osquery-defense-kit/detection
Thomas Strömberg fd2b240344
Merge pull request #103 from tstromberg/sketchy-fetcher-refactor
sketchy fetchers: Remove trailing commas
2022-12-20 08:03:54 -05:00
..
c2 False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
collection False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
credentials Add k3s /dev/kmsg exception, add parent info 2022-12-20 07:51:29 -05:00
discovery Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
evasion Filter out Docker children too 2022-12-20 07:52:04 -05:00
execution sketchy fetchers: Remove trailing commas 2022-12-20 08:03:14 -05:00
exfil Another false positive flush: Capital One, tailscaled, agetty, snap, ninja, epson printers, etc 2022-12-15 16:51:58 -05:00
impact Resolve latest reported false positives 2022-12-02 11:20:18 -05:00
initial_access False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
persistence False-positive flush: mount.ntfs, docker-credential-desktop, exotic socket refactor 2022-12-19 18:06:06 -05:00
privesc Sort out more false positives 2022-12-16 17:37:32 -05:00