Skip to content

Actions: chainguard-dev/osquery-defense-kit

Actions

All workflows

Actions

Loading...
Loading

Showing runs from all workflows
306 workflow runs
306 workflow runs

Filter by Event

Filter by Status

Filter by Branch

Filter by Actor

split detection pack into subpacks
verify #253: Pull request #315 opened by tstromberg
September 20, 2023 21:44 6h 0m 23s tstromberg:make-specific
September 20, 2023 21:44 6h 0m 23s
Merge pull request #314 from tstromberg/yara
verify #252: Commit 547fe50 pushed by tstromberg
September 20, 2023 21:13 6h 0m 22s main
September 20, 2023 21:13 6h 0m 22s
Add 14 new YARA based checks
verify #251: Pull request #314 opened by tstromberg
September 20, 2023 21:04 6h 0m 24s tstromberg:yara
September 20, 2023 21:04 6h 0m 24s
Merge pull request #313 from tstromberg/fpr-sep20
verify #250: Commit 2d920e4 pushed by tstromberg
September 20, 2023 13:52 1m 2s main
September 20, 2023 13:52 1m 2s
Merge pull request #312 from tstromberg/fpr-sep20
verify #248: Commit fe2eb92 pushed by tstromberg
September 20, 2023 13:32 1m 0s main
September 20, 2023 13:32 1m 0s
fpr: RSA keys, tcpdump, login, crane, souregraph, etc
verify #247: Pull request #312 synchronize by tstromberg
September 20, 2023 13:31 1m 10s tstromberg:fpr-sep20
September 20, 2023 13:31 1m 10s
fpr: RSA keys, tcpdump, login, crane, souregraph, etc
verify #246: Pull request #312 synchronize by tstromberg
September 20, 2023 12:08 1m 12s tstromberg:fpr-sep20
September 20, 2023 12:08 1m 12s
fpr: RSA keys, tcpdump, login, crane, souregraph, etc
verify #245: Pull request #312 opened by tstromberg
September 20, 2023 12:04 1m 4s tstromberg:fpr-sep20
September 20, 2023 12:04 1m 4s
Merge pull request #310 from tstromberg/fpr-sep18
verify #244: Commit ddb37c0 pushed by tstromberg
September 19, 2023 21:48 59s main
September 19, 2023 21:48 59s
Merge pull request #311 from tstromberg/hidden-cwd-events
verify #243: Commit e958c9f pushed by tstromberg
September 19, 2023 21:48 1m 0s main
September 19, 2023 21:48 1m 0s
new check: hidden cwd events
verify #242: Pull request #311 opened by tstromberg
September 19, 2023 21:19 1m 24s tstromberg:hidden-cwd-events
September 19, 2023 21:19 1m 24s
unexpected talker events: address easy false positives
verify #241: Pull request #310 opened by tstromberg
September 19, 2023 21:18 1m 21s tstromberg:fpr-sep18
September 19, 2023 21:18 1m 21s
Merge pull request #309 from tstromberg/fpr-sep18
verify #240: Commit 41eb8f2 pushed by tstromberg
September 19, 2023 19:59 1m 5s main
September 19, 2023 19:59 1m 5s
new check: Unexpected talker events
verify #239: Pull request #309 opened by tstromberg
September 19, 2023 19:57 59s tstromberg:fpr-sep18
September 19, 2023 19:57 59s
Merge pull request #308 from tstromberg/lusca
verify #238: Commit 4abe0fa pushed by tstromberg
September 18, 2023 18:27 1m 8s main
September 18, 2023 18:27 1m 8s
More checks for unusual process names inspired by Earth Lusca
verify #237: Pull request #308 opened by tstromberg
September 18, 2023 18:15 1m 31s tstromberg:lusca
September 18, 2023 18:15 1m 31s
Merge pull request #307 from tstromberg/fpr-sep14
verify #236: Commit 9963a4e pushed by tstromberg
September 14, 2023 21:16 1m 11s main
September 14, 2023 21:16 1m 11s
Merge pull request #304 from tstromberg/infostealerz
verify #234: Commit 6adfb1d pushed by tstromberg
September 14, 2023 21:14 1m 9s main
September 14, 2023 21:14 1m 9s
Merge pull request #306 from tstromberg/apt36-desktop
verify #233: Commit e97f2fd pushed by tstromberg
September 14, 2023 20:43 59s main
September 14, 2023 20:43 59s
Improve base64/crontab detection
verify #232: Pull request #306 opened by tstromberg
September 14, 2023 20:40 1m 0s tstromberg:apt36-desktop
September 14, 2023 20:40 1m 0s
Merge pull request #305 from tstromberg/acrobat-reader
verify #231: Commit a9eba00 pushed by tstromberg
September 14, 2023 20:37 1m 1s main
September 14, 2023 20:37 1m 1s
Detect vulnerable versions of Acrobat Reader
verify #230: Pull request #305 opened by tstromberg
September 14, 2023 20:30 1m 10s tstromberg:acrobat-reader
September 14, 2023 20:30 1m 10s
Add primitive name-based detection for possible InfoStealers
verify #229: Pull request #304 opened by tstromberg
September 12, 2023 14:19 1m 10s tstromberg:infostealerz
September 12, 2023 14:19 1m 10s
ProTip! You can narrow down the results and go further in time using created:<2023-09-12 or the other filters available.