fleet/docs/1-Using-Fleet/standard-query-library
Mike McNeil 7bb202f961
Publish fleetdm.com/queries (#899)
* /sandbox/queries becomes /queries, etc

* Publish fleetdm.com/queries

Expose query library routes the rest of the way, move remediation data sanitization to the point of entry, and update query library to match (pairing w/ @gillespi314)

* Fix accidental commit of sailsrc (again)
2021-05-28 17:51:47 -05:00
..
README.md Add "contributors" to YAML format to enable attribution (#780) 2021-05-18 10:33:40 -05:00
standard-query-library.yml Publish fleetdm.com/queries (#899) 2021-05-28 17:51:47 -05:00

Standard query library

Fleet's standard query library includes a growing collection of useful queries for organizations deploying Fleet and osquery.

Importing the queries in Fleet

After cloning the fleetdm/fleet repo, import the queries using fleetctl:

fleetctl apply -f fleet/docs/1-Using-Fleet/standard-query-library/standard-query-library.yml

Contributors

Want to add your own query?

  1. Please copy the following yaml section and paste it at the bottom of the standard-query-library.yml file.
---
apiVersion: v1
kind: query
spec:
  name: What is your query called? Please use a human readable query name.
  platforms: What operating systems support your query? This can usually be determined by the osquery tables included in your query. Heading to the https://osquery.io/schema webpage to see which operating systems are supported by the tables you include.
  description: Describe your query. What does information does your query reveal?
  query: Insert query here
  purpose: What is the goal of running your query? Ex. Detection
  remediation: Are there any remediation steps to resolve the detection triggered by your query? If not, insert "N/A."
  contributors: zwass,mike-j-thomas
  1. Replace each field and submit a pull request to the fleetdm/fleet GitHub repository.

For instructions on submitting pull requests to Fleet check out the Committing Changes section in the Contributors documentation.

Additional resources

Listed below are great resources that contain additional queries.