cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Query Exchange

QUERIES

Carbon black APIs

Under Review 0 Comments Submitted by shankarj123 3 hours ago

Description: I am looking for carbon black security analysis APIs - For example - i would like submi...

Carbon Black Incident Response Linux Mac Other Windows

0Votes

query salt-master rpm/deb versions with remote-code-execution vulnerabilities: CVE-2020-11651 and CVE-2020-116...

Under Review 0 Comments Submitted by gallen 3 weeks ago

Description: This query looks for versions of the salt-master package vulnerable toCVE-2020-11651 an...

Carbon Black Linux Vulnerability Management

1Vote

SMB named pipe based C2/LM activity indicator

Under Review 0 Comments Submitted by jaydelcic 3 weeks ago

Description: This query looks for the default named pipes used by the most common C2/LM tools.
W...

Community Incident Response Windows

1Vote

Open sockets from Endpoints

Approved 1 Comment Submitted by gstrandberg 04-07-2020

Description:This Query get the currently open sockets from the Endpoints - useful in Incident Respon...

Community Incident Response Linux Mac Windows

2Votes

Windows SMBv3 Client/Server Remote Code Execution Vulnerability (CVE-2020-0796)

Approved 1 Comment Submitted by gallen 03-16-2020

Description:Discover SMB servers potentially vulnerable to CVE-2020-0796. Indicates vulnerability wh...

Carbon Black Vulnerability Management Windows

3Votes

CVE-2020-0796 | Windows SMBv3 RCE

Approved 1 Comment Submitted by s-shimizu 03-13-2020

Description:Query checks forCVE-2020-0796Windows SMBv3 Client/Server Remote Code Execution Vulnerabi...

Community IT Hygiene Windows

3Votes

Linux and macOS X login information

Approved 3 Comments Submitted by stympanick 02-27-2020

Description:Linux and macOS X login information
Source:https://medium.com/@zercurity/building-at...

Carbon Black Help Desk Operations Incident Response IT Hygiene Linux Mac

2Votes

Programs Installed In Non-Standard Windows Locations

Approved 2 Comments Submitted by stympanick 02-27-2020

Description: Programs Installed In Non-Standard Windows Locations
What The Data Shows:Programs I...

Carbon Black Incident Response IT Hygiene Windows

3Votes

Find potential reverse shell or TTY abuse

Approved 6 Comments Submitted by gallen 02-12-2020

Description:
This query searches for socat or scripting connections to TTYs as non-root users. T...

Carbon Black Incident Response Linux

1Vote

CVE-2019-18634: sudo 1.7.1 <= version < 1.8.26 vulnerable when pwfeedback set (query for RHEL/CENTOS)

Approved 1 Comment Submitted by gallen 02-11-2020

Description: This query looks for vulnerable versions of SUDO on rpm-based systems that also have th...

Carbon Black Linux Vulnerability Management

1Vote

Welcome to the Query Exchange

The Query Exchange is a place for everyone to take, learn, and share queries. Since Live Query is built off of the open source project Osquery, we want to encourage the spirit of community participation. As a collective group we can help each other be more efficient, more innovative, and more secure. All query submissions default to the “Under Review” stage when initially posted. Once submissions are vetted by Carbon Black, submissions will be updated to reflect “Approved.”

Query Use Cases

IT Hygiene: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's IT Hygiene.

Compliance: Provides a list of SQL queries that we recommend you run in Live Query to help manage Compliance across your organization.

Incident Response: Provides a list of SQL queries that we recommend you run in Live Query to help during an investigation.

Vulnerability Management: Provides a list of SQL queries that we recommend you run in Live Query to help with Vulnerability Management in your organization.

Help Desk Operations: Provides a list of SQL queries that we recommend you run in Live Query to help with Help Desk items.

Container Support: Provides a list of SQL queries that we recommend you run in Live Query to help with your organization's Container Support.