Ted Dorosheff
11/23/2021, 1:35 PMconfig:
options:
events_expiry: 60
config_refresh: 600
host_identifier: instance
distributed_interval: 60
decorators:
load:
- SELECT COALESCE((select instance_id FROM ec2_instance_metadata), hostname) as hostname FROM system_info;
file_paths:
etc:
- /etc/group
- /etc/passwd
- /etc/shadow
- /etc/services
- /etc/sudoers
- /etc/ld.so.preload
- /etc/ld.so.conf
- /etc/ld.so.conf.d/%%
- /etc/pam.d/%%
- /etc/resolv.conf
- /etc/modules
- /etc/hosts
- /etc/hostname
- /etc/fstab
- /etc/rsyslog.conf
ssh:
- /root/.ssh/%%
- /home/%/.ssh/%%
- /etc/ssh/%%
- /var/lib/sia/keys/
- /var/lib/sia/certs/
logs:
- /var/log/secure
docker:
- /etc/docker/%%
- /etc/default/docker
- /etc/docker/daemon.json
- /usr/bin/containerd
- /usr/sbin/runc
- /etc/sysconfig/docker
- /usr/lib/systemd/system/docker.service
- /usr/lib/systemd/system/docker.socket
osquery:
- /etc/osquery/%%
- /usr/share/osquery/packs/%%
firewalls:
- /etc/sysconfig/iptables
- /home/y/conf/yakl/%%
- /etc/yakl/conf/%%
overrides:
platforms:
windows:
options:
events_expiry: 60
config_refresh: 600
host_identifier: instance
distributed_interval: 60
decorators:
load:
- SELECT COALESCE((select instance_id FROM ec2_instance_metadata), hostname) as hostname FROM system_info;
file_paths:
users:
- C:\users\AppData\Roaming
- C:\users\AppData\Local
- C:\users\AppData\Local\temp
- C:\users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- C:\users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- C:\Users\Default
windows:
- C:\Windows
- C:\Windows\temp
- C:\Windows\system32\Drivers
- C:\Windows\SysWOW64\Drivers
- C:\Windows\system32\GroupPolicy\Machine\Scripts
- C:\Windows\system32\GroupPolicy\User\Scripts
- C:\Windows\system32\Wbem
- C:\Windows\SysWOW64\Wbem
- C:\Windows\system32\WindowsPowerShell
- C:\Windows\SysWOW64\WindowsPowerShell
- C:\Windows\Tasks
- C:\Windows\system32\Tasks
- C:\Windows\AppPatch\Custom%
ProgramData:
- C:\ProgramData\Microsoft\Windows\Start Menu
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs
exclude_paths:
windows:
- C:\Windows\system32\DriverStore\Temp\%
- C:\Windows\system32\wbem\Performance%
- C:\$WINDOWS.~BT\Sources\%
- C:\Windows\Installer\%
- C:\Windows\System32\Tasks\Adobe Acrobat Update Task%
- C:\Windows\System32\Tasks\Adobe Flash Player Updater%
- C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask%
and then after i hit submit, this is what the editor shows me
config:
options:
events_expiry: 60
config_refresh: 600
host_identifier: instance
distributed_interval: 60
decorators:
load:
- >-
SELECT COALESCE((select instance_id FROM ec2_instance_metadata),
hostname) as hostname FROM system_info;
file_paths:
etc:
- /etc/group
- /etc/passwd
- /etc/shadow
- /etc/services
- /etc/sudoers
- /etc/ld.so.preload
- /etc/ld.so.conf
- /etc/ld.so.conf.d/%%
- /etc/pam.d/%%
- /etc/resolv.conf
- /etc/modules
- /etc/hosts
- /etc/hostname
- /etc/fstab
- /etc/rsyslog.conf
ssh:
- /root/.ssh/%%
- /home/%/.ssh/%%
- /etc/ssh/%%
- /var/lib/sia/keys/
- /var/lib/sia/certs/
logs:
- /var/log/secure
docker:
- /etc/docker/%%
- /etc/default/docker
- /etc/docker/daemon.json
- /usr/bin/containerd
- /usr/sbin/runc
- /etc/sysconfig/docker
- /usr/lib/systemd/system/docker.service
- /usr/lib/systemd/system/docker.socket
osquery:
- /etc/osquery/%%
- /usr/share/osquery/packs/%%
firewalls:
- /etc/sysconfig/iptables
- /home/y/conf/yakl/%%
- /etc/yakl/conf/%%
overrides:
platforms:
windows:
options:
events_expiry: 60
config_refresh: 600
host_identifier: instance
distributed_interval: 60
decorators:
load:
- >-
SELECT COALESCE((select instance_id FROM ec2_instance_metadata),
hostname) as hostname FROM system_info;
file_paths:
users:
- 'C:\users\AppData\Roaming'
- 'C:\users\AppData\Local'
- 'C:\users\AppData\Local\temp'
- >-
C:\users\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup
- 'C:\users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs'
- 'C:\Users\Default'
windows:
- 'C:\Windows'
- 'C:\Windows\temp'
- 'C:\Windows\system32\Drivers'
- 'C:\Windows\SysWOW64\Drivers'
- 'C:\Windows\system32\GroupPolicy\Machine\Scripts'
- 'C:\Windows\system32\GroupPolicy\User\Scripts'
- 'C:\Windows\system32\Wbem'
- 'C:\Windows\SysWOW64\Wbem'
- 'C:\Windows\system32\WindowsPowerShell'
- 'C:\Windows\SysWOW64\WindowsPowerShell'
- 'C:\Windows\Tasks'
- 'C:\Windows\system32\Tasks'
- 'C:\Windows\AppPatch\Custom%'
ProgramData:
- 'C:\ProgramData\Microsoft\Windows\Start Menu'
- 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs'
exclude_paths:
windows:
- 'C:\Windows\system32\DriverStore\Temp\%'
- 'C:\Windows\system32\wbem\Performance%'
- 'C:\$WINDOWS.~BT\Sources\%'
- 'C:\Windows\Installer\%'
- 'C:\Windows\System32\Tasks\Adobe Acrobat Update Task%'
- 'C:\Windows\System32\Tasks\Adobe Flash Player Updater%'
- >-
C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask%
Mystery Incorporated
11/24/2021, 4:13 AMTed Dorosheff
11/24/2021, 11:44 AMMystery Incorporated
11/29/2021, 11:21 PM