Teddy Reed
59750ec87d
Speed up file hashing
2015-12-11 00:36:16 -08:00
Teddy Reed
1a1b07b5c6
Merge pull request #1716 from theopolis/pack_shards
...
[#1636 ] Add simple sharding to packs and pack queries
2015-12-10 17:37:57 -08:00
Lex Neva
e9c183d962
DRY for inotify event mask (we missed IN_MOVE)
2015-12-10 16:00:02 -05:00
Teddy Reed
9d394065e3
[ #1636 ] Add simple sharding to packs and pack queries
2015-12-10 10:01:53 -08:00
Teddy Reed
309944c586
Configuration triggered publisher reconfiguration
2015-12-08 14:03:35 -08:00
Teddy Reed
6602a59b7d
Change EventSubscriber API to include subscription references
2015-12-07 22:22:04 -08:00
Teddy Reed
b7650e5291
Remove passwd_changes and user_data from event callbacks
2015-12-07 17:47:38 -08:00
Teddy Reed
b88d6816f3
Additional TSK tables
2015-12-07 08:36:22 -08:00
Teddy Reed
ad07e07879
Make chrome extension identifiers easier to extract
2015-12-04 11:50:13 -08:00
Teddy Reed
1acba4dfa6
Merge pull request #1700 from theopolis/tsk2
...
TSK integration and example tables
2015-12-04 11:26:03 -08:00
Teddy Reed
373ce339dc
TSK integration and example tables
2015-12-04 11:08:51 -08:00
Teddy Reed
e5bc6410ba
Merge pull request #1697 from theopolis/fix_1660
...
[Fix #1660 ] Prevent spurious NETLINK recv retries
2015-12-02 23:56:39 -08:00
Teddy Reed
4dc6b9f0a3
[ Fix #1660 ] Prevent spurious NETLINK recv retries
2015-12-02 23:33:20 -08:00
Teddy Reed
ffb5b7020e
[ Fix #1693 , #1527 ] Add osquery-specific query planner output
2015-12-02 19:57:24 -08:00
Teddy Reed
ccff0c8c18
[ Fix #1686 ] Add 'subject' and 'signing_algorithm' to certificates
2015-11-29 18:32:13 -08:00
Teddy Reed
2e57869d34
Merge pull request #1681 from theopolis/fix_1665
...
[#1665 , #1615 ] Refactor user-based tables to act uniformly
2015-11-24 13:07:28 -08:00
Teddy Reed
35129a7af7
[ #1665 , #1615 ] Refactor user-based tables to act uniformly
2015-11-24 12:46:25 -08:00
Teddy Reed
5370fef950
Merge pull request #1678 from theopolis/audit_user_events
...
[#1497 ] Add user_events table based on audit user-type messages
2015-11-23 21:31:37 -08:00
Teddy Reed
07fd718e00
Add user_events table based on audit user-type messages
2015-11-23 18:13:31 -08:00
Teddy Reed
08c7911eb7
Merge pull request #1655 from theopolis/iokit_events
...
Rewrite OS X hardware events to use IOKit proper
2015-11-21 19:45:10 -08:00
Teddy Reed
6748fdb024
Rewrite OS X hardware events to use IOKit proper
2015-11-21 19:31:05 -08:00
Teddy Reed
7ca7974dfb
Merge pull request #1668 from cdown/f/freebsd_uid
...
freebsd process table: Fix EUID/EGID to not use saved IDs
2015-11-21 11:19:36 -08:00
Teddy Reed
283f7c6d59
Fix clang analyze failures in signature table
2015-11-21 09:56:19 -08:00
Chris Down
d4d87a69ce
freebsd process table: Fix EUID/EGID to not use saved IDs
...
It's not totally clear why saved IDs were used here. There is some precident in
sigar (https://github.com/hyperic/sigar ), where they also use the saved UID,
but me and @wxsBSD are not really sure why. Maybe it's because kinfo_proc feels
different than similar structs on other Unices.
Fixes #1662 .
2015-11-21 02:52:06 -08:00
Teddy Reed
8425010874
Merge pull request #1664 from stripe/andrew-better-homebrew
...
Determine Homebrew Cellar from binary
2015-11-20 16:06:30 -08:00
Andrew Dunham
161f8b9fd0
Determine Homebrew Cellar from binary
...
We look at the location of the Homebrew binary `brew` on disk, and use
the real path (i.e. path with all symlinks resolved) from that binary to
determine the Cellar. This behavior mirrors that of Homebrew itself.
2015-11-20 15:15:18 -08:00
Teddy Reed
9ae53f2158
Merge pull request #1663 from cdown/f/saved_ids
...
Add saved UIDs and GIDs to process table
2015-11-20 14:35:20 -08:00
Teddy Reed
5cd040eb35
Merge pull request #1667 from theopolis/add_hash_check
...
Use a noexcept method of directory checking for hash
2015-11-20 14:24:43 -08:00
Teddy Reed
a72fa19536
Use a noexcept method of directory checking for hash
2015-11-20 13:32:56 -08:00
Teddy Reed
a673a793fe
Merge pull request #1659 from PickmanSec/knownhosts
...
Added known_hosts table
2015-11-20 12:46:13 -08:00
Teddy Reed
16247f10e8
Merge pull request #1624 from PickmanSec/master
...
added authorized_keys table
2015-11-19 09:10:59 -08:00
Chris Down
39bdec4c8d
Add saved UIDs and GIDs to process table
2015-11-18 16:44:07 -08:00
Michael George
dde59f8c18
Added known_hosts file
...
added known_hosts table
2015-11-17 12:38:19 -08:00
Michael George
a649bf6733
Added authorized_keys table
...
Fixed mislabled variable from line parsing
Update authorized_keys.cpp
Update authorized_keys.cpp
Check if line is empty
2015-11-16 10:36:24 -08:00
Andrew Dunham
a0932105f6
Refactor how we determine the OS version in the signature table
2015-11-11 11:34:15 -08:00
Teddy Reed
aa4973a1b3
Merge pull request #1644 from stripe/andrew-add-timezone
...
Add timezone field to time table
2015-11-10 16:41:39 -08:00
Teddy Reed
daee71919a
Merge pull request #1642 from stripe/andrew-add-codesign
...
Add a `signature` table on Darwin
2015-11-10 16:23:16 -08:00
Andrew Dunham
0ae380297f
Add timezone field to time table
2015-11-10 15:17:49 -08:00
Andrew Dunham
dea93c8aa5
Add a signature
table on Darwin
...
This table allows verifying the signature of files (or bundles) on
Darwin. It also provides the signing identifier that is a part of the
signature.
2015-11-10 13:21:18 -08:00
Teddy Reed
0a6d334f27
Fix missed nullptr checks in wifi
2015-11-10 01:01:12 -08:00
Teddy Reed
57e8ef2ab3
[ #1546 ] Add computer_name to system_info and extend to Linux
2015-11-04 10:31:16 -08:00
Teddy Reed
084ccaf080
Use default blank value for startup_items Alias
2015-11-03 22:58:00 -08:00
Teddy Reed
cd4de8023f
Merge pull request #1630 from theopolis/fix_1626
...
[Fix #1626 ] Add schedule blacklist and protect DBHandle
2015-11-03 21:05:29 -08:00
Teddy Reed
edea3d6edd
[ Fix #1626 ] Add schedule blacklist and protect DBHandle
2015-11-03 20:50:22 -08:00
Teddy Reed
5aa225d4c3
Merge pull request #1619 from sharvilshah/wifi
...
Implement wifi_networks tables for OS X
2015-11-02 16:11:21 -08:00
Teddy Reed
15215cdbc0
Add persistent splays
2015-11-02 14:10:04 -08:00
Teddy Reed
5233d7dcf8
Add start time to osquery_info, remove md5/path
2015-11-02 10:57:01 -08:00
Teddy Reed
75bfcddc31
Merge pull request #1622 from theopolis/faster_sockets
...
Faster socket_events on Linux
2015-11-02 10:56:37 -08:00
Teddy Reed
a1a9131174
Optimize socket_events and Linux users
2015-11-02 10:37:56 -08:00
Teddy Reed
50550e607a
Build and provision edits for FreeBSD CI
2015-11-02 01:47:09 -08:00