Artem
05/12/2022, 3:47 PMdisable_tables: 'curl'
osquery option via Fleet UI (inspired by https://www.tenchisecurity.com/abusing-the-osquery-curl-table-for-pivoting-into-cloud-environments/) , it continues to work!
It looks like this option only applies after restarting osqueryd service on endpoint.
Is it right behavior? Looks strange, but maybe I just do something wrong way…Lucas Rodriguez
05/13/2022, 12:40 PMArtem
05/14/2022, 8:10 PM