|
2 | 2 |
|
3 | 3 | This document tracks the coverage of forensic artifacts in Osquery. |
4 | 4 |
|
5 | | -**Last Updated**: 2025-11-07 |
6 | | -**Total Core Artifacts**: 1 available + 39 in progress + 6 not available = 46 total variants |
7 | | -**Total Queries**: 30 (3 core forensic variants + 27 additional) |
8 | | -**Completion Rate**: 2.2% (1/46 core artifacts fully supported) |
| 5 | +**Last Updated**: 2025-12-03 |
| 6 | +**Total Core Artifacts**: 2 available + 38 in progress + 6 not available = 46 total variants |
| 7 | +**Total Queries**: 31 (4 core forensic variants + 27 additional) |
| 8 | +**Completion Rate**: 4.3% (2/46 core artifacts fully supported) |
9 | 9 |
|
10 | 10 | --- |
11 | 11 |
|
12 | 12 | ## Coverage Summary |
13 | 13 |
|
14 | 14 | | Status | Count | Percentage | |
15 | 15 | |--------|-------|------------| |
16 | | -| ✅ Available (Fully Supported) | 0 | 0% | |
17 | | -| ⚠️ In Progress (Needs Validation) | 39 | 87.0% | |
| 16 | +| ✅ Available (Fully Supported) | 2 | 4.3% | |
| 17 | +| ⚠️ In Progress (Needs Validation) | 38 | 82.6% | |
18 | 18 | | ❌ Not Available (Requires Extensions) | 6 | 13.0% | |
19 | 19 |
|
20 | 20 | --- |
@@ -66,8 +66,8 @@ This document tracks the coverage of forensic artifacts in Osquery. |
66 | 66 | | 21a | Tasks | ⚠️ | Linux | - | - | scheduled_tasks table | |
67 | 67 | | 21b | Tasks | ⚠️ | Mac | - | - | scheduled_tasks table | |
68 | 68 | | 22 | User Assist | ⚠️ | Win | - | - | userassist table | |
69 | | -| 23 | WMI Config & Used Apps | ⚠️ | Win | - | - | wmi_cli_event_consumers, wmi_script_event_consumers | |
70 | | -| 24 | WMI Providers & Filters | ⚠️ | Win | - | - | wmi_event_filters, wmi_filter_consumer_binding | |
| 69 | +| 23 | WMI Config & Used Apps | ✅ | Win | wmi_persistence_event_subscriptions | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | wmi_cli_event_consumers, wmi_script_event_consumers - Combined with #24 into single comprehensive query | |
| 70 | +| 24 | WMI Providers & Filters | ✅ | Win | wmi_persistence_event_subscriptions | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | wmi_event_filters, wmi_filter_consumer_binding - Combined with #23 into single comprehensive query | |
71 | 71 | | 25 | MFT | ❌ | Win | - | - | Not natively supported. Available via Trail of Bits extension | |
72 | 72 |
|
73 | 73 | --- |
@@ -105,6 +105,7 @@ These queries existed in the original repository and provide additional coverage |
105 | 105 | | 24 | unsigned_startup_items_vt | ✅ | Win | [b068](kibana/osquery_saved_query/osquery_manager-b0683c20-0dbb-11ed-a49c-6b13b058b135.json) | Unsigned startup items with VirusTotal integration | |
106 | 106 | | 25 | unsigned_dlls_on_system_folders_vt | ✅ | Win | [63c1](kibana/osquery_saved_query/osquery_manager-63c1fe20-176f-11ed-89c6-331eb0db6d01.json) | Unsigned DLLs in system folders with VirusTotal integration | |
107 | 107 | | 26 | executables_in_temp_folder_vt | ✅ | Win | [3e55](kibana/osquery_saved_query/osquery_manager-3e553650-17fd-11ed-89c6-331eb0db6d01.json) | Executables/drivers in temp folders with VirusTotal integration | |
| 108 | +| 27 | wmi_persistence_event_subscriptions | ✅ | Win | [4003](kibana/osquery_saved_query/osquery_manager-40033716-3580-48fe-a17d-441a838acd8a.json) | WMI persistence detection (T1546.003) - bound subscriptions and orphaned components with hash/signature enrichment | |
108 | 109 |
|
109 | 110 | **Note**: Queries with VirusTotal integration require the VirusTotal extension configured in osquery. |
110 | 111 |
|
@@ -162,8 +163,8 @@ While some artifacts are not directly available, the existing queries provide st |
162 | 163 | - ⚠️ Persistence (All platforms: multiple tables) |
163 | 164 | - ⚠️ Registry (Windows: registry table) |
164 | 165 | - ⚠️ Tasks (All platforms: scheduled_tasks table) |
165 | | -- ⚠️ WMI Config & Used Apps (Windows: wmi_cli_event_consumers, wmi_script_event_consumers) |
166 | | -- ⚠️ WMI Providers & Filters (Windows: wmi_event_filters, wmi_filter_consumer_binding) |
| 166 | +- ✅ WMI Config & Used Apps (Windows: wmi_cli_event_consumers, wmi_script_event_consumers) |
| 167 | +- ✅ WMI Providers & Filters (Windows: wmi_event_filters, wmi_filter_consumer_binding) |
167 | 168 | - ⚠️ BITS Jobs Database (Windows: via windows_eventlog) |
168 | 169 |
|
169 | 170 | ### User Activity |
|
0 commit comments