Emory L. · @emory
180 followers · 1853 posts · Server soc.kvet.ch

@qwxlea @dhrystone @EpiphanicSynchronicity

i use 1blocker on safari but i also have a whole-house dns server that consults adguard home and it's been great. my biggest concern there is the scareware shit that is usually a variation of OMG TAP HERE FOR MY EXPLOIT BEFORE SOME OTHER SCUMBAG ROOTS YOU!1 attacks.

but i also have UTM in-line, and iot on its own vlans, a honeynet, so, if someone wants to james bond me with a 0day, i'm honored, but i will write and publish an for

#ioc #osquery

Last updated 2 years ago

Jeremy Beker · @gothmog
126 followers · 296 posts · Server xoxo.zone

Hello friends! If you are curious about open source contributions, go see my amazing coworker @cc_codes at Nebraska.code() in July. Her keynote, The Power of Open-Source: How To Contribute To and Manage Communities, will be super interesting!

nebraskacode.amegala.com

#opensource #osquery #dev

Last updated 2 years ago

Håkon O. · @eselet
248 followers · 539 posts · Server snabelen.no

The default password policy on isn't really that impressive. But is definitely impressive.

#macos #osquery #infosec

Last updated 2 years ago

chmod777 :donor:​ · @chmod777
355 followers · 569 posts · Server infosec.exchange

Played with OSQuery today for the 1st time. I had no idea this was created by Facebook (now Meta). Prior to messing with it on TryHackMe, I've never heard of it.

Is this tool used widely in the infosec community?



#osqueryi #osquery #tryhackme

Last updated 2 years ago

Håkon O. · @eselet
247 followers · 524 posts · Server snabelen.no

An generated for the featuring , , and a manager in dispair. (1/4)

#infosec #ai #poetry #thread #weekend #osquery #Splunk #sentinel #finance

Last updated 2 years ago

osquery-defense-kit v1.8.0 is out & is our biggest release ever, containing 60+ new queries and proper CI! github.com/chainguard-dev/osqu

This is the first release that's tuned to work well on VM-based environments and the first with generalized detection.

#rootkit #linux #osquery

Last updated 2 years ago

osqtool v1.2.0 is out & stable: if you've ever had to work with pack files, it probably has something for you! github.com/chainguard-dev/osqt

New is a simple "run" command for osquery pack files or directories of queries.

#osquery

Last updated 2 years ago

Josh Lemon · @joshlemon
130 followers · 29 posts · Server infosec.exchange

Some of our brilliant team members, Amit Malik and Pratik Jeware from Uptycs, talking about and the ways to leverage for detection at Nullcon.


youtu.be/UjttDseKXaA

#threatintel #macos #malware #osquery #threatdetection #dfir

Last updated 2 years ago

I'm pretty proud of this query, as it's the culmination of tricks I've learned over the last 6 months: github.com/chainguard-dev/osqu

In particular, the multiple unnatural joins using synthetically concatenated data; used to find the download URL for a likely matching DMG + finding paths to apps located within the mounts.

The downside is that if a mounted disk image has a symlink to "/" or "/Applications", the query will follow it due to limitations, which causes a performance hit.

#osquery

Last updated 2 years ago

Matt Franz · @mdfranz
227 followers · 504 posts · Server infosec.exchange

Wow. Super impressed with Fleet once I figured out to use the --insecure option to not fight with cert errors on my home network. The most amazing thing was how fleetctl downloaded Docker images on a Linux box to create the MSI installer for my Windows 10 hosts 👏​ -- next on to see if works on ARM Linux

#osquery

Last updated 2 years ago

Introducing v1.0: github.com/chainguard-dev/osqt

It's a swiss-army tool for testing, creating, and manipulating query packs.

Got a directory full of SQL files and want to archive it into a query pack?

`osqtool pack <directory>`

want to ensure that none of the queries in it will consume more than 15 minutes across a day of querying by multiplying the interval vs runtime duration?

`osqtool -max-query-daily-duration=15m verify <pack|directory>`

Go forth and enjoy!

#osquery #osqtool

Last updated 2 years ago

Gerry Gosselin :donor: · @snafui
60 followers · 153 posts · Server infosec.exchange

Security folks, does osquery have a role in your security life? In what way?

I’d been aware of it and it seemed impressive. Finally, yesterday I gave it a go on my desktop and I really dig it. But I’m not sure what I ultimately could or should do with it at an enterprise scale with a distributed workforce. I talked to someone who forked it and used it as EDR which was cool. Telemetry plus inventory querying in the same agent. I can get behind that. Any other fancy use cases out there?

#osquery

Last updated 2 years ago

defense kit v1.6.0 just dropped with some new queries:

- unencrypted service account keys
- unexpected calls
- unexpected calls
- unexpected file made
- unexpected Security.Framework program

If nothing else, I hope the queries are useful ideas for others! Have a great weekend. 🌴

#executable #xattr #sysctl #gcp #blueteam #osquery

Last updated 2 years ago

I wrote my first CFPsince the pandemic, for - a local InfoSec conference.

Working title: "Uncovering nation-state actors with "

#osquery #cackalackycon

Last updated 2 years ago

New blog post outlining some of the techniques we use with

unfinished.bike/behavioral-det

#osquery #detection

Last updated 2 years ago

Tyson, Chicken Rancher 🐓 · @tsupasat
110 followers · 507 posts · Server infosec.exchange

@bea We had a lot of good speakers talking about how they're using at places like Netflix, Hashicorp, and Stripe. Videos should be released in the next few weeks. You could also ask on the osquery Slack channel.

osqueryatscale.com/

join.slack.com/t/osquery/share

#osquery

Last updated 2 years ago

Happy to see awesome tools like MISP (17th), Wireshark, Atomic Read Team, OSQUERY and wazuh on this list: opensourcesecurityindex.io/

#misp #Atomicredteam #wazuh #wireshark #sigma #osquery

Last updated 2 years ago

grep_security · @grep_security
93 followers · 80 posts · Server infosec.exchange

@enscroot If you want to detect based on the Mutex then you could use

"select object_name, object_type from winbaseobj where object_type = 'Mutant' AND object_name LIKE %mutant--regex-%"

#osquery

Last updated 2 years ago

bEA 🔓 · @bea
722 followers · 192 posts · Server infosec.exchange

Hey , are people still rolling out osquery for things? I’ve seen a couple of projects for deploying it at/on kubernininis, but nothing has really convinced me they’re super well matched?

#infosec #osquery #hashtags

Last updated 2 years ago

grep_security · @grep_security
33 followers · 27 posts · Server infosec.exchange

@ackroyd Nice, some of the CobaltStrike rules recently released by Chronicle would detect. Will shortly publish a few queries for BRC4 detection.

#osquery

Last updated 2 years ago