• Queries from the March SophSkills presentation

    • Approved on
    • 1 Comment
    Video: https://vimeo.com/519661823 Queries used: Queries used during SophSkills Demo DATA LAKE - List all EP and FW tables in the data lake This query will need to run against the data lake. As we add more sensors to the data lake we will be extending...
  • Sophos Central Azure AD, MFA Device Registration

    • Under Review on
    • 0 Comments
    Is it possible to query for new MFA device registration for an user in azure ad?
  • vulnerability_kernel_null_page_access

    • Under Review on
    • 0 Comments
    vulnerability_kernel_null_page_access SCHEMA analysis string JSON object representing the analysis data string Data content of registry value key string Name of the key mtime long time of the most recent registry...
  • open_sockets

    • Under Review on
    • 0 Comments
    List open socket info SCHEMA cmdline string Process command line local_address string Socket local address name string Name of the registry value entry parent long Process parent's PID path string ...
  • windows_event_user_account_created

    • Under Review on
    • 0 Comments
    windows_event_user_account_created SCHEMA user_workstations string Contains the list of NetBIOS or DNS names of the computers from which the user can logon. account_expires string The date when the account expires allowed_to_delegate_to...
  • pending_windows_updates_patch

    • Under Review on
    • 0 Comments
    Pending windows updates/patches SCHEMA hotfix_id string The kb article ID for the update installed string Is the update installed mandatory string Is the update mandatory msrc_severity string Severity of the...
  • installed_applications

    • Coming Soon on
    • 0 Comments
    List installed applications Windows. This will show applications added to the windows system during the data lake period (Default is 7 days) It needs to be tested SCHEMA bundle_executable string Info properties CFBundleExecutable label...
  • Application Inventory Query

    • Under Review on
    • 0 Comments
    I thought I had already published this one and if I can't find it I suspect others have that same challenge. This was from one of the videos to show how the data lake can go broad and the devices dive deep. -- Application Inventory across all devices...
  • windows_startup_programs_md5

    • Under Review on
    • 0 Comments
    windows_startup_programs_md5 SCHEMA core_file_info string Core file info file_size long File size now global_rep int The machine learning global reputation now global_rep_data string All global reputation data...
  • windows_programs

    • Under Review on
    • 0 Comments
    windows_programs SCHEMA identifying_number string Product identification such as a serial number on software, or a die number on a hardware chip install_date string Date that this product was installed on the system install_source...