osquery-defense-kit/detection
Thomas Stromberg 9f4b8a0b69
refactor to reduce false positives
2024-10-16 09:44:19 -04:00
..
c2 refactor to reduce false positives 2024-10-16 09:44:19 -04:00
collection fpr: sequoia, osquery, cups, atops, transmission, etc 2024-09-23 11:07:53 -04:00
credentials fpr: prosoft, ujust, kandji-library-manager, etc 2024-09-26 12:40:04 -04:00
discovery Merge pull request #388 from tstromberg/net-events 2024-09-24 15:53:07 -04:00
evasion refactor to reduce false positives 2024-10-16 09:44:19 -04:00
execution refactor to reduce false positives 2024-10-16 09:44:19 -04:00
exfil mark https-linux extra, minor query tuning 2024-10-11 09:55:04 -04:00
impact fpr: snap, mutedeck, idea, Chrome exts 2024-01-18 17:15:37 -05:00
initial_access widen query scope 2024-10-16 09:32:00 -04:00
persistence exceptions for Bluefin systemd services 2024-10-11 10:06:57 -04:00
privesc Add events and extra tags to relevant event-based queries 2024-09-24 15:36:03 -04:00