osquery-defense-kit
                                
                                
                                
                                    osquery-defense-kit copied to clipboard
                            
                            
                            
                        Make a `socket_events` port of `unexpected-https-client-linux`
Detection will be less racy on machines with eventing enabled.
See the currently ported queries as a template to use:
- https://github.com/chainguard-dev/osquery-defense-kit/blob/main/detection/c2/unexpected-icmp-socket-events.sql
 - https://github.com/chainguard-dev/osquery-defense-kit/blob/main/detection/c2/unexpected-dns-traffic-events.sql