home.social

#osquery — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #osquery, aggregated by home.social.

  1. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  2. #osquery defense kit v1.6.0 just dropped with some new #blueteam queries: github.com/chainguard-dev/osqu

    - unencrypted #GCP service account keys
    - unexpected #sysctl calls
    - unexpected #xattr calls
    - unexpected file made #executable
    - unexpected Security.Framework program

    If nothing else, I hope the queries are useful ideas for others! Have a great weekend. 🌴