Uptycs is excited to announce Osquery release 3.3.2.24, released 08/19/2019.
Following are the key improvements / issues addressed in this release :
With this release, Uptycs supports configuration of Yara events. Configuration of Yara events is supported under File Integrity Monitoring.
New tables added -
New Table | Description |
---|---|
battery | Provides information about the internal battery of a Macbook. |
ulimit_info | Provides System resource usage limits. |
ntfs_acl_permissions | Retrieve NTFS ACL permission information for files and directories |
ssh_configs | A table of parsed ssh_configs |
smart_drive_info | Drive information read by SMART controller utilizing autodetect. |
elf_info | ELF file information on Linux |
winbaseobj | Lists named Windows objects in the default object directories, across all terminal services sessions |
oem_strings | Gets OEM defined strings from SMBIOS |
interface_ipv6 | Provides IPv6 configuration and stats of network interfaces |
platform_info | Provides Information about EFI/UEFI/ROM and platform/boot |
ntdomains | Display basic NT domain information of a Windows machine |
yara_events | New table implementation for Windows signifying events related to modified or created files that match preconfigured yara signatures (Uptycs version only) |
prefetch | Information about prefetch database (Windows only) that provides forensic level visibility into recently launched programs (Uptycs version only) |
logon_sessions | Windows logon session information |
New columns added -
Table Name | New Columns |
---|---|
cpuid | Various new columns for CPU identification |
hash | ssdeep columns to hash table for Mac And Linux |
interface_details | link_speed |
sharing_preferences | new column indicating if content caching is enabled |
routes | hopcount - indicating maximum hopcounts expected per route |
pci_devices | New columns providing vendor and model information from the system copy of pci.ids. Also added new columns about pci class and subclasses. |
os_version | New column to os_version table related to installation dates |
processes | Per process performance information data for Windows processes |
process_events | ancestor_list, process hash - md5, sha1, sha256 |
Other notable features / improvements: