• Basic search to find Log4J running on hosts from the DataLake

    CraigJones
    CraigJones
    • Compliance
    • Approved on 13 Dec 2021
    • 30 Comments
    Basic search which lists processes that include log4j in the cmdline> on Windows, Mac and Linux. The query returns a lot of results but works for an insight into what's running on the estate. SELECT meta_hostname AS ep_name, name, cmdline, path...
    • 13 Dec 2021 4:22 PM
  • Identify vulnerable Log4j Apache components

    Qoosh
    Qoosh
    • Compliance
    • Approved on 13 Dec 2021
    • 28 Comments
    Note: This query is designed for Linux only. For a basic search which lists processes called Log4J on Windows, Mac and Linux, please view this query. This query helps customers identify vulnerable Log4J components in their environment. It shows Log4J...
    • 10 Dec 2021 5:36 PM
  • List Office Macro documents touched on a client computer (from Data Lake)

    LHerzog
    LHerzog
    • Files
    • Under Review on 9 Dec 2021
    • 4 Comments
    Hi, this Data Lake query finds all Office Documents by file name in a given time frame and on specific host or all hosts (wildcard) and only those, that have not been touched by a specific process (e.g. dropbox.exe) Unfortunately it does not find...
    • 9 Dec 2021 4:28 PM
  • Query for System Reboots/Shutdowns

    JeramyKopacko
    JeramyKopacko
    • Events
    • Approved on 6 Dec 2021
    • 1 Comment
    Posted this for easier access as I am sharing it with another community user who looked for this functionality: SELECT DISTINCT eventid, CASE eventid WHEN '41' THEN 'Rebooted without clean shutdown' WHEN '1074' THEN 'Shutdown properly by user...
    • 6 Dec 2021 5:44 PM
  • Live Discovery Query for Event log - system reboots

    Chad Tracy
    Chad Tracy
    • Events
    • Complete on 6 Dec 2021
    • 1 Comment
    Hello. I am not sure I even have this messages going to the right group. I am trying to find a query I can use that will show me a timestamp for when a machine reboots. Any help you can provide would be greatly appreciated. Best Chad
    • 6 Dec 2021 5:10 PM
  • Compare IP activity to Remote List of IOC IP addresses

    Spencer_Brown
    Spencer_Brown
    • Threat Hunting
    • Under Review on 2 Dec 2021
    • 0 Comments
    Utilizing a post from Karl_Ackerman and the precanned queries in Sophos Central, here is a query that can pull down a remote csv table, and join it to the sophos_ip_journal. It takes one variable: URL -- String -- $$URL$$ In this use case, I took...
    • 2 Dec 2021 10:56 PM
  • List all NIX processes during a boot session

    Karl_Ackerman
    Karl_Ackerman
    • Threat Hunting
    • Approved on 16 Nov 2021
    • 0 Comments
    Given a time we want to list all processes that ran during the boot session. -- This will take a few steps. First lets narrow down the time range ---------------------- -- DETERMINE THE LOWER AND UPPER TIME LIMITS FOR THE SOPHOS_PID -------...
    • 16 Nov 2021 9:25 PM
  • NIX TTP Detector (MITRE ATT&CK)

    Karl_Ackerman
    Karl_Ackerman
    • Threat Hunting
    • Approved on 16 Nov 2021
    • 0 Comments
    Below is a query to classify activity to MITRE for NIX machines (LINUX and MAC). It runs against the data lake The detection risk level has not been tuned, so you will need to edit the query in your environment. /*******************************...
    • 16 Nov 2021 8:49 PM
  • Rare process trees with a LOLBIN tool

    Karl_Ackerman
    Karl_Ackerman
    • Threat Hunting
    • Approved on 16 Nov 2021
    • 0 Comments
    With leadless threat hunting where you are simply looking for strange activity in the environment to determine if it is an as yet undiscovered adversary it is often valuable identify things that are RARE or UNIQUE. With the Rare Tree query below we...
    • 16 Nov 2021 8:33 PM
  • List Installed Deb Packages on Debian/Ubuntu Linux Serve

    benjm
    benjm
    • Device
    • Approved on 18 May 2022
    • 0 Comments
    SELECT name "Package name", version "Package version", source "Package source", size "Package size in bytes", arch "Package architecture", revision "Package revision" FROM deb_packages
    • 3 Nov 2021 6:05 PM
<>