osquery-defense-kit/detection
Ian Brown ffd552aa54
Missed one
Signed-off-by: Ian Brown <ian@zestysoft.com>
2023-02-18 16:10:48 -08:00
..
c2 fpr: Fujitsu, vmware, objective-see, paragon, etc 2023-02-18 12:02:40 -08:00
collection False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
credentials fpr: Fujitsu, vmware, objective-see, paragon, etc 2023-02-18 12:02:40 -08:00
discovery fpr: Nessus, mysql-shell, ntia-checker, Ecamm, CopyClip, etc 2023-02-14 08:33:05 -05:00
evasion fpr: Fujitsu, vmware, objective-see, paragon, etc 2023-02-18 12:02:40 -08:00
execution Rewrite exotic-command-events-linux with INSTR to decrease CPU time 2023-02-17 16:39:52 -05:00
exfil fpr: New Chrome etxensions, vbox, chrome, gcloud, gdm3, yay, etc 2023-01-30 14:58:47 -05:00
impact fpr: minikube, tailscale, dex, pacman, virtualbox, steam, lsmod, busybox, etc 2023-01-23 20:33:52 -05:00
initial_access False positive flush, particularly in talkers 2023-02-17 11:57:23 -05:00
persistence fpr: Fujitsu, vmware, objective-see, paragon, etc 2023-02-18 12:02:40 -08:00
privesc Missed one 2023-02-18 16:10:48 -08:00