Mystery Incorporated
12/05/2020, 11:52 AMCptOfEvilMinions
12/05/2020, 6:30 PMiptables
, however you will need to instruct Osquery to generate logs for addition/removal of IPtables.
osquery config:
{
"schedule": {
"iptables_monitor": {
"query": "SELECT * FROM iptables",
"interval": 60,
"removed": true
}
}
}
Mystery Incorporated
12/06/2020, 10:05 AMCptOfEvilMinions
12/06/2020, 4:16 PMMystery Incorporated
12/15/2020, 1:52 AM