slevchenko
10/19/2022, 11:58 AM/proc/${PID/exe}
belongs to corresponding process
SELECT DISTINCT processes.path, (SELECT sha256 FROM hash WHERE path = concat('/proc/', socket.pid, '/exe')) AS sha256, socket.remote_address, socket.remote_port FROM bpf_socket_events socket LEFT JOIN bpf_process_events processes ON socket.pid = processes.pid WHERE socket.remote_port NOT IN (0, 443, 993, 4172, 4195) AND socket.remote_address NOT LIKE '127.0.%.%';
seph
nc
process short lived?slevchenko
10/19/2022, 12:52 PMnc -l 8983
nc -v 8983 <http://XXX.XXX.XXX.XXX|XXX.XXX.XXX.XXX>
seph
slevchenko
10/19/2022, 12:55 PMosqueryi
but not from config ? Query always rerturns non-empty result when executed interactively, but never appears in results file if executed by daemonseph
slevchenko
10/19/2022, 3:23 PMseph
slevchenko
10/19/2022, 3:25 PMseph
slevchenko
10/19/2022, 3:27 PMosqueryi
while extension registered such test connection only once or twiceseph
slevchenko
10/19/2022, 3:30 PMseph
slevchenko
10/19/2022, 3:32 PMlogger_plugin="threat_logger,filesystem"
and it worksseph
slevchenko
10/19/2022, 3:35 PMseph
bpf_socket_events
is eventedslevchenko
10/19/2022, 3:37 PMseph
slevchenko
10/19/2022, 3:40 PMosqueryd.results.log
seph
bpf_socket_events
is it reliable?
I wonder if that subselect is being weird.slevchenko
10/19/2022, 3:50 PM1130:2022/10/19 11:48:25 string: {"name":"pack_osquery-process-ioc_process_unknown_outbound_connection","hostIdentifier":"HP-Spectre-x360-Convertible-13-aw0xxx","calendarTime":"Wed Oct 19 08:48:25 2022 UTC","unixTime":1666169305,"epoch":0,"counter":0,"numerics":false,"columns":{"path":"","remote_address":"<http://XXX.XXX.XXX.XXX|XXX.XXX.XXX.XXX>","remote_port":"53","sha256":"1a2b9a41d835898601a4778921c2504ab2e74f1cd76a4c48fcfda43[REDATED]"},"action":"added"}
2022/10/19 11:48:27 INFO: VirusTotal client API sucessfully created with daily request limit: 500
2022/10/19 11:48:27 ERROR: Unable to canonicalize url
2022/10/19 11:49:00 deregistering extension: write unix @->/var/osquery/osquery.em: write: broken pipe
seph
2022/10/19 11:48:27 ERROR: Unable to canonicalize url
2022/10/19 11:49:00 deregistering extension: write unix @->/var/osquery/osquery.em: write: broken pipe
slevchenko
10/19/2022, 3:54 PMseph
slevchenko
10/19/2022, 3:55 PMseph
slevchenko
10/19/2022, 3:58 PMseph
slevchenko
10/19/2022, 4:02 PM