kolide / osquery-starter-kit
A starter-kit for a source-controlled, CLI-based osquery management workflow.
☆30Updated 6 years ago
Alternatives and similar repositories for osquery-starter-kit:
Users that are interested in osquery-starter-kit are comparing it to the libraries listed below
- ALPHA/WIP for OSquery configuration for Mac and Linux Operating Systems☆16Updated 7 years ago
- Dockerfiles for containerized osquery☆13Updated 7 years ago
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆62Updated last year
- [DEPRECATED] A quickstart demo for Kolide tools☆52Updated 6 years ago
- Example Express application for collecting data from the Stethoscope app☆14Updated 6 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆53Updated last month
- Launchd daemon that reports major OSX modifications through growl☆16Updated 9 years ago
- Deploy Kolide's Fleet into AWS using Terraform.☆15Updated 6 years ago
- Osquery Mangement Server☆114Updated 4 years ago
- ☆15Updated 5 years ago
- Create Logstash events from the Okta API!☆19Updated 2 years ago
- first commit☆20Updated last year
- Things to know when DFIR occurs near a vault deployment.☆43Updated 6 years ago
- Osquery Packs we use for customer security hardening☆12Updated 3 months ago
- ☆17Updated 7 years ago
- D4 core software (server and sample sensor client)☆43Updated last year
- ☆46Updated 9 years ago
- Materials for the BSides NoVA/Charleston 2018 Bro Workshop☆14Updated last year
- Looks for GitHub org users without 2FA turned on☆9Updated 8 years ago
- The boilerplate for a new Journal site☆21Updated 5 years ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 5 years ago
- osquery query packs☆14Updated 6 years ago
- Build Automated Machine Images for MISP☆28Updated last year
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 6 years ago
- A python script to shift the timestamp on syslog data. Useful for forensicators combating time skew.☆20Updated 2 years ago
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆34Updated last year