• firefox_addons

    Karl_Ackerman
    Karl_Ackerman
    • Coming Soon on 13 Oct 2020
    • 0 Comments
    Firefox addons from devices with that browser If you do not have firefox on any devices like me then you will not have any data, if someone could test that would be great. Schema: creator string Addon-supported creator string description...
    • 13 Oct 2020 8:05 PM
  • vulnerability_app_compatibility

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    This detects a potential vulnerability in application compatibility mode being set https://www.itnews.com.au/news/windows-compatibility-mode-resurfaces-old-flaws-473058 Schema analysis string JSON object representing the analysis ...
    • 14 Oct 2020 1:22 PM
  • windows_event_dos_attack_detected

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    windows_event_dos_attack_detected SCHEMA description string Plugin description text eventid int The Windows event ID provider_name string The Windows event provider source string The Windows event source ...
    • 14 Oct 2020 7:39 PM
  • launchd_md5

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 13 Oct 2020
    • 0 Comments
    This collects the SHA256 and SHA1 has of launchd processes on LINUX and no I do not know why the scheduled query has an MD5 in the name seeing as we do not get the MD5 value. launchd launchd has two main tasks. The first is to boot the system, and...
    • 13 Oct 2020 10:01 PM
  • user_events_linux

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    Linux user events SCHEMA address string IPv4 address target audit_type int The file description for the process socket message string Message from the event path string Full path to the value pid long...
    • 14 Oct 2020 1:18 PM
  • windows_event_successful_logon

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    windows_event_successful_logon SCHEMA authentication_package string The name of the authentication package which was used for the logon description string Plugin description text event_timestamps string List of times...
    • 14 Oct 2020 7:53 PM
  • pending_osx_updates_patch

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    List pending updates/patch for MAC os x SCHEMA package_id string Label packageIdentifiers recommended string recommended restart string restart size long Size of the update title string Title of the...
    • 14 Oct 2020 12:31 PM
  • running_processes_windows_sophos

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    Windows process history SCHEMA cmdline string Process command line file_size long File size now gid long Group ID (unsigned) of the user running the process global_rep int The machine learning global reputation...
    • 14 Oct 2020 12:46 PM
  • threat_promisc_interfaces_linux

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    Detect promiscuous interfaces on LInux https://en.wikipedia.org/wiki/Promiscuous_mode SCHEMA flags int Flags (netdevice) for the device interface string Interface name loopback long Loopback interface mac string...
    • 14 Oct 2020 1:08 PM
  • vulnerability_weak_algorithms

    Karl_Ackerman
    Karl_Ackerman
    • Under Review on 14 Oct 2020
    • 0 Comments
    vulnerability_weak_algorithms SCHEMA data string Data content of registry value key string Name of the key mtime long time of the most recent registry write name string Name of the registry value entry ...
    • 14 Oct 2020 7:27 PM
<>