Avik Sengupta
02/09/2022, 10:02 PMTed Dorosheff
02/09/2022, 11:29 PMC:\Program Files\osquery>"C:\Program Files\osquery\osqueryd\osqueryd.exe" --flagfile="C:\Program Files\osquery\osquery.flags" --config_dump=true
{"tls_plugin": {"decorators":{"load":["SELECT COALESCE((select instance_id FROM ec2_instance_metadata), hostname) as hostname FROM system_info;"]},"exclude_paths":{"Windows":["C:\\\\Windows\\\\Prefetch\\\\%"]},"file_paths":{"ProgramData":["C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Start Menu\\\\%","C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Start Menu\\\\Programs\\\\%"],"Users":["C:\\\\Users\\\\%\\\\AppData\\\\Roaming\\\\%","C:\\\\Users\\\\%\\\\AppData\\\\Local\\\\%","C:\\\\Users\\\\%\\\\AppData\\\\Local\\\\temp\\\\%","C:\\\\Users\\\\%\\\\AppData\\\\Roaming\\\\Microsoft\\\\Windows\\\\Start Menu\\\\Programs\\\\Startup\\\\%","C:\\\\Users\\\\%\\\\AppData\\\\Roaming\\\\Microsoft\\\\Windows\\\\Start Menu\\\\Programs\\\\%","C:\\\\Users\\\\%\\\\Default\\\\%"],"Windows":["C:\\\\Windows\\\\%","C:\\\\Windows\\\\Temp\\\\%","C:\\\\Windows\\\\System32\\\\Drivers\\\\%","C:\\\\Windows\\\\SysWOW64\\\\Drivers\\\\%","C:\\\\Windows\\\\System32\\\\GroupPolicy\\\\Machine\\\\Scripts\\\\%","C:\\\\Windows\\\\System32\\\\GroupPolicy\\\\User\\\\Scripts\\\\%","C:\\\\Windows\\\\System32\\\\Wbem\\\\%","C:\\\\Windows\\\\SysWOW64\\\\Wbem\\\\%","C:\\\\Windows\\\\System32\\\\WindowsPowerShell\\\\%","C:\\\\Windows\\\\SysWOW64\\\\WindowsPowerShell\\\\%","C:\\\\Windows\\\\Tasks\\\\%","C:\\\\Windows\\\\System32\\\\Tasks\\\\%","C:\\\\Windows\\\\AppPatch\\\\Custom\\\\%","C:\\\\Windows\\\\system32\\\\DriverStore\\\\Temp\\\\%","C:\\\\Windows\\\\system32\\\\wbem\\\\Performance\\\\%","C:\\\\Windows\\\\System32\\\\Tasks\\\\Adobe Acrobat Update Task\\\\%","C:\\\\Windows\\\\System32\\\\Tasks\\\\Adobe Flash Player Updater\\\\%","C:\\\\Windows\\\\System32\\\\Tasks\\\\OfficeSoftwareProtectionPlatform\\\\SvcRestartTask\\\\%"]},"options":{"disable_distributed":false,"disable_events":false,"distributed_interval":60,"enable_ntfs_event_publisher":true,"enable_powershell_events_subscriber":true,"enable_windows_events_publisher":true,"enable_windows_events_subscriber":true},"packs":{"Endpoints_Windows10":{"queries":{"win_end_bios_diff":{"query":"SELECT * FROM wmi_bios_info;","interval":3600,"platform":"windows","removed":false},"win_end_file_events_diff":{"query":"SELECT action, category, old_path, path, file_attributes, time FROM ntfs_journal_events;","interval":60,"platform":"windows"},"win_end_firmware_snapshot":{"query":"SELECT vendor, version, date, address, extra FROM platform_info;","interval":86400,"platform":"windows","snapshot":true},"win_end_hardware_events_diff":{"query":"SELECT hardware_vendor, hardware_model, hardware_version, hardware_serial FROM system_info;","interval":60,"platform":"windows"}}}}}}
ytonui
02/10/2022, 4:02 PM{
"component": "http",
"err": "timestamp: 2022-02-10T15:42:49Z: error in query ingestion || timestamp: 2022-02-10T15:42:49Z: error in query ingestion || timestamp: 2022-02-10T15:42:49Z: error in query ingestion || getting app config: selecting app config: timestamp: 2022-02-10T15:42:49Z: context canceled",
"ingestion-err": "ingest detail query: selecting app config: timestamp: 2022-02-10T15:42:49Z: context canceled",
"ip_addr": "10.16.14.145:57498",
"level": "error",
"method": "POST",
"took": "14.669590338s",
"ts": "2022-02-10T15:42:49.244372692Z",
"uri": "/api/v1/osquery/distributed/write",
"x_for_ip_addr": "10.23.14.12"
}
user
02/10/2022, 4:18 PMbenbass
02/11/2022, 3:36 PMAvik Sengupta
02/14/2022, 3:35 PMBrandon
02/14/2022, 8:11 PMzwass
zwass
Saulo Guilhermino
02/15/2022, 6:15 PMOjas
02/16/2022, 10:20 AMRyan
02/16/2022, 5:05 PMvulnerabilities
key is present in the fleet.yml
and it was enabled previously. Has anyone else encountered this? Thanks in advance ๐Noah Talerman
02/16/2022, 11:02 PMIvan
02/17/2022, 2:30 PMScott Blake
02/17/2022, 3:54 PMMarc Roelofs
02/18/2022, 8:31 AMIvan
02/18/2022, 9:37 AMNathaniel Strauss
02/18/2022, 10:12 PMNicolas
02/20/2022, 7:39 AMonel1ner
02/20/2022, 11:23 PMFound autoloadable extension: C:\Program Files\Orbit\extensions\test.ext.exe
but it never runs the extension or registers the tables. If I run .\osqueryi.exe --flagfile="C:\Program Files\Orbit\osquery.flags"
it loads fine. Is there a setting in Fleet I need to toggle to allow extension loading?mikermcneil
02/21/2022, 4:10 PMHi! I have attempted to deploy fleet inside GCP - unfortunately I did not had any luck with the methods described in the public documentation and even https://holdmybeersecurity.com/2021/01/07/getting-started-with-fleetdm-v3-6-0/ (faced issues with MySQL, config files which where supposed to be edited but did not exist (fleetdm.yml), couldnt connect to the WebUI regardless of Firewall settings). Is there anything else I can refer to, to safely deploy fleet inside GCP?
Tor Houghton
02/22/2022, 8:23 AMdram
02/22/2022, 9:35 PMTilman Bender
02/24/2022, 1:56 PMTilman Bender
02/24/2022, 2:12 PMTilman Bender
02/24/2022, 4:28 PMKeith Swagler
02/24/2022, 7:25 PMMissing migrations: tables=[20211216131203 20211221110132], data=[].
When running prepare dbTilman Bender
02/25/2022, 10:25 AMTilman Bender
02/25/2022, 10:26 AMTilman Bender
02/25/2022, 7:05 PM