mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-04-26 06:27:50 +02:00
Merge pull request #8778 from Security-Onion-Solutions/2.4/elastic-fleet
Hunt Query - Elastic Agent Live Osquery Logs
This commit is contained in:
@@ -797,9 +797,6 @@ soc:
|
|||||||
- name: NTLM
|
- name: NTLM
|
||||||
description: NTLM grouped by computer name
|
description: NTLM grouped by computer name
|
||||||
query: 'event.dataset:ntlm | groupby ntlm.server.dns.name'
|
query: 'event.dataset:ntlm | groupby ntlm.server.dns.name'
|
||||||
- name: Osquery Live Queries
|
|
||||||
description: Osquery Live Query results grouped by computer name
|
|
||||||
query: 'event.dataset:live_query | groupby host.hostname'
|
|
||||||
- name: PE
|
- name: PE
|
||||||
description: PE files list
|
description: PE files list
|
||||||
query: 'event.dataset:pe | groupby file.machine file.os file.subsystem'
|
query: 'event.dataset:pe | groupby file.machine file.os file.subsystem'
|
||||||
@@ -1457,9 +1454,6 @@ soc:
|
|||||||
- name: NTLM
|
- name: NTLM
|
||||||
description: NTLM logs
|
description: NTLM logs
|
||||||
query: 'event.dataset:ntlm | groupby ntlm.server.dns.name | groupby ntlm.server.nb.name | groupby ntlm.server.tree.name | groupby ntlm.success | groupby source.ip | groupby destination.ip | groupby destination.port'
|
query: 'event.dataset:ntlm | groupby ntlm.server.dns.name | groupby ntlm.server.nb.name | groupby ntlm.server.tree.name | groupby ntlm.success | groupby source.ip | groupby destination.ip | groupby destination.port'
|
||||||
- name: Osquery Live Queries
|
|
||||||
description: Osquery Live Query results
|
|
||||||
query: 'event.dataset:live_query | groupby host.hostname'
|
|
||||||
- name: PE
|
- name: PE
|
||||||
description: PE files list
|
description: PE files list
|
||||||
query: 'event.dataset:pe | groupby file.machine | groupby file.os | groupby file.subsystem | groupby file.section_names | groupby file.is_exe | groupby file.is_64bit'
|
query: 'event.dataset:pe | groupby file.machine | groupby file.os | groupby file.subsystem | groupby file.section_names | groupby file.is_exe | groupby file.is_64bit'
|
||||||
|
|||||||
Reference in New Issue
Block a user