Madhur Jodhwani
07/31/2021, 1:36 PMsecret.txt
,fleet.pem
, flagfile.txt
part as well in this, any help would be appreciated.Mystery Incorporated
07/31/2021, 2:21 PMMadhur Jodhwani
07/31/2021, 3:00 PMMystery Incorporated
08/01/2021, 4:35 AMMadhur Jodhwani
08/01/2021, 7:45 AMMystery Incorporated
08/01/2021, 11:08 AM--audit_allow_config=true
--audit_allow_sockets=true
--audit_allow_process_events=true
--audit_persist=true
--events_optimize=true
--events_max=100000
--events_expiry=900
--disable_events=false
--disable_audit=false
--enable_syslog
--syslog_events_max=50000
--syslog_pipe_path=/var/osquery/syslog_pipe
# Server
--tls_hostname=YourFleetServerURLHere:Port
--tls_server_certs=/etc/osquery/fleet.pem
# Enrollment
--host_identifier=instance
--enroll_secret_path=/etc/osquery/secret.txt
--enroll_tls_endpoint=/api/v1/osquery/enroll
# Configuration
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_refresh=90
# Live query
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=95
--distributed_tls_max_attempts=5
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
# Logging
--logger_plugin=tls
--logger_tls_endpoint=/api/v1/osquery/log
--logger_tls_period=5
--osquery_detail_update_interval=45m
# File carving
--disable_carver=false
--carver_start_endpoint=/api/v1/osquery/carve/begin
--carver_continue_endpoint=/api/v1/osquery/carve/block
--carver_block_size=2000000
Madhur Jodhwani
08/01/2021, 1:56 PMMystery Incorporated
08/01/2021, 5:48 PMMadhur Jodhwani
08/02/2021, 4:32 AMMystery Incorporated
08/02/2021, 5:02 AMMadhur Jodhwani
08/02/2021, 5:46 AMMystery Incorporated
08/02/2021, 9:34 AMMadhur Jodhwani
08/02/2021, 9:51 AMMystery Incorporated
08/02/2021, 1:50 PMMadhur Jodhwani
08/03/2021, 4:04 AMMystery Incorporated
08/06/2021, 4:23 AM