cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Follow the latest information and updates available on the FireEye and SolarWinds situations here.

Query Exchange

QUERIES

Process by user

Approved 1 Comment Submitted by gstrandberg 11-26-2020

Description:This query gives you the started processed also with username
Tested on Windows 7 Wi...

Carbon Black Compliance Incident Response Linux Mac Windows

0Votes

CB Standard (CB Defense) Background Scan Status

Approved 7 Comments Submitted by Alon 11-09-2020

Description: This query leverages the new feature in Audit and Remediation to be able to query the W...

Carbon Black Compliance Help Desk Operations IT Hygiene Windows

4Votes

Finding specific indicators of compromise (IOCs) for Mac in memory or on disk

Approved 5 Comments Submitted by alpopov 10-07-2020

Description: Finding specific indicators of compromise (IOCs) in memory or on disk
What The Data...

Community Mac Vulnerability Management

1Vote

List all inactive security products

Approved 1 Comment Submitted by jaydelcic 10-01-2020

Description: Threat actors disable AV to evade detection. The proposed query probes the state of reg...

Community Incident Response IT Hygiene Windows

2Votes

macOS Disk Encryption

Approved 1 Comment Submitted by stympanick 09-17-2020

Source:https://www.uptycs.com/blog/osquery-tutorial-how-to-check-disk-encryption-on-mac-linux-and-wi...

Community IT Hygiene Mac

3Votes

Audit docker TCP API sockets (re Doki malware)

Approved 1 Comment Submitted by gallen 07-30-2020

Description: This query looks for listening docker daemon TCP sockets. These sockets are vulnerable ...

Carbon Black Compliance IT Hygiene Linux Vulnerability Management

1Vote

Determine CVE-2020-0594 Vulnerability Status

Approved 1 Comment Submitted by DPennyDell 07-02-2020

Description: This query discovers the Intel Management Engine (IME) version, and cross-references it...

Carbon Black Compliance IT Hygiene Vulnerability Management Windows

4Votes

SMBleed CVE-2020-1206 Vulnerability

Approved 1 Comment Submitted by JRoosa 06-11-2020

Description:Lists endpoints that are either vulnerable or not vulnerable to the SMBleed vulnerabilit...

Carbon Black Vulnerability Management Windows

2Votes

query salt-master rpm/deb versions with remote-code-execution vulnerabilities: CVE-2020-11651 and CVE-2020-116...

Approved 1 Comment Submitted by gallen 05-08-2020

Description: This query looks for versions of the salt-master package vulnerable toCVE-2020-11651 an...

Carbon Black Linux Vulnerability Management

1Vote

SMB named pipe based C2/LM activity indicator

Approved 6 Comments Submitted by jaydelcic 05-06-2020

Description: This query looks for the default named pipes used by the most common C2/LM tools.What T...

Community Incident Response Windows

1Vote

Welcome to the Query Exchange

The Query Exchange is a place for everyone to take, learn, and share queries. Since Live Query is built off of the open source project Osquery, we want to encourage the spirit of community participation. As a collective group we can help each other be more efficient, more innovative, and more secure. All query submissions default to the “Under Review” stage when initially posted. Once submissions are vetted by Carbon Black, submissions will be updated to reflect “Approved.”

Query Use Cases

IT Hygiene: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's IT Hygiene.

Compliance: Provides a list of SQL queries that we recommend you run in Live Query to help manage Compliance across your organization.

Incident Response: Provides a list of SQL queries that we recommend you run in Live Query to help during an investigation.

Vulnerability Management: Provides a list of SQL queries that we recommend you run in Live Query to help with Vulnerability Management in your organization.

Help Desk Operations: Provides a list of SQL queries that we recommend you run in Live Query to help with Help Desk items.

Container Support: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's Container Support.