-
Notifications
You must be signed in to change notification settings - Fork 40
Open
Description
https://osquery.io/blog/community-articles hasn't been updated in a year, but there are many examples of community articles that have been published in that time or prior.
- https://medium.com/palantir/auditing-with-osquery-part-one-introduction-to-the-linux-audit-framework-217967cec406
- https://medium.com/palantir/auditing-with-osquery-part-two-configuration-and-implementation-87a8bba0ef48
- Articles from the Kolide blog https://blog.kolide.com/tagged/osquery
- Articles from the Uptycs blog https://www.uptycs.com/blog
- Articles from the DefensiveDepth blog https://defensivedepth.com/tag/osquery/
- https://www.alienvault.com/blogs/labs-research/hunting-for-linux-library-injection-with-osquery
- https://blog.trailofbits.com/2018/05/28/collect-ntfs-forensic-information-with-osquery/
- https://blog.trailofbits.com/2018/05/29/manage-santa-within-osquery/
- https://blog.trailofbits.com/2018/05/30/manage-your-fleets-firewalls-with-osquery/
- https://blog.trailofbits.com/2019/05/31/using-osquery-for-remote-forensics/
Metadata
Metadata
Assignees
Labels
No labels