Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#fleet
Title
# fleet
a
arod
02/04/2021, 7:42 PM
Anyone mind dropping some community packs/queries? Here are some links I have found that have syntax (good or bad lol):
https://github.com/osquery/osquery/tree/master/packs
https://resources.infosecinstitute.com/topic/threat-hunting-with-kolide-and-osquery/
https://github.com/palantir/osquery-configuration
https://engineering.fb.com/2014/10/29/security/introducing-osquery/
https://www.alibabacloud.com/blog/server-endpoint-security-with-osquery_594950?spm=a2c41.13076147.0.0
https://github.com/teoseller/osquery-attck
👍 1
c
CptOfEvilMinions
02/04/2021, 8:03 PM
My go is:
https://github.com/palantir/osquery-configuration
✅ 2
3 Views
Post