Commit Graph

3966 Commits

Author SHA1 Message Date
Teddy Reed
501bb22de9 deps: Add rapidjson bottle for macOS (#3591) 2017-08-22 12:01:40 -07:00
Teddy Reed
a7330e41fc deps: Update Linux bottles libcryptsetup libdevmapper libdpkg rapidjson (#3590) 2017-08-22 11:52:49 -07:00
Teddy Reed
1fadfb11d4 deploy: Change OLD_PIDFILE for systemd to be LOCAL_PIDFILE (#3589) 2017-08-22 10:46:25 -07:00
Teddy Reed
48ab0c783c logger: Use a mutex to protect buffered counts (#3588) 2017-08-22 01:30:13 -07:00
Nick Anderson
8bb1e40d27 tables: porting the process_memory_map table to windows (#3587) 2017-08-21 21:47:45 -07:00
Teddy Reed
57f6e37839 audit: Handle AUDIT_SOCKADDR messages (#3586) 2017-08-21 20:53:32 -07:00
Teddy Reed
072aa7dad1 sql: Handle potential LIKE and GLOB optimizations by increasing comparisons (#3580) 2017-08-21 19:31:44 -07:00
Nick Anderson
cbed65d10e tables: Adding list indexing to darwin plist table (#3546) 2017-08-21 09:29:33 -07:00
Teddy Reed
7b2f905f43 aws: Fix TSAN warning in request exception (#3556) 2017-08-21 01:04:58 -07:00
Teddy Reed
89f1de3a3b leaks: Return 1 if profile detects any leaks in tables (#3578) 2017-08-20 21:41:33 -07:00
Teddy Reed
2e5beca2e2 deps: Add doxygen and valgrind and remove realpath requirement (#3577) 2017-08-20 20:14:53 -07:00
Teddy Reed
cf170c4278 cleanup: Move query out of database header (#3576) 2017-08-20 02:44:38 -07:00
uptycs-nishant
5a92d2c7f0 Implementing exclude paths for FIM (#3530) 2017-08-19 19:59:23 -07:00
Nick Anderson
5172580ac8 bug: Processes name correctly displays uid for domain users (#3574) 2017-08-18 21:51:39 -07:00
Nick Anderson
efcc879450 deploy: adding sanity checks to deployment powershell scripts (#3572) 2017-08-18 13:32:41 -07:00
Mark Ignacio
04b51fd450 add LVM and parental contexts to block_devices and disk_encryption on Linux (#3551) 2017-08-15 10:33:54 -07:00
Nick Anderson
22de4c7d34 Adding build script for llvm-clang package (#3565) 2017-08-14 20:23:36 -07:00
iBigQ
6600361230 fix c++ doc for rapidjson arguments (#3559) 2017-08-14 10:55:45 -07:00
Teddy Reed
2e6a0e7e2f build: Set DEPS_DIR in the make defines (#3557) 2017-08-13 02:52:29 -07:00
Teddy Reed
c141dd390f sanitizers: Skip several tests that fail custom alloc checks (#3555) 2017-08-13 02:01:05 -07:00
Teddy Reed
98c91e337f deps: Fix Linux build-world and link math for cryptsetup (#3554) 2017-08-13 00:10:03 -07:00
Allan Liu
3a70fd7336 md tables: additional bounds checking around substr calls (#3532) 2017-08-10 18:14:39 -07:00
Mitchell Grenier
c680e7d1c7 Fix an sqlite3 memory leak in quicklook_cache (#3552) 2017-08-10 12:02:59 -07:00
lxcode
d391c3e585 Fix memory leak (#3553) 2017-08-10 11:45:00 -07:00
Chris Long
293331e244 Adding detection for osx-mughthesec (#3550) 2017-08-09 16:42:57 -07:00
Chris Long
1c9d6e4394 Updating shell_history in IR pack (#3549) 2017-08-09 15:57:23 -07:00
Nick Anderson
b42b3d677e tables: adding scheduled action to windows scheduled tasks table (#3543) 2017-08-09 09:54:39 -07:00
Teddy Reed
38c3d3dce9 deps: Update LVM2/devmapper to r173 and install lvm2app (#3547) 2017-08-08 18:11:09 -07:00
Thomas Maurice
a41ff4117f linux usb_devices: add the class, subclass and protocol information (#3542) 2017-08-08 12:17:29 -07:00
Teddy Reed
242ca5f484 implement LIKEs for extended attributes table (#3541) 2017-08-08 08:00:55 -07:00
Vishwa Shah
c54c6e6c0e corrected size in block_devices on darwin, linux (#3539) 2017-08-07 19:21:18 -07:00
Hugh Neale
2b48fbc557 A fix for Mac OSX process start_time (#3534) 2017-08-07 17:49:12 -07:00
Mitchell Grenier
8a963e8d40 [Distributed] Moving to RapidJSON (#3265) 2017-08-07 16:34:44 -07:00
Mitchell Grenier
b22a403bf1 OpenBSM Events (#3503) 2017-08-07 16:02:16 -07:00
Nick Anderson
b4316a57a0 tables: Adding certificates virtual table for windows (#3498) 2017-08-07 09:08:53 -07:00
Nick Anderson
405ec99476 Adding threads and start_time fields to processes table (#3536) 2017-08-06 20:58:18 -07:00
Nick Anderson
0ef2037bd4 Updating package path written to stdout for deployment (#3537) 2017-08-06 20:58:05 -07:00
Teddy Reed
3dd5fcadcb deps: Fix libdpkg download url (#3535) 2017-08-06 16:57:07 -07:00
Seshu Pasam
9dc69ee282 Minor static analysis fixes. (#3529) 2017-08-04 18:22:10 -07:00
Zachary Wasserman
af444370f4 Fix memory leaks in Gatekeeper table (#3531) 2017-08-04 18:19:50 -07:00
Mitchell Grenier
e577a76b9b macOS - Listeners on folders that throw mount events (#3506) 2017-08-03 18:09:04 -07:00
Seshu Pasam
34a6cfe74e Option to skip ccache for running static analysis tools like coverity (#3526) 2017-08-03 18:02:26 -07:00
Nick Anderson
c34d9f8348 windows: Updating various chocolatey powershell build scripts (#3427) 2017-08-03 18:01:10 -07:00
Seshu Pasam
32ad42aea0 EC2 instance metadata implementation. (#3502) 2017-08-03 17:54:17 -07:00
Nick Anderson
ea5f06bfc5 [Fix #3527] Addressing interface indexing in arp_cache table (#3528) 2017-08-03 17:49:58 -07:00
Teddy Reed
7ca18f5a32 audit: Add cwd to process_events on Linux (#3525) 2017-08-03 08:21:15 -07:00
Teddy Reed
d581be4ef0 Fix #3522: Do not call SQL ctor directly (#3524) 2017-08-02 20:20:19 -07:00
Teddy Reed
2e54af369d deps: Update AWS-SDK 1.1.20 bottles (#3523) 2017-08-02 20:20:00 -07:00
Seshu Pasam
6495f14828 EC2 instance tags implementation. (#3507) 2017-08-02 13:40:59 -07:00
Teddy Reed
b56accb089 format: Remove Cpp restriction (#3521) 2017-08-02 10:32:12 -07:00