Tech notes
seek to understand the question
  • Home
  • Posts
  • OSQuery
  • query-index
  • About
  • Privacy
  1. Home
  2. OSquery

Svchost.exe Incorrect Path

OSquery
SELECT * FROM processes WHERE LOWER(name)='svchost.exe' AND LOWER(path)!='c:\windows\system32\svchost.exe' AND LOWER(path)!='c:\windows\syswow64\svchost.exe' AND path!='';
View Full Query Details

SysmonConfig

OSquery
select * from registry where key='HKEY_LOCAL_MACHINE\SYSTEM\CCS\Services\SysmonDrv\Parameters'
View Full Query Details

T0rn Rootkit

OSquery
select * from file where path in ('/usr/src/.puta', '/usr/info/.t0rn', '/lib/ldlib.tk', '/etc/ttyhash', '/sbin/xlogin');
View Full Query Details

Tc2 Worm

OSquery
select * from file where path in ('/usr/info/.tc2k', '/usr/bin/util', '/usr/sbin/initcheck', '/usr/sbin/ldb');
View Full Query Details

Telekit Trojan

OSquery
select * from file where path in ('/dev/hda06', '/usr/info/libc1.so');
View Full Query Details

Temperatures

OSquery
select * from temperature_sensors;
View Full Query Details

Tibet.D

OSquery
select * from launchd where path like '%com.apple.AudioService.plist';
View Full Query Details

TouchVPN

OSquery
SELECT * FROM users JOIN chrome_extensions USING (uid) WHERE identifier='bihmplhobchoageeokmgbdihknkjbknd';
View Full Query Details

TransparentEnabledMachine

OSquery
select * from registry where key='HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled'
View Full Query Details

TransparentEnabledUser

OSquery
select * from registry where key like 'HKEY_USERS\%\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled'
View Full Query Details
Previous 1… 22 23 24 25 26 27 Next

Recent Posts

  • Connect private network to AWS using ZeroTier
  • Using kitchen-salt for testing salt-formulas
  • RPM package creation for BRO IDS Deployments
  • Installing pf_ring on CentOS 7 using yum
  • Using a systemd.service file to control promiscuous mode automatically at boot

Platforms

  • darwin 32
  • linux 65
  • posix 21
  • windows 4

Categories

  • Linux 25
  • Logging 14
  • NSM 1
  • Open Source 3
  • OSquery 269
  • SaltStack 4
  • Security 15
  • Sys Admin 30
  • VMware 2

Archives

  • September 2019 1
  • August 2019 1
  • July 2018 2
  • February 2018 1
  • April 2017 1
  • January 2017 1
  • December 2016 8
  • June 2016 1
  • January 2016 5
  • February 2015 11

Post Series

  • Setting up a multi-tiered log infrastructure
  • Setup internal yum repositories for CentOS and RedHat Servers
© 2025 Tech notes. Generated with Hugo and a heavily modified Roadster theme.