mirror of
https://github.com/valitydev/osquery-1.git
synced 2024-11-07 01:55:20 +00:00
OSX Keranger detection fix
This commit is contained in:
parent
677c448dea
commit
7c18ce9bb0
@ -202,7 +202,7 @@
|
||||
"value": "Artifact used by this malware"
|
||||
},
|
||||
"Keranger_2": {
|
||||
"query": "select * from file where path like '/Users/%/Library/.kernel_%' or path like '/Users/%/Library/kernel_service';",
|
||||
"query": "select * from file where path like '/Users/%/Library/.kernel_%' union select * from file where path like '/Users/%/Library/kernel_service';",
|
||||
"interval": "86400",
|
||||
"description": "http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/",
|
||||
"value": "Artifact used by this malware"
|
||||
|
Loading…
Reference in New Issue
Block a user