Enye Sec Rootkit
select * from file where path in ('/etc/.enyelkmHIDE^IT.ko');View Full Query Detailsselect * from file where path in ('/etc/.enyelkmHIDE^IT.ko');View Full Query Detailsselect * from file where path in ('/usr/lib/tcl5.3');View Full Query Detailsselect * from etc_hosts;View Full Query Details
select name, publisher, type, subscriptions, events, active from osquery_events;View Full Query Details
select * from registry where key='HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\ExecutableTry'View Full Query Details
select * from registry where key like 'HKEY_USERS\%\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\ExecutableTry'View Full Query Details
select * from fan_speed_sensors;View Full Query Details
select firefox_addons.* from users join firefox_addons using (uid);View Full Query Details
select * from registry where key='HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\MitigationOptions\MitigationOptions_FontBlocking'View Full Query Details
select * from file where path in ('/sbin/xc', '/usr/include/ivtype.h', '/bin/.lib');View Full Query Details