Name
|
Query
|
Interval
|
Minimum osquery Version
|
Description
|
3600 | ||||
7200 | ||||
FROM apk_packages | ||||
WHERE system_type IN ('docker_container', 'crio_container') | ||||
19800 | ||||
FROM apparmor_profiles; | ||||
19800 | ||||
FROM apt_sources; | ||||
600 | ||||
FROM arp_cache; | ||||
43200 | ||||
FROM atom_packages; | ||||
600 | ||||
FROM audit_status; | ||||
3600 | ||||
FROM authorized_keys | ||||
WHERE authorized_keys.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
3600 | ||||
FROM block_devices; | ||||
7200 | ||||
FROM carbon_black_info; | ||||
3600 | ||||
FROM certificates; | ||||
7200 | ||||
FROM chrome_extension_content_scripts | ||||
WHERE chrome_extension_content_scripts.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
7200 | ||||
FROM chrome_extensions | ||||
WHERE chrome_extensions.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
300 | ||||
FROM cpu_time; | ||||
3600 | ||||
FROM cpuid; | ||||
600 | ||||
FROM crio_container_labels; | ||||
600 | ||||
FROM crio_container_mounts; | ||||
600 | ||||
FROM crio_container_stats; | ||||
600 | ||||
FROM crio_containers; | ||||
600 | ||||
FROM crio_image_fs_info; | ||||
3600 | ||||
FROM crio_images; | ||||
600 | ||||
FROM crio_pod_sandbox_labels; | ||||
600 | ||||
FROM crio_pod_sandboxes; | ||||
3600 | ||||
FROM crio_status; | ||||
3600 | ||||
FROM crio_version; | ||||
7200 | ||||
FROM crontab; | ||||
19800 | ||||
FROM deb_packages; | ||||
7200 | ||||
FROM deb_packages | ||||
WHERE system_type IN ('host', 'docker_container', 'crio_container') | ||||
3600 | ||||
FROM diag_watcher_stats; | ||||
3600 | ||||
FROM disk_encryption; | ||||
600 | ||||
FROM dns_resolvers; | ||||
600 | ||||
FROM docker_container_labels; | ||||
600 | ||||
FROM docker_container_mounts; | ||||
600 | ||||
FROM docker_container_networks; | ||||
600 | ||||
FROM docker_container_ports; | ||||
30 | ||||
pid, | ||||
name, | ||||
cmdline, | ||||
uid, | ||||
gid, | ||||
euid, | ||||
egid, | ||||
suid, | ||||
sgid, | ||||
start_time, | ||||
parent, | ||||
pgroup, | ||||
nice | ||||
FROM docker_container_processes; | ||||
30 | ||||
name, | ||||
image, | ||||
image_id, | ||||
command, | ||||
created, | ||||
state | ||||
FROM docker_containers; | ||||
30 | ||||
name, | ||||
image, | ||||
image_id, | ||||
command, | ||||
created, | ||||
state, | ||||
status, | ||||
pid, | ||||
path, | ||||
config_entrypoint, | ||||
started_at, | ||||
finished_at, | ||||
ipc_namespace, | ||||
mnt_namespace, | ||||
net_namespace, | ||||
pid_namespace, | ||||
user_namespace, | ||||
uts_namespace | ||||
FROM docker_containers; | ||||
3600 | ||||
FROM docker_image_history; | ||||
3600 | ||||
FROM docker_image_labels; | ||||
3600 | ||||
FROM docker_image_layers; | ||||
3600 | ||||
FROM docker_images; | ||||
21600 | ||||
FROM docker_info; | ||||
3600 | ||||
FROM docker_network_labels; | ||||
3600 | ||||
FROM docker_networks; | ||||
21600 | ||||
FROM docker_version; | ||||
3600 | ||||
FROM docker_volume_labels; | ||||
3600 | ||||
FROM docker_volumes; | ||||
3600 | ||||
FROM ebpf_kernel_support; | ||||
7200 | ||||
FROM ec2_instance_metadata; | ||||
21600 | ||||
FROM efivars; | ||||
19800 | ||||
FROM etc_hosts; | ||||
19800 | ||||
FROM etc_protocols; | ||||
19800 | ||||
FROM etc_services; | ||||
7200 | ||||
FROM firefox_addons | ||||
WHERE firefox_addons.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
3600 | ||||
FROM groups; | ||||
3600 | ||||
FROM interface_addresses; | ||||
600 | ||||
FROM interface_details; | ||||
7200 | ||||
SELECT d.interface, | ||||
d.mac, | ||||
a.address, | ||||
a.mask, | ||||
'true' AS ismain | ||||
FROM interface_details d, | ||||
interface_addresses a | ||||
WHERE d.interface = a.interface | ||||
AND a.interface = ( | ||||
SELECT interface | ||||
FROM routes | ||||
WHERE TYPE = 'gateway' | ||||
AND ( | ||||
( | ||||
destination = '0.0.0.0' | ||||
AND netmask = '0' | ||||
) | ||||
OR ( | ||||
destination = '::' | ||||
AND netmask = '0' | ||||
) | ||||
) | ||||
LIMIT 1 | ||||
) | ||||
), all_interfaces AS ( | ||||
SELECT d.interface, | ||||
d.mac, | ||||
a.address, | ||||
a.mask, | ||||
'false' AS ismain | ||||
FROM interface_details d, | ||||
interface_addresses a | ||||
WHERE d.interface = a.interface | ||||
AND d.interface != 'lo' | ||||
AND ( | ||||
a.broadcast != '' | ||||
OR a.point_to_point != '' | ||||
) | ||||
) | ||||
SELECT a.interface AS interface, | ||||
a.mac AS mac, | ||||
a.address AS address, | ||||
a.mask AS mask, | ||||
b.ismain AS is_primary | ||||
FROM all_interfaces a | ||||
LEFT JOIN main_interfaces b ON a.address = b.address | ||||
AND a.mac = b.mac | ||||
AND a.interface = b.interface | ||||
AND a.mask = b.mask; | ||||
21600 | ||||
FROM interface_ipv6; | ||||
19800 | ||||
FROM iptables; | ||||
3600 | ||||
FROM kernel_info; | ||||
1800 | ||||
FROM kernel_integrity; | ||||
1200 | ||||
FROM kernel_modules; | ||||
3600 | ||||
FROM known_hosts | ||||
WHERE known_hosts.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
3600 | ||||
FROM last; | ||||
19800 | ||||
FROM listening_ports; | ||||
60 | ||||
FROM load_average; | ||||
60 | ||||
FROM logged_in_users; | ||||
3600 | ||||
FROM lxd_certificates; | ||||
600 | ||||
FROM lxd_cluster; | ||||
600 | ||||
FROM lxd_cluster_members; | ||||
3600 | ||||
FROM lxd_images; | ||||
30 | ||||
FROM lxd_instances; | ||||
3600 | ||||
FROM lxd_networks; | ||||
3600 | ||||
FROM lxd_storage_pools; | ||||
21600 | ||||
FROM md_devices; | ||||
21600 | ||||
FROM md_drives; | ||||
21600 | ||||
FROM md_personalities; | ||||
19800 | ||||
FROM memory_array_mapped_addresses; | ||||
19800 | ||||
FROM memory_arrays; | ||||
19800 | ||||
FROM memory_device_mapped_addresses; | ||||
21600 | ||||
FROM memory_devices; | ||||
19800 | ||||
FROM memory_error_info; | ||||
300 | ||||
FROM memory_info; | ||||
3600 | ||||
FROM memory_map; | ||||
600 | ||||
FROM mounts; | ||||
3600 | ||||
FROM msr; | ||||
21600 | ||||
FROM npm_packages; | ||||
21600 | ||||
FROM oem_strings; | ||||
7200 | ||||
FROM opera_extensions | ||||
WHERE opera_extensions.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
21600 | ||||
FROM os_version; | ||||
7200 | ||||
FROM os_version | ||||
WHERE system_type IN ('host', 'docker_container', 'crio_container', ''); | ||||
3600 | ||||
FROM osquery_config; | ||||
600 | ||||
FROM osquery_events; | ||||
3600 | ||||
FROM osquery_extensions; | ||||
3600 | ||||
FROM osquery_flags; | ||||
3600 | ||||
FROM osquery_info; | ||||
3600 | ||||
FROM osquery_packs; | ||||
3600 | ||||
FROM osquery_registry; | ||||
19800 | ||||
FROM osquery_schedule; | ||||
600 | ||||
FROM osquery_upt_stats; | ||||
3600 | ||||
FROM pci_devices; | ||||
7200 | ||||
FROM platform_info; | ||||
300 | ||||
FROM process_envs; | ||||
21600 | ||||
FROM process_namespaces; | ||||
300 | ||||
FROM process_open_files; | ||||
600 | ||||
FROM process_open_pipes; | ||||
30 | ||||
FROM process_open_sockets | ||||
WHERE NOT ( | ||||
protocol IN (6, 17) | ||||
AND remote_address != '::' | ||||
AND remote_address != '0.0.0.0' | ||||
AND remote_address NOT LIKE '10.%' | ||||
AND remote_address NOT LIKE '192.168.%' | ||||
AND CASE | ||||
WHEN remote_address LIKE '172.__.%' | ||||
AND SUBSTR(remote_address, 5, 2) BETWEEN '16' AND '31' THEN 0 | ||||
ELSE 1 | ||||
END | ||||
); | ||||
30 | ||||
FROM process_open_sockets | ||||
WHERE protocol IN (6, 17) | ||||
AND remote_address != '::' | ||||
AND remote_address != '0.0.0.0' | ||||
AND remote_address NOT LIKE '::ffff:%' | ||||
AND remote_address NOT LIKE '127.%' | ||||
AND remote_address NOT LIKE '10.%' | ||||
AND remote_address NOT LIKE '192.168.%' | ||||
AND CASE | ||||
WHEN remote_address LIKE '172.__.%' | ||||
AND SUBSTR(remote_address, 5, 2) BETWEEN '16' AND '31' THEN 0 | ||||
ELSE 1 | ||||
END; | ||||
300 | ||||
cmdline, | ||||
user_time, | ||||
system_time, | ||||
start_time | ||||
FROM processes; | ||||
30 | ||||
name, | ||||
path, | ||||
cmdline, | ||||
cwd, | ||||
root, | ||||
uid, | ||||
gid, | ||||
euid, | ||||
egid, | ||||
suid, | ||||
sgid, | ||||
on_disk, | ||||
parent, | ||||
pgroup, | ||||
nice | ||||
FROM processes; | ||||
30 | ||||
name, | ||||
path, | ||||
cmdline, | ||||
cwd, | ||||
root, | ||||
uid, | ||||
gid, | ||||
euid, | ||||
egid, | ||||
suid, | ||||
sgid, | ||||
on_disk, | ||||
parent, | ||||
pgroup, | ||||
nice, | ||||
is_elevated_token, | ||||
cgroup_namespace, | ||||
ipc_namespace, | ||||
mnt_namespace, | ||||
net_namespace, | ||||
pid_namespace, | ||||
user_namespace, | ||||
uts_namespace | ||||
FROM processes; | ||||
30 | ||||
name, | ||||
path, | ||||
cmdline, | ||||
cwd, | ||||
root, | ||||
uid, | ||||
gid, | ||||
euid, | ||||
egid, | ||||
suid, | ||||
sgid, | ||||
on_disk, | ||||
parent, | ||||
pgroup, | ||||
nice, | ||||
is_elevated_token | ||||
FROM processes; | ||||
30 | ||||
name, | ||||
path, | ||||
cmdline, | ||||
cwd, | ||||
root, | ||||
uid, | ||||
gid, | ||||
euid, | ||||
egid, | ||||
suid, | ||||
sgid, | ||||
on_disk, | ||||
parent, | ||||
pgroup, | ||||
nice, | ||||
is_elevated_token, | ||||
upid, | ||||
uppid, | ||||
cpu_type, | ||||
cpu_subtype, | ||||
is_container_process, | ||||
pid_ns | ||||
FROM processes; | ||||
300 | ||||
a.name, | ||||
a.path, | ||||
a.cmdline, | ||||
a.state, | ||||
a.cwd, | ||||
a.root, | ||||
a.uid, | ||||
a.gid, | ||||
a.euid, | ||||
a.egid, | ||||
a.suid, | ||||
a.sgid, | ||||
a.on_disk, | ||||
a.wired_size, | ||||
a.start_time, | ||||
a.parent, | ||||
a.pgroup, | ||||
a.nice, | ||||
h.directory, | ||||
h.md5, | ||||
h.sha1, | ||||
h.sha256 | ||||
FROM processes a, | ||||
hash h | ||||
WHERE a.path = h.path; | ||||
19800 | ||||
FROM python_packages; | ||||
3600 | ||||
FROM routes; | ||||
19800 | ||||
FROM rpm_packages; | ||||
7200 | ||||
FROM rpm_packages | ||||
WHERE system_type IN ('host', 'docker_container', 'crio_container') | ||||
19800 | ||||
FROM selinux_settings; | ||||
300 | ||||
FROM shadow; | ||||
3600 | ||||
FROM shared_memory; | ||||
3600 | ||||
FROM shell_history | ||||
WHERE shell_history.uid IN ( | ||||
SELECT uid | ||||
FROM users | ||||
); | ||||
3600 | ||||
FROM slack_user_info; | ||||
3600 | ||||
FROM smbios_tables; | ||||
21600 | ||||
FROM ssh_configs; | ||||
3600 | ||||
FROM sudoers; | ||||
3600 | ||||
FROM suid_bin; | ||||
19800 | ||||
FROM system_controls; | ||||
21600 | ||||
FROM system_info; | ||||
21600 | ||||
FROM ulimit_info; | ||||
15 | ||||
c.idle AS cpu_idle, | ||||
m.memory_total AS memory_total, | ||||
m.memory_free AS memory_free, | ||||
m.swap_total AS swap_total, | ||||
m.swap_free AS swap_free, | ||||
d.total AS disk_total, | ||||
d.free AS disk_free, | ||||
n.in_bytes AS in_bytes, | ||||
n.out_bytes AS out_bytes | ||||
FROM ( | ||||
SELECT SUM( | ||||
user + nice + system + idle + iowait + irq + softirq + steal | ||||
) AS total, | ||||
SUM(idle) AS idle | ||||
FROM cpu_time | ||||
) c, | ||||
( | ||||
SELECT memory_total, | ||||
memory_free, | ||||
swap_total, | ||||
swap_free | ||||
FROM memory_info | ||||
) m, | ||||
( | ||||
SELECT SUM(blocks) AS total, | ||||
SUM(blocks_available) AS free | ||||
FROM ( | ||||
SELECT DISTINCT device, | ||||
blocks, | ||||
blocks_available | ||||
FROM mounts | ||||
WHERE blocks > 0 | ||||
AND TYPE NOT LIKE '%tmpfs' | ||||
) | ||||
) d, | ||||
( | ||||
SELECT SUM(ibytes) AS in_bytes, | ||||
SUM(obytes) AS out_bytes | ||||
FROM interface_details | ||||
WHERE interface != 'lo' | ||||
) n; | ||||
3600 | ||||
FROM uptime; | ||||
3600 | ||||
FROM usb_devices; | ||||
3600 | ||||
FROM user_groups; | ||||
3600 | ||||
FROM user_ssh_keys; | ||||
300 | ||||
FROM users; | ||||
21600 | ||||
FROM yum_sources; | ||||