Skip to content

Commit d8f08b1

Browse files
committed
Update artifacts matrix with WMI persistence coverage
- Mark WMI Config & Used Apps (#23) as available - Mark WMI Providers & Filters (#24) as available - Add wmi_persistence_event_subscriptions to Additional Queries - Update coverage statistics: 2/46 artifacts now fully supported (4.3%)
1 parent 6c17fd7 commit d8f08b1

File tree

1 file changed

+11
-10
lines changed

1 file changed

+11
-10
lines changed

packages/osquery_manager/artifacts_matrix.md

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,19 +2,19 @@
22

33
This document tracks the coverage of forensic artifacts in Osquery.
44

5-
**Last Updated**: 2025-11-07
6-
**Total Core Artifacts**: 1 available + 39 in progress + 6 not available = 46 total variants
7-
**Total Queries**: 30 (3 core forensic variants + 27 additional)
8-
**Completion Rate**: 2.2% (1/46 core artifacts fully supported)
5+
**Last Updated**: 2025-12-03
6+
**Total Core Artifacts**: 2 available + 38 in progress + 6 not available = 46 total variants
7+
**Total Queries**: 31 (4 core forensic variants + 27 additional)
8+
**Completion Rate**: 4.3% (2/46 core artifacts fully supported)
99

1010
---
1111

1212
## Coverage Summary
1313

1414
| Status | Count | Percentage |
1515
|--------|-------|------------|
16-
| ✅ Available (Fully Supported) | 0 | 0% |
17-
| ⚠️ In Progress (Needs Validation) | 39 | 87.0% |
16+
| ✅ Available (Fully Supported) | 2 | 4.3% |
17+
| ⚠️ In Progress (Needs Validation) | 38 | 82.6% |
1818
| ❌ Not Available (Requires Extensions) | 6 | 13.0% |
1919

2020
---
@@ -66,8 +66,8 @@ This document tracks the coverage of forensic artifacts in Osquery.
6666
| 21a | Tasks | ⚠️ | Linux | - | - | scheduled_tasks table |
6767
| 21b | Tasks | ⚠️ | Mac | - | - | scheduled_tasks table |
6868
| 22 | User Assist | ⚠️ | Win | - | - | userassist table |
69-
| 23 | WMI Config & Used Apps | ⚠️ | Win | - | - | wmi_cli_event_consumers, wmi_script_event_consumers |
70-
| 24 | WMI Providers & Filters | ⚠️ | Win | - | - | wmi_event_filters, wmi_filter_consumer_binding |
69+
| 23 | WMI Config & Used Apps | | Win | wmi_persistence_event_subscriptions | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | wmi_cli_event_consumers, wmi_script_event_consumers - Combined with #24 into single comprehensive query |
70+
| 24 | WMI Providers & Filters | | Win | wmi_persistence_event_subscriptions | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | wmi_event_filters, wmi_filter_consumer_binding - Combined with #23 into single comprehensive query |
7171
| 25 | MFT || Win | - | - | Not natively supported. Available via Trail of Bits extension |
7272

7373
---
@@ -105,6 +105,7 @@ These queries existed in the original repository and provide additional coverage
105105
| 24 | unsigned_startup_items_vt || Win | [b068](kibana/osquery_saved_query/osquery_manager-b0683c20-0dbb-11ed-a49c-6b13b058b135.json) | Unsigned startup items with VirusTotal integration |
106106
| 25 | unsigned_dlls_on_system_folders_vt || Win | [63c1](kibana/osquery_saved_query/osquery_manager-63c1fe20-176f-11ed-89c6-331eb0db6d01.json) | Unsigned DLLs in system folders with VirusTotal integration |
107107
| 26 | executables_in_temp_folder_vt || Win | [3e55](kibana/osquery_saved_query/osquery_manager-3e553650-17fd-11ed-89c6-331eb0db6d01.json) | Executables/drivers in temp folders with VirusTotal integration |
108+
| 27 | wmi_persistence_event_subscriptions || Win | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | WMI persistence detection (T1546.003) - bound subscriptions and orphaned components with hash/signature enrichment |
108109

109110
**Note**: Queries with VirusTotal integration require the VirusTotal extension configured in osquery.
110111

@@ -162,8 +163,8 @@ While some artifacts are not directly available, the existing queries provide st
162163
- ⚠️ Persistence (All platforms: multiple tables)
163164
- ⚠️ Registry (Windows: registry table)
164165
- ⚠️ Tasks (All platforms: scheduled_tasks table)
165-
- ⚠️ WMI Config & Used Apps (Windows: wmi_cli_event_consumers, wmi_script_event_consumers)
166-
- ⚠️ WMI Providers & Filters (Windows: wmi_event_filters, wmi_filter_consumer_binding)
166+
- WMI Config & Used Apps (Windows: wmi_cli_event_consumers, wmi_script_event_consumers)
167+
- WMI Providers & Filters (Windows: wmi_event_filters, wmi_filter_consumer_binding)
167168
- ⚠️ BITS Jobs Database (Windows: via windows_eventlog)
168169

169170
### User Activity

0 commit comments

Comments
 (0)