Fran Rodríguez
06/16/2020, 5:51 PMCptOfEvilMinions
06/16/2020, 9:27 PMFran Rodríguez
06/17/2020, 8:42 AMCptOfEvilMinions
06/17/2020, 2:38 PM"logger_plugin": "syslog"
.Fran Rodríguez
06/17/2020, 4:06 PMCptOfEvilMinions
06/17/2020, 5:20 PMFran Rodríguez
06/17/2020, 5:22 PMCptOfEvilMinions
06/17/2020, 6:00 PM{
"options": {
"config_plugin": "filesystem",
"logger_plugin": "filesystem,syslog",
"logger_path": "/var/log/osquery",
"logger_snapshot_event_type": "true",
"disable_logging": "false",
"log_result_events": "true",
"schedule_splay_percent": "10",
"events_expiry": "3600",
"verbose": "false",
"worker_threads": "2",
"enable_monitor": "true",
"disable_events": "false",
"disable_audit": "false",
"audit_allow_config": "true",
"audit_allow_sockets": "true",
"host_identifier": "hostname",
"schedule_default_interval": "3600",
"enable_syslog": "false"
},
"platform": "linux",
"schedule": {
"process_events": {
"query": "SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events WHERE path NOT IN ('/bin/sed', '/usr/bin/tr', '/bin/gawk', '/bin/date', '/bin/mktemp', '/usr/bin/dirname', '/usr/bin/head', '/usr/bin/jq', '/bin/cut', '/bin/uname', '/bin/basename') and cmdline NOT LIKE '%_key%' AND cmdline NOT LIKE '%secret%';",
"interval": 10
},
"socket_events": {
"query": "SELECT action, auid, family, local_address, local_port, path, pid, remote_address, remote_port, success, time FROM socket_events WHERE success=1 AND path NOT IN ('/usr/bin/hostname') AND remote_address NOT IN ('127.0.0.1', '169.254.169.254', '', '0000:0000:0000:0000:0000:0000:0000:0001', '::1', '0000:0000:0000:0000:0000:ffff:7f00:0001', 'unknown', '0.0.0.0', '0000:0000:0000:0000:0000:0000:0000:0000');",
"interval": 10
},
"disk_space": {
"query": "select path, round((blocks_available * blocks_size *10e-10),2) as gigs_free, round((blocks_free*1.0/blocks * 100),2) as percent_free from mounts where path='/';",
"interval": 300
},
"python_packages": {
"query": "SELECT * FROM python_packages;",
"interval": 300
}
}
}
Next, I did tail -f /var/log/syslog | grep osquery
then started osqueryd with systemctl start osqueryd
let it run for 30 seconds to get.Fran Rodríguez
06/17/2020, 6:02 PMCptOfEvilMinions
06/17/2020, 6:11 PMFran Rodríguez
06/17/2020, 6:13 PMCptOfEvilMinions
06/18/2020, 4:29 PM