Commit Graph

4233 Commits

Author SHA1 Message Date
Richard Metzler
3df60e6c7c docs: shadow only works for root / sudo (#4228) 2018-03-30 13:58:22 -07:00
Dimitris Tsapakidis
9b837329b5 docs: Fix typo in README.md (#4237) 2018-03-30 11:28:46 -07:00
Filipe Manco
9797276fc8
Properly filter process_open_sockets when pid=-1 (#4234) 2018-03-30 00:15:44 +01:00
Ngo The Trung
a56588819b tests: Fix compression test failing for Sierra #4139 (#4216) 2018-03-29 20:19:01 +01:00
Filipe Manco
00f3be5535
Fix performance regression on process_open_sockets (#4225) 2018-03-29 19:40:43 +01:00
Filipe Manco
567b0e2abc
Don't bail out when querying one namespace fails (#4229) 2018-03-29 19:39:30 +01:00
Nick Anderson
8b186b01ad bug: Windows crashes table crashes parsing stack traces (#4222) 2018-03-29 19:31:32 +01:00
Nick Anderson
7818b94165
deploy: fixing version bug in windows msi build (#4214) 2018-03-26 13:02:52 -07:00
Seshu Pasam
e45ddd98ce kafka: Support for kafka compression.codec (#4181) 2018-03-21 11:53:13 -07:00
Julien
3c54bf8a11 packs: windows compliance pack based on IAD SAMI (#4156) 2018-03-21 11:45:21 -07:00
James Jerger
ab26abb2d6 tables: Add windows disk_info table (#4177) 2018-03-21 11:42:44 -07:00
Jonathan Keljo
bf707ef4a9 mac/linux: add disk I/O columns to processes table (#4204) 2018-03-21 09:46:26 -07:00
Nick Anderson
9e2515a661
database: convert cached ptree entires to RapidJSON results (#4207) 2018-03-21 09:39:50 -07:00
Nick Anderson
2cf2601f77
perf: refactoring drivers table for performance (#4195) 2018-03-20 17:06:36 -07:00
Teddy Reed
2d67bbf482
thrift: Breakout thrift and fbthrift into implementations (#4130) 2018-03-20 15:20:51 -04:00
ryandeivert
06117da0f1 aws_log_forwarder: incrementing index for batches of records that could not be sent (#4188) 2018-03-09 13:28:14 -08:00
packetzero
525f869325 fix minor leak in darwin disk_encryption generate (#4125) 2018-03-09 12:56:18 -08:00
Mitchell Grenier
873fc4124c
Add status back instead of query data again (#4182) 2018-03-09 12:02:53 -08:00
Mitchell Grenier
f34df53ecb
Remove all table autoreleasepools (#4148) 2018-03-09 12:02:42 -08:00
Seshu Pasam
de6efc096d docker: Deal with HTTP/1.1 response. (#4180) 2018-03-09 12:01:26 -08:00
Jason Meller
dab7d67b86 Add account_policy_data virtual table for macOS (#4165) 2018-03-09 09:02:47 -08:00
Julien
98b7564d91 packs: remove escape - Error parsing the "windows-attacks" pack JSON (#4154) 2018-03-09 08:48:36 -08:00
Jesse Luehrs
ca2e33b3ad look up the external plugin by the correct name (#4169) 2018-03-06 20:13:49 -08:00
Mitchell Grenier
26bd32687a
Add block on short-circuiting discovery queries (#4170) 2018-03-05 13:00:54 -08:00
Teddy Reed
999034367a
freebsd: Update CMake for thrift 11 and boost 1.66 (#4166) 2018-03-05 09:13:05 -05:00
James Jerger
2fdc935840 Update confusing variable name and allow multiple row return in bitlocker_info.cpp (#4146) 2018-03-04 19:23:26 -08:00
Mike Arpaia
e48051697a Removing old website and cleaning up the docs directory (#4084) 2018-03-04 20:09:05 -05:00
Mitchell Grenier
1cc0a694db
Pin CMake version for build stability (#4136) 2018-03-02 15:32:06 -08:00
Cem Gürkök
1e432dcd4c adding fields to docker_containers table (#4167)
* adding fields to docker_containers table

* adding more fields: path, entrypoint

* addressing comments by obelisk

* pid to int and osquery::join use
2018-03-02 10:20:59 -08:00
Cem Gürkök
769059fda7 enable docker_container_processes for OS X (#4163) 2018-02-28 19:21:29 -08:00
Filipe Manco
1bbdff8c7a
Replace ptree with JSON on serialization code (#4128) 2018-03-01 00:36:24 +00:00
Nick Anderson
99c8debe4f
deployment: adding default path for Windows packs to example conf (#4159) 2018-02-27 12:22:55 -08:00
Julien
1d96ac1f2c packs: adding platform tag incident-response pack (#4155) 2018-02-26 21:06:44 -08:00
Mitchell Grenier
dad25b89a9
Adding symlink loop detection to globbing (#4129) 2018-02-22 11:57:46 -08:00
Teddy Reed
9f08f0b957
logger: Add check to prevent C++ extensions from using glog (#4147) 2018-02-22 11:53:52 -08:00
Teddy Reed
2c682ee0ce
docs: Fix new table example and add leaks check (#4141) 2018-02-21 17:58:36 -08:00
Teddy Reed
65a85799f5
extensions: Allow option accesses in extensions (#4142) 2018-02-21 17:52:35 -08:00
Alessandro Gario
abfcaf0d0e List all sockets (host and containers) in process_open_sockets (#4024) 2018-02-22 00:36:51 +00:00
Nick Anderson
57e8e123a1
[fix #4140] Removing WEL logger plugin from systemLog due to duplicate linkage (#4143) 2018-02-20 21:30:54 -08:00
TacoRocket
a666d83164 Updated the windows package build script to be clearer on help and usage. Included the proper Get-Help function included in Windows to display help. Changed help from bool to switch where simply typing -h or -help will display the Get-Help information. Included aliases for the script parameters to help those who like to write options certain ways. Also included parameters names that were clearer to identify but the old parameter names are included as aliases. Both will work if identified so no workflow changes should occur. By default will still build chocolatey (#4117) 2018-02-18 12:12:58 -08:00
Mitchell Grenier
94b48ea87f
Fix JSON output from --json (#4134) 2018-02-16 15:41:44 -08:00
Nick Anderson
f89392bdb4
extensions: adding autoloading python extensions for Windows (#4096) 2018-02-16 13:56:38 -08:00
Mitchell Grenier
21049a26d2
Fix issue [#4123] MSVC Permissive Error (#4131) 2018-02-16 12:57:47 -08:00
Chris Long
e421c398a5 docs: Updating build docs to include make packages (#4068) 2018-02-11 01:58:35 -08:00
uptycs-nishant
c475fe880b TLS session reuse support (#3948) 2018-02-11 01:48:24 -08:00
Mitchell Grenier
3f7dda4475 Fix RapidJSON error asserting in configuration (#4086) 2018-02-11 01:16:38 -08:00
Teddy Reed
6f20eced93
thrift: Optionally build and link with fbthrift (#4105) 2018-02-10 23:37:15 -08:00
packetzero
d058e19345 darwin: Separate IOKit routines from IOKit event support (#4087) 2018-02-09 17:07:53 +00:00
James Jerger
6c3e90e170 Add bitlocker_info to Windows (#4113) 2018-02-09 17:06:32 +00:00
Nick Anderson
290f326957
[Fix 4097] Derive Windows groups for internationalization in MSI (#4112) 2018-02-07 22:28:19 -08:00