Browse Rules

Search and filter across all detection sources

21 rules

wazuh low xml

osquery: $(osquery.pack) query result

osquery: $(osquery.pack) query result

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Browser plugin $(osquery.columns.name) is enabled

osquery: $(osquery.pack) $(osquery.subquery): Browser plugin $(osquery.columns.name) is enabled

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Browser plugin $(osquery.columns.name) is disabled

osquery: $(osquery.pack) $(osquery.subquery): Browser plugin $(osquery.columns.name) is disabled

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Sparkle bundle $(osquery.columns.name) is unauthenticated

osquery: $(osquery.pack) $(osquery.subquery): Sparkle bundle $(osquery.columns.name) is unauthenticated

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Python package $(osquery.columns.package_name) is backdoored

osquery: $(osquery.pack) $(osquery.subquery): Python package $(osquery.columns.package_name) is backdoored

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Kernel module $(osquery.columns.name) version $(osquery.columns.version)

osquery: $(osquery.pack) $(osquery.subquery): Kernel module $(osquery.columns.name) version $(osquery.columns.version)

panther high python

A backdoored version of XZ or liblzma is vulnerable to CVE-2024-3094

Detects vulnerable versions of XZ and liblzma on Linux and MacOS using Osquery logs. Versions 5.6.0 and 5.6.1 of xz and liblzma are most likely vulnerable to backdoor exploit. Vuln management pack must be enabled: https://github.com/osquery/osquery/blob/master/packs/vuln-management.conf

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Homebrew package $(osquery.columns.name) version is $(osquery.columns.version)

osquery: $(osquery.pack) $(osquery.subquery): Homebrew package $(osquery.columns.name) version is $(osquery.columns.version)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Portage package $(osquery.columns.package) $(osquery.columns.version) USE flags $(osquery.columns.flags)

osquery: $(osquery.pack) $(osquery.subquery): Portage package $(osquery.columns.package) $(osquery.columns.version) USE flags $(osquery.columns.flags)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): RPM package $(osquery.columns.name) version $(osquery.columns.version) is installed on the system

osquery: $(osquery.pack) $(osquery.subquery): RPM package $(osquery.columns.name) version $(osquery.columns.version) is installed on the system

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OS Kernel module $(osquery.columns.name) is enabled and used by $(osquery.columns.used_by)

osquery: $(osquery.pack) $(osquery.subquery): OS Kernel module $(osquery.columns.name) is enabled and used by $(osquery.columns.used_by)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OSX package recepit $(osquery.columns.package_id) $(osquery.columns.version) is installed on the system

osquery: $(osquery.pack) $(osquery.subquery): OSX package recepit $(osquery.columns.package_id) $(osquery.columns.version) is installed on the system

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OS $(osquery.columns.name) $(osquery.columns.version) with minor $(osquery.columns.minor) and major $(osquery.columns.major)

osquery: $(osquery.pack) $(osquery.subquery): OS $(osquery.columns.name) $(osquery.columns.version) with minor $(osquery.columns.minor) and major $(osquery.columns.major)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Kernel version is $(osquery.columns.version) with path $(osquery.columns.path) and kernel device identifier $(osquery.columns.device)

osquery: $(osquery.pack) $(osquery.subquery): Kernel version is $(osquery.columns.version) with path $(osquery.columns.path) and kernel device identifier $(osquery.columns.device)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Package name $(osquery.columns.name), version $(osquery.columns.version), revision $(osquery.columns.revision),size $(osquery.columns.size) bytes

osquery: $(osquery.pack) $(osquery.subquery): Package name $(osquery.columns.name), version $(osquery.columns.version), revision $(osquery.columns.revision),size $(osquery.columns.size) bytes

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Repository name $(osquery.columns.name), version $(osquery.columns.version), source $(osquery.columns.source),release name $(osquery.columns.release)

osquery: $(osquery.pack) $(osquery.subquery): Repository name $(osquery.columns.name), version $(osquery.columns.version), source $(osquery.columns.source),release name $(osquery.columns.release)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Safari extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

osquery: $(osquery.pack) $(osquery.subquery): Safari extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Opera extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

osquery: $(osquery.pack) $(osquery.subquery): Opera extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Chrome extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

osquery: $(osquery.pack) $(osquery.subquery): Chrome extension $(osquery.columns.name) version is $(osquery.columns.version) and the user that owns it is $(osquery.columns.uid)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Firefox addon $(osquery.columns.name) type is $(osquery.columns.type) and the user that owns it is $(osquery.columns.uid)

osquery: $(osquery.pack) $(osquery.subquery): Firefox addon $(osquery.columns.name) type is $(osquery.columns.type) and the user that owns it is $(osquery.columns.uid)