Mystery Incorporated
05/02/2021, 6:29 AMtheopolis
yara_events
table: https://osquery.readthedocs.io/en/latest/deployment/yara/Mystery Incorporated
05/04/2021, 2:53 AMCptOfEvilMinions
05/04/2021, 6:20 PMSELECT sha256 FROM hash WHERE path="<file>" AND sha256 != <sha256 of canary file>
This might be more practical for envs where you can’t enable file monitoring.Mystery Incorporated
05/04/2021, 6:32 PM