2023-10-08 00:15:08 +00:00
- categoryName : Other
features :
- industryName : File integrity monitoring (FIM) # Short industry phrase
friendlyName : Detect changes to critical files # Short, Fleet one-liner for the feature, written in the imperative mood. (If easy to do, base this off of the words that an actual customer is saying.)
description : Specify files to monitor for changes or deletions, then log those events to your SIEM or data lake, including key information such as filepath and checksum. # Clear Mr. Rogers description
documentationUrl : https://fleetdm.com/guides/osquery-evented-tables-overview#file-integrity-monitoring-fim # URL of the single-best page within the docs which serves as a "jumping-off point" for this feature.
screenshotSrc : "" # A screenshot of the single, best, simplifying, obvious example
tier : Free # Either "Free" or "Premium"
usualDepartment : Security # or omit if there isn't a particular departmental leaning we've noticed
productCategories : [ Endpoint operations] # or omit if this isn't associated with a single product category
dri : mikermcneil #GitHub user name
demos :
- description : A top gaming company needed a way to monitor critical files on production Debian servers.
quote : The FIM features are kind of a top priority.
moreInfoUrl : https://docs.google.com/document/d/1pE9U-1E4YDiy6h4TorszrTOiFAauFiORikSUFUqW7Pk/edit
cues :
- description : Monitor critical files on production Debian servers
- description : Detect illicit activity
moreInfoUrl : https://www.beyondtrust.com/resources/glossary/file-integrity-monitoring
- description : Pinpoint unintended changes
moreInfoUrl : https://www.beyondtrust.com/resources/glossary/file-integrity-monitoring
- description : Verify update status and monitoring system health
moreInfoUrl : https://www.beyondtrust.com/resources/glossary/file-integrity-monitoring
- description : Meet compliance mandates
moreInfoUrl : https://www.beyondtrust.com/resources/glossary/file-integrity-monitoring
- industryName : Human-endpoint mapping
friendlyName : See who logs in on every computer
description : Identify who logs in to any system, including login history and current sessions. Look up any host by the email address of the person using it.
documentationUrl : "" # todo
screenshotSrc : ""
tier : Free
productCategories : [ Endpoint operations]
dri : mikermcneil
demos :
- description : Security engineers at a top gaming company wanted to get demographics off their macOS, Windows, and Linux machines about who the user is and who's logged in.
moreInfoUrl : https://docs.google.com/document/d/1qFYtMoKh3zyERLhbErJOEOo2me6Bc7KOOkjKn482Sqc/edit
cues :
- description : Human-to-device mapping
- description : Look up computer by ActiveDirectory account
- description : Find device by Google Chrome user
- description : Check user login history
moreInfoUrl : https://www.lepide.com/how-to/audit-who-logged-into-a-computer-and-when.html#:~:text=To%20find%20out%20the%20details,logs%20in%20%E2%80%9CWindows%20Logs%E2%80%9D.
- description : See currently logged in users
moreInfoUrl : https://www.top-password.com/blog/see-currently-logged-in-users-in-windows/
- description : Get demographics off of our machines about who the user is and who's logged in
moreInfoUrl : https://docs.google.com/document/d/1qFYtMoKh3zyERLhbErJOEOo2me6Bc7KOOkjKn482Sqc/edit
- description : See what servers someone is logged-in on
moreInfoUrl : https://community.spiceworks.com/topic/138171-is-there-a-way-to-see-what-servers-someone-is-logged-in-on
- industryName : REST API
friendlyName : Automate any feature
description : ""
documentationUrl : https://fleetdm.com/docs/rest-api/rest-api
screenshotSrc : ""
tier : Free
dri : rachaelshaw
- industryName : Command line tool (CLI)
tier : Free
2022-12-09 21:04:29 +00:00
- categoryName : Device management
features :
2023-10-08 00:15:08 +00:00
- industryName : User-initiated enrollment of macOS computers
2022-12-09 21:04:29 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Remotely enforce macOS settings
2022-12-09 21:04:29 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Low-level macOS MDM commands (e.g. remote restart)
2023-01-26 18:03:56 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Native macOS update reminders
2023-02-15 20:34:28 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Zero-touch setup for macOS computers
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
2023-10-11 04:23:11 +00:00
- industryName : Script execution
fiendlyName : Safely execute custom scripts (macOS, Windows, and Linux)
documentationUrl : https://fleetdm.com/docs/using-fleet/scripts
2023-05-25 03:40:19 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
productCategories : [ Device management,Endpoint operations]
- industryName : End-user macOS update reminders (via Nudge)
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Encrypt macOS hard disks with FileVault
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Manage queued MDM commands on macOS
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
comingSoonOn : 2023-12-31
usualDepartment : IT
productCategories : [ Device management]
- industryName : Remotely lock and wipe macOS computers
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Update apps on macOS computers
2022-12-09 21:04:29 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
comingSoonOn : 2024-03-31
usualDepartment : IT
productCategories : [ Device management]
- industryName : Puppet integration
friendlyName : Map macOS settings to computers with Puppet module
2023-08-27 00:41:21 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
- industryName : Interactive MDM migration # « end-user initiated MDM migration, with interactive UI
2023-08-27 00:41:21 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management]
2022-12-05 20:11:46 +00:00
- categoryName : Support
features :
2023-10-08 00:15:08 +00:00
- industryName : Public issue tracker (GitHub)
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Community Slack channel
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Unlimited email support (confidential)
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Phone and video call support
tier : Premium
2022-12-05 20:11:46 +00:00
- categoryName : Inventory management
features :
2023-10-08 00:15:08 +00:00
- industryName : Device inventory dashboard
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Browse installed software packages
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Search devices by IP, serial, hostname, UUID
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Target and configure specific groups of devices
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Generate reports for groups of devices
2022-12-05 20:11:46 +00:00
tier : Premium
- categoryName : Collaboration
features :
2023-10-08 00:15:08 +00:00
- industryName : Shareable device health reports
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Versionable queries and config (GitOps)
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
demos :
- description : A top financial services company needed to set up rolling deployments for changes to osquery agents running on their production servers.
moreInfoUrl : https://docs.google.com/document/d/1UdzZMyBLbs9SUXfSXN2x2wZQCbjZZUetYlNWH6-ryqQ/edit#heading=h.2lh6ehprpvl6
- industryName : Scope transparency
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
moreInfoUrl : https://fleetdm.com/transparency
2022-12-05 20:11:46 +00:00
- categoryName : Security and compliance
features :
2023-10-08 00:15:08 +00:00
- industryName : Single sign on (SSO, SAML)
2023-06-09 21:52:39 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Disk encryption
friendlyName : Ensure hard disks are encrypted
description : Encrypt hard disks of macOS and Windows computers, manage escrowed encryption keys, and report on disk encryption status (FileVault, BitLocker).
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
cues :
- description : Report on disk encryption status
- description : Encrypt hard disks on macOS with FileVault
- description : Escrow FileVault keys on macOS
- description : Encrypt hard disks on Windows with BitLocker
- industryName : Audit queries and user activities
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : Security
- industryName : Grant API-only access
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Programmable audit log
2023-05-25 03:40:19 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : Security
cues :
- description : Export activity of Fleet admins to your SIEM or data lake
- industryName : Just-in-time (JIT) provisioning
2023-05-05 18:10:36 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Automated user role sync via Okta, AD, or any IDP
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
cue :
- description : Automatically set admin access to Fleet based on your IDP
- industryName : Vanta integration
2022-12-23 18:39:35 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Trigger a workflow based on a failing policy
2023-06-09 21:52:39 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Role-based access control
2023-02-09 01:23:08 +00:00
tier : Premium
2022-12-05 20:11:46 +00:00
- categoryName : Monitoring
features :
2023-10-08 00:15:08 +00:00
- industryName : Schedule and automate custom queries
tier : Free
usualDepartment : Security
cues :
- description : Ship logs to Splunk, Snowflake, and more
- description : Export the data to other systems
moreInfoUrl : https://docs.google.com/document/d/1pE9U-1E4YDiy6h4TorszrTOiFAauFiORikSUFUqW7Pk/edit
- description : Export data to a third-party SIEM tool
moreInfoUrl : https://www.websense.com/content/support/library/web/hosted/admin_guide/siem_integration_explain.aspx
- industryName : Detect vulnerable software
tier : Free
usualDepartment : Security
productCategories : [ Vulnerability management]
demos :
- description : A top gaming company wanted to replace Qualys for infrastructure vulnerability detection.
quote : So we have some stuff today through Qualys, but it's just not very good. A lot of it is...it's just really noisy. I'm trying to find out specifically, actually what packages are installed where, and then the ability to live query them.
moreInfoUrl : https://docs.google.com/document/d/1JWtRsW1FUTCkZEESJj9-CvXjLXK4219by-C6vvVVyBY/edit
- industryName : Query performance monitoring
tier : Free
demos :
- description : A top software company needed to understand the performance impact of osquery queries before running them on all of their production Linux servers.
moreInfoUrl : https://docs.google.com/document/d/1WzMc8GJCRU6tTBb6gLsSTzFysqtXO8CtP2sXMPKgYSk/edit?disco=AAAA6xuVxGg
- description : A top software company wanted to detect regressions when adding/changing queries and fail builds if queries were too expensive.
moreInfoUrl : https://docs.google.com/document/d/1WzMc8GJCRU6tTBb6gLsSTzFysqtXO8CtP2sXMPKgYSk/edit?disco=AAAA6xuVxGg
- industryName : Device trust
tier : Free
cue :
- description : Standard query and policy library
- description : Beyondcorp
- description : Zero trust
- description : Conditional access
- industryName : Policy and vulnerability automations (webhook, Zendesk, JIRA, ServiceNow*)
tier : Free
- industryName : Detect and surface issues with devices (policies)
tier : Free
- industryName : Mark policies as critical
2022-12-23 18:48:53 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
- industryName : Vulnerability scores (EPSS and CVSS)
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Vulnerability management]
- industryName : CISA known exploited vulnerabilities
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Vulnerability management]
- industryName : End-user self-service
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : IT
productCategories : [ Device management,Endpoint operations]
2022-12-05 20:11:46 +00:00
- categoryName : Data outputs
features :
2023-10-08 00:15:08 +00:00
- industryName : Flexible log destinations (AWS Kinesis, Lambda, GCP, Kafka)
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Endpoint operations]
- industryName : File carving (AWS S3)
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Endpoint operations]
2022-12-05 20:11:46 +00:00
- categoryName : Deployment
features :
2023-10-08 00:15:08 +00:00
- industryName : Self-hosted
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
cues :
- description : Self-managed
- description : Host it yourself
- industryName : Deployment tools (Terraform, Helm)
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
- industryName : Configure osquery startup flags remotely
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Endpoint operations]
- industryName : Auto-update osquery agents
2022-12-05 20:11:46 +00:00
tier : Free
2023-10-08 00:15:08 +00:00
productCategories : [ Endpoint operations]
- industryName : Self-managed auto-update registry
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
usualDepartment : Security
productCategories : [ Endpoint operations]
- industryName : Manage osquery extensions remotely
2022-12-05 20:11:46 +00:00
tier : Premium
2023-10-08 00:15:08 +00:00
productCategories : [ Endpoint operations]
- industryName : Managed Cloud
2023-05-25 03:40:19 +00:00
tier : Premium