himanshu
02/09/2021, 3:28 PMcharacter_frequencies
map specified here (https://github.com/osquery/osquery/blob/4.6.0/tools/deployment/osquery.example.conf) with osquery 4.5.0. but osquery reports error while parsing the config "The character_frequencies configuration entity array is not valid. Entry #0 is not a double"
.. while looking at osquery code, it seems the value 0.0 in character_frequencies map json is stored as just 0 in character_frequencies_array for which character_frequencies_array[i].IsDouble()
check is not working. while other values in character_frequencies map such as 0.00045
are stored and parsed correctly.
please suggest / confirm in this regard. thanks in advance.Valentín
02/16/2021, 5:19 PMGeorge
02/18/2021, 8:55 AMcaller=level.go:63 level=info caller=log.go:69 component=osquery level=stderr msg="...
messages, has anyone else seen this issue?defensivedepth
03/23/2021, 1:34 PMwindows_events
table to ship the sysmon logs?WS
03/23/2021, 5:15 PMMike Myers
03/23/2021, 5:40 PMStefano Bonicatti
03/26/2021, 12:16 PMINCREMENTAL
under a CMake option for the project, but /MP
varies a lot depending on the target being built and the amount of targets/projects that are building at the same time.metalgearsolid
03/30/2021, 10:20 AMwindows_eventlog
table and figuring out what command to run to check what channels are available from the endpoint? I did a simple select channel from windows_eventlog where channel like '%'
and seems like that does not work, wondering if anyone has a workaround to share? Thanks!manu
04/03/2021, 2:56 AMosquery> select * from osquery_events;
+-------------------------------------------+--------------------------+------------+---------------+--------+-----------+--------+
| name | publisher | type | subscriptions | events | refreshes | active |
+-------------------------------------------+--------------------------+------------+---------------+--------+-----------+--------+
| SysmonEtwEventPublisher | SysmonEtwEventPublisher | publisher | 23 | 0 | 0 | 1 |
| WindowsEventLogPublisher | WindowsEventLogPublisher | publisher | 2 | 0 | 0 | 1 |
| ntfs_event_publisher | ntfs_event_publisher | publisher | 0 | 0 | 0 | 0 |
| ntfs_journal_events | ntfs_event_publisher | subscriber | 0 | 0 | 0 | 1 |
| powershell_events | WindowsEventLogPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_clipboard_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_dnsquery_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_driver_loaded_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_file_created_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_file_delete_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_filestream_created_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_image_load_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_network_connection_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_pipe_connected_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_pipe_created_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_process_accessed_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_process_create_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_process_tampering_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_process_terminate_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_raw_access_read_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_registry_added_deleted_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_registry_renamed_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_registry_valueset_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_remote_thread_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_service_state_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_wmievent_consumer_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_wmievent_consumer_to_filter_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| sysmon_wmievent_filtering_events | SysmonEtwEventPublisher | subscriber | 1 | 0 | 0 | 1 |
| windows_events | WindowsEventLogPublisher | subscriber | 1 | 0 | 0 | 1 |
+-------------------------------------------+--------------------------+------------+---------------+--------+-----------+--------+
theopolis
{
"events": {
"disable_subscribers": [
"sysmon_wmievent_filtering_events"
]
}
}
Hello_There
04/07/2021, 2:38 PMterracatta
MarkMurdock
04/27/2021, 8:32 PMgrahamgilbert
04/29/2021, 3:45 PMNithin Sade
05/11/2021, 3:18 AMChad Priest
05/14/2021, 4:09 PMzwass
Hello_There
05/18/2021, 7:18 PMananta
06/04/2021, 5:01 PMAman Kumar Chagti
06/11/2021, 8:41 AMAman Kumar Chagti
06/12/2021, 7:26 AMMystery Incorporated
06/13/2021, 5:52 AMzwass
SELECT * FROM Win32_Process WHERE ProcessId=2500
I can't find anything that refers to Win32_Process
except within one of the WMI tests.Sebastiaan
07/03/2021, 6:15 PMAman Kumar Chagti
07/05/2021, 10:38 AMfritz
07/06/2021, 8:30 PMMoodyMudit
07/14/2021, 7:33 AMJulia Cox
08/12/2021, 2:33 PMJulia Cox
08/12/2021, 2:33 PMJulia Cox
08/12/2021, 5:32 PMprepare_for_ide
target and disabling automatic cmake configuration in visual studio fixed my problems! Thank you!