fix some false positives 2023-01-09 09:04:38 -05:00
impact
initial_access Add support for .pkg files 2023-01-13 13:47:02 -05:00
persistence false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00
privesc false positives: dots, ipn, apport-gtk, homebrew, hyperkey, contexts 2023-01-09 09:34:20 -05:00