osquery-defense-kit

Production-ready detection & response queries for osquery (by chainguard-dev)

Osquery-defense-kit Alternatives

Similar projects and alternatives to osquery-defense-kit

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better osquery-defense-kit alternative or higher similarity.

osquery-defense-kit reviews and mentions

Posts with mentions or reviews of osquery-defense-kit. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-03-07.
  • Google ads malvertising is targeting open source software
    2 projects | news.ycombinator.com | 7 Mar 2023
    We had a close call with malvertising ourselves, so we wrote an osquery query to alert on .dmg/.iso/.pkg downloads from unknown sources:

    https://github.com/chainguard-dev/osquery-defense-kit/blob/m...

    This query should not be your only line of defense, but can provide an early heads up before the package is opened. You can deploy this query with Kolide, as it uses osquery under the hood.

    It was once possible to have a query like this that worked on Linux using the user.xdg.origin.url extended file attribute, but Chromium dropped support for it in 2019 for privacy reasons: https://chromium.googlesource.com/chromium/src/+/a9b4fb70b43...

  • osquery-defense-kit: Production-ready detection & response queries for osquery
    1 project | /r/blueteamsec | 21 Oct 2022

Stats

Basic osquery-defense-kit repo stats
2
496
8.7
6 days ago

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com