Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#kolide
Title
# kolide
e
Esteban
10/19/2020, 6:39 PM
Is any option to import query packs (or queries) from the console? I've got all the .conf files
z
zwass
10/19/2020, 6:41 PM
Yeah, use
fleetctl convert
e
Esteban
10/19/2020, 6:45 PM
Only, fleetctl convert -f [File], file being my .conf with the pack and queries defined
z
zwass
10/19/2020, 6:46 PM
Yeah
e
Esteban
10/19/2020, 6:49 PM
I'm not seeing any new packs or queries after executing the command
File used:
https://raw.githubusercontent.com/teoseller/osquery-attck/master/windows_service-persistence.conf
Or it only outputs a formatted configuration to use? Where should i paste the outputted text?
z
zwass
10/19/2020, 6:53 PM
You can put it into a file and use
fleetctl apply
to provide it to the Fleet server.
e
Esteban
10/19/2020, 6:55 PM
Perfect, thank you!
🍻 1
2 Views
Post