Channels
android_tests
apple-silicon
arm-architecture
auditing-warroom
aws
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
general
golang
goquery
infrastructure
jobs
kolide
linen-dev
linux
macos
officehours
osctrl
plugins
process-auditing
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Title
a
arod
02/04/2021, 7:42 PM
Anyone mind dropping some community packs/queries? Here are some links I have found that have syntax (good or bad lol):
https://github.com/osquery/osquery/tree/master/packs
https://resources.infosecinstitute.com/topic/threat-hunting-with-kolide-and-osquery/
https://github.com/palantir/osquery-configuration
https://engineering.fb.com/2014/10/29/security/introducing-osquery/
https://www.alibabacloud.com/blog/server-endpoint-security-with-osquery_594950?spm=a2c41.13076147.0.0
https://github.com/teoseller/osquery-attck
👍 1
c
CptOfEvilMinions
02/04/2021, 8:03 PM
My go is:
https://github.com/palantir/osquery-configuration
✅ 2
3 Views
#fleet
Join Slack