forked from teoseller/osquery-attck
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathwindows_generic_detection.conf
67 lines (67 loc) · 2.07 KB
/
windows_generic_detection.conf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
{
"platform": "windows",
"description": "ATT&CK: T1136,T1078,T1116,T1075,T1097",
"queries": {
"system_info": {
"query": "SELECT * FROM system_info;",
"interval": 3600,
"description": "System information for identification."
},
"system_info_snapshot": {
"query": "SELECT * FROM system_info;",
"interval": 28800,
"description": "System info snapshot query",
"snapshot": true
},
"uptime": {
"query": "SELECT * FROM uptime;",
"interval": 28800,
"description": "System uptime",
"snapshot": true
},
"programs": {
"query": "SELECT * FROM users;",
"interval": 3600,
"description": "Local system users."
},
"programs_snapshot": {
"query": "select * from programs;",
"interval": 28800,
"description": "Local system users.",
"snapshot": true
},
"logged_in_users": {
"query": "select * from logged_in_users;",
"interval": 3600,
"description": "Users with an active shell on the system. - ATT&CK T1075,T1097"
},
"users": {
"query": "SELECT * FROM users;",
"interval": 3600,
"description": "Local system users. - ATT&CK T1136,T1078"
},
"users_snapshot": {
"query": "SELECT * FROM users;",
"interval": 28800,
"description": "Users snapshot query - ATT&CK T1136,T1078",
"snapshot": true
},
"certificates": {
"query": "select * from certificates;",
"interval": 3600,
"description": "Local system users. - ATT&CK T1116,T1130"
},
"certificates_snapshot": {
"query": "select * from certificates;",
"interval": 28800,
"description": "Users snapshot query - ATT&CK T1116,T1130",
"snapshot": true
},
"windows_crashes": {
"query": "SELECT * FROM windows_crashes;",
"interval": 3600,
"description": "Extracted information from Windows crash logs (Minidumps).",
"removed": false
}
}
}