Skip to content

Commit b6543db

Browse files
committed
shellbags artifact
1 parent 43e4d46 commit b6543db

File tree

2 files changed

+66
-9
lines changed

2 files changed

+66
-9
lines changed

packages/osquery_manager/artifacts_matrix.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,20 +2,20 @@
22

33
This document tracks the coverage of forensic artifacts in Osquery.
44

5-
**Last Updated**: 2025-11-07
6-
**Total Core Artifacts**: 1 available + 39 in progress + 6 not available = 46 total variants
7-
**Total Queries**: 30 (3 core forensic variants + 27 additional)
8-
**Completion Rate**: 2.2% (1/46 core artifacts fully supported)
5+
**Last Updated**: 2025-11-20
6+
**Total Core Artifacts**: 1 available + 38 in progress + 6 not available = 45 total variants
7+
**Total Queries**: 31 (1 core forensic variant + 30 additional)
8+
**Completion Rate**: 2.2% (1/45 core artifacts fully supported)
99

1010
---
1111

1212
## Coverage Summary
1313

1414
| Status | Count | Percentage |
1515
|--------|-------|------------|
16-
| ✅ Available (Fully Supported) | 0 | 0% |
17-
| ⚠️ In Progress (Needs Validation) | 39 | 87.0% |
18-
| ❌ Not Available (Requires Extensions) | 6 | 13.0% |
16+
| ✅ Available (Fully Supported) | 1 | 2.2% |
17+
| ⚠️ In Progress (Needs Validation) | 38 | 84.4% |
18+
| ❌ Not Available (Requires Extensions) | 6 | 13.3% |
1919

2020
---
2121

@@ -61,7 +61,7 @@ This document tracks the coverage of forensic artifacts in Osquery.
6161
| 18 | Registry | ⚠️ | Win | - | - | registry table |
6262
| 19 | Shell History | ⚠️ | Linux | - | - | shell_history table |
6363
| 19a | Shell History | ⚠️ | Mac | - | - | shell_history table |
64-
| 20 | Shellbags | ⚠️ | Win | - | - | shellbags table |
64+
| 20 | Shellbags | | Win | shellbags_windows_elastic | [a4b2](kibana/osquery_saved_query/osquery_manager-a4b2c8d0-8876-11f0-b4d1-4f9e8c3a1b2e.json) | shellbags table - tracks directory access via Windows Explorer |
6565
| 21 | Tasks | ⚠️ | Win | - | - | scheduled_tasks table |
6666
| 21a | Tasks | ⚠️ | Linux | - | - | scheduled_tasks table |
6767
| 21b | Tasks | ⚠️ | Mac | - | - | scheduled_tasks table |
@@ -169,7 +169,7 @@ While some artifacts are not directly available, the existing queries provide st
169169
### User Activity
170170
- ⚠️ LNK files (Windows: shortcut_files, file, recent_files tables)
171171
- ⚠️ Shell History (Linux/Mac: shell_history table)
172-
- ⚠️ Shellbags (Windows: shellbags table)
172+
- Shellbags (Windows: shellbags table)
173173
- ⚠️ User Assist (Windows: userassist table)
174174
- ⚠️ Browser URL History (All platforms: via ATC custom tables)
175175
- ❌ Jumplists (Not Available - Use Shellbags + LNK Files as alternatives)
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
{
2+
"attributes": {
3+
"created_at": "2025-11-20T00:00:00.000Z",
4+
"created_by": "elastic",
5+
"description": "Windows Shellbags forensic analysis - tracks directories accessed via Windows Explorer for user activity investigation. Useful for identifying folder browsing history and user behavior patterns.",
6+
"ecs_mapping": [
7+
{
8+
"key": "user.id",
9+
"value": {
10+
"field": "sid"
11+
}
12+
},
13+
{
14+
"key": "registry.hive",
15+
"value": {
16+
"field": "source"
17+
}
18+
},
19+
{
20+
"key": "file.path",
21+
"value": {
22+
"field": "path"
23+
}
24+
},
25+
{
26+
"key": "file.mtime",
27+
"value": {
28+
"field": "modified_time"
29+
}
30+
},
31+
{
32+
"key": "file.created",
33+
"value": {
34+
"field": "created_time"
35+
}
36+
},
37+
{
38+
"key": "file.accessed",
39+
"value": {
40+
"field": "accessed_time"
41+
}
42+
}
43+
],
44+
"id": "shellbags_windows_elastic",
45+
"interval": "3600",
46+
"query": "SELECT\n sid,\n source,\n path,\n modified_time,\n created_time,\n accessed_time,\n mft_entry,\n mft_sequence\nFROM shellbags\nWHERE path != '' AND path IS NOT NULL\nORDER BY modified_time DESC;",
47+
"platform": "windows",
48+
"updated_at": "2025-11-20T00:00:00.000Z",
49+
"updated_by": "elastic"
50+
},
51+
"coreMigrationVersion": "8.3.0",
52+
"id": "osquery_manager-a4b2c8d0-8876-11f0-b4d1-4f9e8c3a1b2e",
53+
"references": [],
54+
"type": "osquery-saved-query",
55+
"updated_at": "2025-11-20T00:00:00.000Z",
56+
"version": "WzEsMV0="
57+
}

0 commit comments

Comments
 (0)