Skip to content

davequick/demo-osqueryd

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Running on a mac

bash ./run-demo.sh

then demo the data rolling into kibana...

then to simulate someone doing potential bad things to a system, we'll just copy an executable in sbin...

bash ./demo2.sh

now go and search for badactor and find the record of a new file being introduced

then change it again...

bash ./demo3.sh

and show a second line recorded that details a change in /sbin/ to the same file.

About

Simple Demo of OSQuery with Kafka and ELK

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published