Anonoiyng Rootkit
select * from file where path in ('/usr/sbin/mech', '/usr/sbin/kswapd');View Full Query Detailsselect * from file where path in ('/usr/sbin/mech', '/usr/sbin/kswapd');View Full Query Detailsselect * from launchd where name like 'com.ab.kl%.plist';View Full Query Details
select * from file where path in ('/usr/share/.aPa');View Full Query Detailsselect * from registry where key like 'HKEY_LOCAL_MACHINE\SOFTWARE\%Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%\DisableExceptionChainValidation'View Full Query Details
select * from registry where key like 'HKEY_LOCAL_MACHINE\SOFTWARE\%Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%\executeOptions'View Full Query Details
select * from registry where key like 'HKEY_LOCAL_MACHINE\SOFTWARE\%Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%\MitigationOptions'View Full Query Details
select * from app_schemes;View Full Query Details
select * from registry where key='HKEY_LOCAL_MACHINE\SOFTWARE\%Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers'View Full Query Details
select * from apt_sources;View Full Query Details
select * from file where path in ('/dev/ptyxx');View Full Query Details