osquery extensions by Trail of Bits
This release brings some new changes to the Santa tables, and a new experimental (not yet ready for production) DNS monitoring table.
This extension allows users to acquire the Santa activity log and the configured rules. Thanks to the osquery writable tables, it is also possible to add and remove new configuration rules (provided that there is no sync-server configured).
The table has been split into two:
This experimental extension (not yet ready for production) aims at introducing new network monitoring capabilities to osquery.
This table captures the DNS queries and answers that have been passing through the configured interface.
Location: /var/osquery/extensions/com/trailofbits/network_monitor.json
.
{
"dns_events": {
"interface": "interface_name"
}
}
Initial release containing all the extensions we have published. Note that osquery 3.3.0 is required to run them.