Description:Attempts to find PHP webshell type malware in the systemWhat The Data Shows: report if t...
Description: This query checks a registry key to see if Fast Startup is enabled or disabled on the c...
Description: Whether theTelnet Client Enabled, Disabled or AbsentWhat The Data Shows: Telnet is...
Carbon Black Compliance Help Desk Operations IT Hygiene Windows
Description:Shows if you have TFTP enabled, disabled or absent in your windows environment.What...
Carbon Black Compliance Help Desk Operations IT Hygiene Windows
Description: Creates a report of endpoints with Notepad++ installed, including application version, ...
Description: This query looks for any system that has a static IP set.What The Data Shows: The ...
Carbon Black Compliance Help Desk Operations IT Hygiene Linux Windows
Description: This query looks for suspected webshells in the locations they are commonly located, wh...
Description: This query looks for extensions using known extension identifiers.Replace the extension...
Carbon Black Compliance Incident Response IT Hygiene Windows
Description: This query searches the downloads folder of all computers looking for .iso files. Can b...
Description: This query looks for the 'ExecutionPolicy' registry key under HKEY_USERS hive to provid...
Carbon Black Compliance Help Desk Operations Incident Response IT Hygiene Vulnerability Management Windows
The Query Exchange is a place for everyone to take, learn, and share queries. Since Live Query is built off of the open source project Osquery, we want to encourage the spirit of community participation. As a collective group we can help each other be more efficient, more innovative, and more secure. All query submissions default to the “Under Review” stage when initially posted. Once submissions are vetted by Carbon Black, submissions will be updated to reflect “Approved.”
IT Hygiene: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's IT Hygiene.
Compliance: Provides a list of SQL queries that we recommend you run in Live Query to help manage Compliance across your organization.
Incident Response: Provides a list of SQL queries that we recommend you run in Live Query to help during an investigation.
Vulnerability Management: Provides a list of SQL queries that we recommend you run in Live Query to help with Vulnerability Management in your organization.
Help Desk Operations: Provides a list of SQL queries that we recommend you run in Live Query to help with Help Desk items.
Container Support: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's Container Support.