@@ -6,285 +6,285 @@ spec:
6
6
queries :
7
7
- description : ' Query to monitor files for changes inside of /etc/emon.d/ or /private/var/db/emondClients/
8
8
which can be used for persistence: (https://www.xorrior.com/emond-persistence/)'
9
- interval : 0
9
+ interval : 3600
10
10
name : emond
11
11
platform : darwin
12
12
query : emond
13
13
- description : ' Snapshot query to monitor files for changes inside of /etc/emon.d/
14
14
or /private/var/db/emondClients/ which can be used for persistence: (https://www.xorrior.com/emond-persistence/)'
15
- interval : 0
15
+ interval : 28800
16
16
name : emond_snapshot
17
17
platform : darwin
18
18
query : emond_snapshot
19
19
snapshot : true
20
20
- description : Track time/action changes to files specified in configuration data.
21
- interval : 0
21
+ interval : 300
22
22
name : file_events
23
23
platform : darwin
24
24
query : file_events
25
25
removed : false
26
26
- description : The installed homebrew package database.
27
- interval : 0
27
+ interval : 28800
28
28
name : homebrew_packages_snapshot
29
29
platform : darwin
30
30
query : homebrew_packages_snapshot
31
31
snapshot : true
32
32
- description : List kernel extensions, their signing status, and their hashes (excluding
33
33
extensions signed by Apple)
34
- interval : 0
34
+ interval : 3600
35
35
name : macosx_kextstat
36
36
platform : darwin
37
37
query : macosx_kextstat
38
38
- description : Checks the MD5 hash of /etc/rc.common and records the results if
39
39
the hash differs from the default value. /etc/rc.common can be used for persistence.
40
- interval : 0
40
+ interval : 3600
41
41
name : rc.common
42
42
platform : darwin
43
43
query : rc.common
44
44
- description : Returns information about installed event taps. Can be used to detect
45
45
keyloggers
46
- interval : 0
46
+ interval : 300
47
47
name : event_taps
48
48
platform : darwin
49
49
query : event_taps
50
50
- description : LaunchAgents and LaunchDaemons from default search paths.
51
- interval : 0
51
+ interval : 3600
52
52
name : launchd
53
53
platform : darwin
54
54
query : launchd
55
55
- description : Snapshot query for launchd
56
- interval : 0
56
+ interval : 28800
57
57
name : launchd_snapshot
58
58
platform : darwin
59
59
query : launchd_snapshot
60
60
snapshot : true
61
61
- description : Detect the presence of the LD_PRELOAD environment variable
62
- interval : 0
62
+ interval : 60
63
63
name : ld_preload
64
64
platform : darwin
65
65
query : ld_preload
66
66
removed : false
67
67
- description : USB devices that are actively plugged into the host system.
68
- interval : 0
68
+ interval : 300
69
69
name : usb_devices
70
70
platform : darwin
71
71
query : usb_devices
72
72
- description : System mounted devices and filesystems (not process specific).
73
- interval : 0
73
+ interval : 3600
74
74
name : mounts
75
75
platform : darwin
76
76
query : mounts
77
77
removed : false
78
78
- description : Apple NVRAM variable listing.
79
- interval : 0
79
+ interval : 3600
80
80
name : nvram
81
81
platform : darwin
82
82
query : nvram
83
83
removed : false
84
84
- description : Line parsed values from system and user cron/tab.
85
- interval : 0
85
+ interval : 3600
86
86
name : crontab
87
87
platform : darwin
88
88
query : crontab
89
89
- description : Hardware (PCI/USB/HID) events from UDEV or IOKit.
90
- interval : 0
90
+ interval : 300
91
91
name : hardware_events
92
92
platform : darwin
93
93
query : hardware_events
94
94
removed : false
95
95
- description : The installed homebrew package database.
96
- interval : 0
96
+ interval : 3600
97
97
name : homebrew_packages
98
98
platform : darwin
99
99
query : homebrew_packages
100
100
- description : OS X applications installed in known search paths (e.g., /Applications).
101
- interval : 0
101
+ interval : 3600
102
102
name : installed_applications
103
103
platform : darwin
104
104
query : installed_applications
105
105
- description : System logins and logouts.
106
- interval : 0
106
+ interval : 3600
107
107
name : last
108
108
platform : darwin
109
109
query : last
110
110
removed : false
111
111
- description : Snapshot query for macosx_kextstat
112
- interval : 0
112
+ interval : 28800
113
113
name : macosx_kextstat_snapshot
114
114
platform : darwin
115
115
query : macosx_kextstat_snapshot
116
116
snapshot : true
117
117
- description : Checks the MD5 hash of /etc/rc.common and records the results if
118
118
the hash differs from the default value. /etc/rc.common can be used for persistence.
119
- interval : 0
119
+ interval : 28800
120
120
name : rc.common_snapshot
121
121
platform : darwin
122
122
query : rc.common_snapshot
123
123
snapshot : true
124
124
- description : Safari browser extension details for all users.
125
- interval : 0
125
+ interval : 3600
126
126
name : safari_extensions
127
127
platform : darwin
128
128
query : safari_extensions
129
129
- description : suid binaries in common locations.
130
- interval : 0
130
+ interval : 28800
131
131
name : suid_bin
132
132
platform : darwin
133
133
query : suid_bin
134
134
removed : false
135
135
- description : Local system users.
136
- interval : 0
136
+ interval : 28800
137
137
name : users
138
138
platform : darwin
139
139
query : users
140
140
- description : List authorized_keys for each user on the system
141
- interval : 0
141
+ interval : 28800
142
142
name : authorized_keys
143
143
platform : darwin
144
144
query : authorized_keys
145
145
- description : Application, System, and Mobile App crash logs.
146
- interval : 0
146
+ interval : 3600
147
147
name : crashes
148
148
platform : darwin
149
149
query : crashes
150
150
removed : false
151
151
- description : Displays the percentage of free space available on the primary disk
152
152
partition
153
- interval : 0
153
+ interval : 3600
154
154
name : disk_free_space_pct
155
155
platform : darwin
156
156
query : disk_free_space_pct
157
157
snapshot : true
158
158
- description : Retrieve the interface name, IP address, and MAC address for all
159
159
interfaces on the host.
160
- interval : 0
160
+ interval : 600
161
161
name : network_interfaces_snapshot
162
162
platform : darwin
163
163
query : network_interfaces_snapshot
164
164
snapshot : true
165
165
- description : Information about EFI/UEFI/ROM and platform/boot.
166
- interval : 0
166
+ interval : 28800
167
167
name : platform_info
168
168
platform : darwin
169
169
query : platform_info
170
170
removed : false
171
171
- description : System uptime
172
- interval : 0
172
+ interval : 1800
173
173
name : uptime
174
174
platform : darwin
175
175
query : uptime
176
176
snapshot : true
177
177
- description : MD5 hash of boot.efi
178
- interval : 0
178
+ interval : 28800
179
179
name : boot_efi_hash
180
180
platform : darwin
181
181
query : boot_efi_hash
182
182
- description : Snapshot query for Chrome extensions
183
- interval : 0
183
+ interval : 28800
184
184
name : chrome_extensions_snapshot
185
185
platform : darwin
186
186
query : chrome_extensions_snapshot
187
187
- description : Snapshot query for installed_applications
188
- interval : 0
188
+ interval : 28800
189
189
name : installed_applications_snapshot
190
190
platform : darwin
191
191
query : installed_applications_snapshot
192
192
snapshot : true
193
193
- description : NFS shares exported by the host.
194
- interval : 0
194
+ interval : 3600
195
195
name : nfs_shares
196
196
platform : darwin
197
197
query : nfs_shares
198
198
removed : false
199
199
- description : List the version of the resident operating system
200
- interval : 0
200
+ interval : 28800
201
201
name : os_version
202
202
platform : darwin
203
203
query : os_version
204
204
- description : Applications and binaries set as user/login startup items.
205
- interval : 0
205
+ interval : 3600
206
206
name : startup_items
207
207
platform : darwin
208
208
query : startup_items
209
209
- description : All C/NPAPI browser plugin details for all users.
210
- interval : 0
210
+ interval : 3600
211
211
name : browser_plugins
212
212
platform : darwin
213
213
query : browser_plugins
214
214
- description : List installed Firefox addons for all users
215
- interval : 0
215
+ interval : 3600
216
216
name : firefox_addons
217
217
platform : darwin
218
218
query : firefox_addons
219
219
- description : Discover hosts that have IP forwarding enabled
220
- interval : 0
220
+ interval : 28800
221
221
name : ip_forwarding_enabled
222
222
platform : darwin
223
223
query : ip_forwarding_enabled
224
224
removed : false
225
225
- description : Platform info snapshot query
226
- interval : 0
226
+ interval : 28800
227
227
name : platform_info_snapshot
228
228
platform : darwin
229
229
query : platform_info_snapshot
230
230
- description : Python packages installed in a system.
231
- interval : 0
231
+ interval : 3600
232
232
name : python_packages
233
233
platform : darwin
234
234
query : python_packages
235
235
- description : List installed Chrome Extensions for all users
236
- interval : 0
236
+ interval : 3600
237
237
name : chrome_extensions
238
238
platform : darwin
239
239
query : chrome_extensions
240
240
- description : Disk encryption status and information.
241
- interval : 0
241
+ interval : 3600
242
242
name : disk_encryption
243
243
platform : darwin
244
244
query : disk_encryption
245
245
- description : Local system users.
246
- interval : 0
246
+ interval : 28800
247
247
name : users_snapshot
248
248
platform : darwin
249
249
query : users_snapshot
250
250
- description : OS X known/remembered Wi-Fi networks list.
251
- interval : 0
251
+ interval : 28800
252
252
name : wireless_networks
253
253
platform : darwin
254
254
query : wireless_networks
255
255
removed : false
256
256
- description : Determine if the host is running the expected EFI firmware version
257
257
given their Mac hardware and OS build version (https://github.com/duo-labs/EFIgy)
258
- interval : 0
258
+ interval : 28800
259
259
name : efigy
260
260
platform : darwin
261
261
query : efigy
262
262
snapshot : true
263
263
- description : List the contents of /etc/hosts
264
- interval : 0
264
+ interval : 28800
265
265
name : etc_hosts
266
266
platform : darwin
267
267
query : etc_hosts
268
268
- description : Operating system version snapshot query
269
- interval : 0
269
+ interval : 28800
270
270
name : os_version_snapshot
271
271
platform : darwin
272
272
query : os_version_snapshot
273
273
snapshot : true
274
274
- description : Information about the resident osquery process
275
- interval : 0
275
+ interval : 28800
276
276
name : osquery_info
277
277
platform : darwin
278
278
query : osquery_info
279
279
snapshot : true
280
280
- description : Apple's System Integrity Protection (rootless) status.
281
- interval : 0
281
+ interval : 3600
282
282
name : sip_config
283
283
platform : darwin
284
284
query : sip_config
285
285
- description : Returns the private keys in the users ~/.ssh directory and whether
286
286
or not they are encrypted.
287
- interval : 0
287
+ interval : 3600
288
288
name : user_ssh_keys
289
289
platform : darwin
290
290
query : user_ssh_keys
0 commit comments