Skip to content

Commit

Permalink
Automated commit to rebuild the static site
Browse files Browse the repository at this point in the history
Signed-off-by: Build and Push Automation Script <>
  • Loading branch information
Amndeep7 authored and Build and Push Automation Script committed Feb 27, 2023
1 parent 9f06a95 commit 6a882ac
Show file tree
Hide file tree
Showing 9 changed files with 485 additions and 485 deletions.
100 changes: 50 additions & 50 deletions docs/analytics/by_technique/index.md

Large diffs are not rendered by default.

622 changes: 311 additions & 311 deletions docs/car_attack/car_attack.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/data/analytics.json

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions docs/sensors/auditd_2.8.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,17 +15,13 @@ auditd is the userspace component to the Linux Auditing System. It's responsible

## Data Model Coverage

### [file](../data_model/file)
### [process](../data_model/process)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || | | | ||| ||| | | ||
| `delete` | | || ||| | | | || || | | | ||| ||| | | ||
| `modify` | | || ||| | | | || || | | | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||
| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

Expand All @@ -42,13 +38,17 @@ auditd is the userspace component to the Linux Auditing System. It's responsible
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | | ||| | | | || | | | || | | | |||| | | ||

### [process](../data_model/process)
### [file](../data_model/file)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || | | | ||| ||| | | ||
| `delete` | | || ||| | | | || || | | | ||| ||| | | ||
| `modify` | | || ||| | | | || || | | | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||



Expand Down
32 changes: 16 additions & 16 deletions docs/sensors/osquery_4.1.2.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,17 +14,13 @@ osquery exposes an operating system as a high-performance relational database. T

## Data Model Coverage

### [file](../data_model/file)
### [process](../data_model/process)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || | | | ||| ||| | | ||
| `delete` | | || ||| | | | || || | | | ||| ||| | | ||
| `modify` | | || ||| | | | || || | | | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||
| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

Expand All @@ -41,13 +37,17 @@ osquery exposes an operating system as a high-performance relational database. T
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | | ||| | | | || | | | || | | | |||| | | ||

### [process](../data_model/process)
### [file](../data_model/file)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || | | | ||| ||| | | ||
| `delete` | | || ||| | | | || || | | | ||| ||| | | ||
| `modify` | | || ||| | | | || || | | | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||



Expand Down
32 changes: 16 additions & 16 deletions docs/sensors/osquery_4.6.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,17 +14,13 @@ osquery exposes an operating system as a high-performance relational database. T

## Data Model Coverage

### [file](../data_model/file)
### [process](../data_model/process)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || || | ||| ||| | |||
| `delete` | | || ||| | | | || || || | ||| ||| | |||
| `modify` | | || ||| | | | || || || | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || || | ||| ||| | | ||
| `write` | | || ||| | | | || || || | ||| ||| | | ||
| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||||| | | || || | | | ||||| | | | | | | || |
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

Expand All @@ -41,13 +37,17 @@ osquery exposes an operating system as a high-performance relational database. T
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | | ||| | | | || | | | || | | | |||| | | ||

### [process](../data_model/process)
### [file](../data_model/file)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||||| | | || || | | | ||||| | | | | | | || |
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || ||| | | | || || || | ||| ||| | |||
| `delete` | | || ||| | | | || || || | ||| ||| | |||
| `modify` | | || ||| | | | || || || | ||| ||| | | ||
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || ||| | | | || || || | ||| ||| | | ||
| `write` | | || ||| | | | || || || | ||| ||| | | ||



Expand Down
50 changes: 25 additions & 25 deletions docs/sensors/sysmon_10.4.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,14 +14,13 @@ Sysmon is a freely available program from Microsoft that is provided as part of

## Data Model Coverage

### [thread](../data_model/thread)
### [process](../data_model/process)

| | `hostname` | `src_pid` | `src_tid` | `stack_base` | `stack_limit` | `start_address` | `start_function` | `start_module` | `start_module_name` | `tgt_pid` | `tgt_tid` | `uid` | `user` | `user_stack_base` | `user_stack_limit` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `create` ||| | | |||| ||| | | | |
| `remote_create` ||| | | |||| ||| | | | |
| `suspend` | | | | | | | | | | | | | | | |
| `terminate` | | | | | | | | | | | | | | | |
| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| | || | ||||| | |||||| | | | | | | | ||
| `terminate` | | | | | | || | || | | | | | || | | | | | | | | | | | |

### [registry](../data_model/registry)

Expand All @@ -32,18 +31,6 @@ Sysmon is a freely available program from Microsoft that is provided as part of
| `remove` | ||| ||| || | ||
| `value_edit` | | | | | | | | | | | |

### [file](../data_model/file)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || || || | | || | | | | | || | | | | | | | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || || || | | || | | | | | || || | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
Expand All @@ -58,6 +45,15 @@ Sysmon is a freely available program from Microsoft that is provided as part of
| `load` | || ||| ||||| || |
| `unload` | | | | | | | | | | | | | |

### [thread](../data_model/thread)

| | `hostname` | `src_pid` | `src_tid` | `stack_base` | `stack_limit` | `start_address` | `start_function` | `start_module` | `start_module_name` | `tgt_pid` | `tgt_tid` | `uid` | `user` | `user_stack_base` | `user_stack_limit` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `create` ||| | | |||| ||| | | | |
| `remote_create` ||| | | |||| ||| | | | |
| `suspend` | | | | | | | | | | | | | | | |
| `terminate` | | | | | | | | | | | | | | | |

### [flow](../data_model/flow)

| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
Expand All @@ -66,13 +62,17 @@ Sysmon is a freely available program from Microsoft that is provided as part of
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | |||| | | | || | | | || | | ||||| | | ||

### [process](../data_model/process)
### [file](../data_model/file)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| | || | ||||| | |||||| | | | | | | | ||
| `terminate` | | | | | | || | || | | | | | || | | | | | | | | | | | |
| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || || || | | || | | | | | || | | | | | | | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || || || | | || | | | | | || || | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |



Expand Down
Loading

0 comments on commit 6a882ac

Please sign in to comment.