Fran Rodríguez
06/16/2020, 5:51 PMCptOfEvilMinions
06/16/2020, 9:27 PMFran Rodríguez
06/17/2020, 8:42 AMCptOfEvilMinions
06/17/2020, 2:38 PM"logger_plugin": "syslog" .Fran Rodríguez
06/17/2020, 4:06 PMFran Rodríguez
06/17/2020, 4:46 PMFran Rodríguez
06/17/2020, 4:46 PMFran Rodríguez
06/17/2020, 4:46 PMCptOfEvilMinions
06/17/2020, 5:20 PMFran Rodríguez
06/17/2020, 5:22 PMFran Rodríguez
06/17/2020, 5:22 PMFran Rodríguez
06/17/2020, 5:23 PMCptOfEvilMinions
06/17/2020, 6:00 PM{
  "options": {
    "config_plugin": "filesystem",
    "logger_plugin": "filesystem,syslog",
    "logger_path": "/var/log/osquery",
    "logger_snapshot_event_type": "true",
    "disable_logging": "false",
    "log_result_events": "true",
    "schedule_splay_percent": "10",
    "events_expiry": "3600",
    "verbose": "false",
    "worker_threads": "2",
    "enable_monitor": "true",
    "disable_events": "false",
    "disable_audit": "false",
    "audit_allow_config": "true",
    "audit_allow_sockets": "true",
    "host_identifier": "hostname",
    "schedule_default_interval": "3600",
    "enable_syslog": "false"
  },
  "platform": "linux",
  "schedule": {
    "process_events": {
      "query": "SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events WHERE path NOT IN ('/bin/sed', '/usr/bin/tr', '/bin/gawk', '/bin/date', '/bin/mktemp', '/usr/bin/dirname', '/usr/bin/head', '/usr/bin/jq', '/bin/cut', '/bin/uname', '/bin/basename') and cmdline NOT LIKE '%_key%' AND cmdline NOT LIKE '%secret%';",
      "interval": 10
    },
    "socket_events": {
      "query": "SELECT action, auid, family, local_address, local_port, path, pid, remote_address, remote_port, success, time FROM socket_events WHERE success=1 AND path NOT IN ('/usr/bin/hostname') AND remote_address NOT IN ('127.0.0.1', '169.254.169.254', '', '0000:0000:0000:0000:0000:0000:0000:0001', '::1', '0000:0000:0000:0000:0000:ffff:7f00:0001', 'unknown', '0.0.0.0', '0000:0000:0000:0000:0000:0000:0000:0000');",
      "interval": 10
    },
    "disk_space": {
      "query": "select path, round((blocks_available * blocks_size *10e-10),2) as gigs_free, round((blocks_free*1.0/blocks * 100),2) as percent_free from mounts where path='/';",
      "interval": 300
    },
    "python_packages": {
      "query": "SELECT * FROM python_packages;",
      "interval": 300
    }
  }
}
Next, I did tail -f /var/log/syslog | grep osquery  then started osqueryd with systemctl start osqueryd let it run for 30 seconds to get.CptOfEvilMinions
06/17/2020, 6:02 PMFran Rodríguez
06/17/2020, 6:02 PMFran Rodríguez
06/17/2020, 6:02 PMFran Rodríguez
06/17/2020, 6:03 PMFran Rodríguez
06/17/2020, 6:06 PMFran Rodríguez
06/17/2020, 6:06 PMFran Rodríguez
06/17/2020, 6:06 PMFran Rodríguez
06/17/2020, 6:08 PMCptOfEvilMinions
06/17/2020, 6:11 PMFran Rodríguez
06/17/2020, 6:13 PMFran Rodríguez
06/18/2020, 4:01 PMFran Rodríguez
06/18/2020, 4:02 PMFran Rodríguez
06/18/2020, 4:02 PMCptOfEvilMinions
06/18/2020, 4:29 PM