Tech notes
seek to understand the question
  • Home
  • Posts
  • OSQuery
  • query-index
  • About
  • Privacy
  1. Home
  2. Query Index

# A B C D E F G H I J K L M N O P Q R S T U V W X Z

#

  • 55808.a Worm

A

  • Acpi Tables
  • Ad Config
  • Adore Rootkit
  • Adore Worm
  • Ajakit Rootkit
  • Alf
  • Alf Exceptions
  • Alf Explicit Auths
  • Alf Services
  • Anonoiyng Rootkit
  • Aobo Keylogger
  • Apa Kit
  • App DisabledExceptionChainValidation
  • App ExecuteOptions
  • App MitigationOptions
  • App Schemes
  • AppCompat
  • Apt Sources
  • Ark Rootkit
  • Arp Cache
  • AuditSpecialGroups

B

  • Backdoor MAC Eleanor
  • Backdoored Python Packages
  • Bash Door
  • Beastkit Rootkit
  • Behavioral Reverse Shell
  • BetternetVPN
  • BlazingKeylogger
  • Bmbl Rootkit
  • Bobkit Rootkit
  • Browser Plugins
  • Buca
  • Bundlore

C

  • CallMe
  • Careto
  • Cback Worm
  • CCleaner Trojan Stage2.Floxif
  • CCleaner Trojan.Floxif
  • Chrome Extensions
  • Chrometana
  • Codecm
  • Conduit
  • Conhost.exe Incorrect Path
  • ControlFlowGuard
  • CopyFish
  • Cpuid
  • Crontab
  • CwdIllegalInDllSearch

D

  • Darwin Kernel System Controls
  • Deb Packages
  • DefaultLevelMachine
  • DefaultLevelUser
  • DepPolicy
  • DeveloperMode
  • Device Nodes
  • DevilRobber
  • DisabledExceptionChainValidation
  • Disallowed
  • Disallowed Paths
  • Disallowed Paths ItemData
  • Disk Encryption
  • Dllhost.exe Incorrect Path
  • Dockster

E

  • Efi File Hashes
  • EliteKeylogger
  • EmPyre Agent
  • EnableCertPaddingCheck
  • EnableCertPaddingCheck Wow64
  • EnableLowVaAccess
  • Enye Sec Rootkit
  • Esrk Rootkit
  • Etc Hosts
  • Events
  • ExecutableTryMachine
  • ExecutableTryUser

F

  • Fan Speeds
  • Firefox Addons
  • FontBlocking
  • Fu Rootkit

G

  • Genieo
  • GenieoPart2
  • Giphy

H

  • HackingTeam Mac Persistence
  • HackingTeam Mac RAT1
  • HackingTeam Mac RAT2
  • HackingTeam Mac RAT3
  • Hardware Events
  • Hidr00tkit
  • HolaVPN
  • Homebrew Packages

I

  • Icefog
  • Illogic Rootkit
  • Imuler
  • InfinityNewTab
  • Inqtana
  • Installed Applications
  • Iokit Devicetree
  • Ip Forwarding
  • Iptables
  • IWorkServ
  • IWorm
  • IWorm 1

J

  • Java Adwind Trojan

K

  • Kenga3 Rootkit
  • Keranger 1
  • Keranger 2
  • Kernel Extensions
  • Kernel Info
  • Kernel Modules
  • KernelSehopEnabled
  • Kextstat
  • Keychain Items
  • Knark Installed

L

  • Last
  • Launchd
  • Ldp Worm
  • Leverage-A 1
  • Leverage-A 2
  • Leverage-A 3
  • Lion Worm
  • Listening Ports
  • Loc Rookit
  • Logged In Users
  • Loginwindow1
  • Loginwindow2
  • Loginwindow3
  • Loginwindow4
  • Lrk Rootkit
  • Lsass.exe Incorrect Path

M

  • MacKontrol
  • MacOSInstallCore
  • MacSearch Adware
  • Madalin Rootkit
  • Maniac Rk
  • Mithra`s Rootkit
  • MitigationOptions
  • Monkit
  • Monkit Found
  • Morcut
  • Mounts
  • MoveImages

N

  • Nfs Shares
  • Nvram

O

  • OceanLotus Dropped File 1
  • OceanLotus Launchagent
  • Old Rootkits
  • Olyx
  • Omega Worm
  • Open Files
  • Open Sockets
  • OpenType Font Driver Vulnerability
  • Opera Extensions
  • Optickit
  • OS Version
  • Osquery Info
  • OSX Backdoor Mokes
  • OSX ColdRoot RAT Files
  • OSX ColdRoot RAT Launchd
  • OSX DOK 1
  • OSX DOK 2
  • OSX DOK 3
  • OSX DOK 4
  • OSX Dummy Files
  • OSX Dummy Launchd
  • OSX FruitFly
  • OSX HiddenLotus
  • OSX Keydnap
  • OSX Komplex
  • OSX MaMi Certificate
  • OSX MaMi DNS Servers
  • OSX Mughthesec
  • OSX Pirrit
  • OSX Proton Files
  • OSX Proton Launchd
  • OSX Proton Process
  • OSX Snake
  • Override Rootkit

P

  • Package Receipts
  • Pci Devices
  • Phalanx Rootkit
  • PolicyScopeMachine
  • PolicyScopeUser
  • Portage Packages
  • PremierOpinion
  • Process Env
  • Process Memory
  • Pronto
  • Protecting Against Weak Crypto Algo
  • PubSab

Q

  • Quimitchin Backdoor

R

  • Ramdisk
  • Ramen Worm
  • Recent Items
  • Rh Sharpe
  • Rk17
  • Romanian Rootkit
  • Rpm Packages
  • Rsha
  • Rule
  • RuleSetEnforcementMode

S

  • Sadmind/iis Worm
  • Safari Extensions
  • SaferFlags
  • Sandboxes
  • Scalper Installed
  • Schedule
  • SearchInstUpdater
  • SecureBoot
  • Services.exe Incorrect Parent Process
  • Shell History
  • Shitc
  • Shkit Rootkit
  • Showtee
  • Showtee / Romanian Rootkit
  • Shv5 Rootkit
  • Sip Config
  • Slapper Installed
  • Smbios Tables
  • SniperSpy
  • SocialFixer
  • Solaris Worm
  • Spigot
  • Startup Items
  • StickyKeys File Replace Backdoor
  • StickyKeys Registry Backdoor
  • Suckit Rootkit
  • Suid Bin
  • Suspicious File
  • Svchost.exe Incorrect Parent Process
  • Svchost.exe Incorrect Path
  • SysmonConfig

T

  • T0rn Rootkit
  • Tc2 Worm
  • Telekit Trojan
  • Temperatures
  • Tibet.D
  • TouchVPN
  • TransparentEnabledMachine
  • TransparentEnabledUser
  • Tribe Bot
  • Trk Rootkit
  • Tuxkit Rootkit

U

  • UAC Disabled
  • Unauthenticated Sparkle Feeds
  • Unrestricted
  • Unrestricted Paths
  • Unrestricted Paths ItemData
  • UnTabs 1
  • UnTabs 2
  • USB Devices

V

  • Volc Rootkit
  • Vsearch

W

  • WebDeveloper
  • WebPaint
  • Whitesmoke
  • Windows Drivers
  • Windows Patches
  • Windows Programs
  • Windows Shared Resources
  • Winsecurity Info 1
  • Winsecurity Info 2
  • Wireless Networks
  • WireLurker

X

  • XcodeGhost
  • Xprotect Reports
  • XSLCmd

Z

  • Zarwt Rootkit
  • Zk Rootkit

Recent Posts

  • Connect private network to AWS using ZeroTier
  • Using kitchen-salt for testing salt-formulas
  • RPM package creation for BRO IDS Deployments
  • Installing pf_ring on CentOS 7 using yum
  • Using a systemd.service file to control promiscuous mode automatically at boot

Platforms

  • darwin 32
  • linux 65
  • posix 21
  • windows 4

Categories

  • Linux 25
  • Logging 14
  • NSM 1
  • Open Source 3
  • OSquery 269
  • SaltStack 4
  • Security 15
  • Sys Admin 30
  • VMware 2

Archives

  • September 2019 1
  • August 2019 1
  • July 2018 2
  • February 2018 1
  • April 2017 1
  • January 2017 1
  • December 2016 8
  • June 2016 1
  • January 2016 5
  • February 2015 11

Post Series

  • Setting up a multi-tiered log infrastructure
  • Setup internal yum repositories for CentOS and RedHat Servers
© 2025 Tech notes. Generated with Hugo and a heavily modified Roadster theme.