Skip to content

Commit

Permalink
Added test to Linux.Sys.LastUserLogin (#3237)
Browse files Browse the repository at this point in the history
Also refactored VQL to be a bit faster
  • Loading branch information
scudette authored Jan 22, 2024
1 parent 2a79363 commit 5db9bc4
Show file tree
Hide file tree
Showing 190 changed files with 292 additions and 231 deletions.
2 changes: 1 addition & 1 deletion accessors/data/data.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/file/accessor_darwin.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/file/accessor_freebsd.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/file/accessor_linux.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/file/os_windows.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/ntfs/mft.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/ntfs/ntfs_accessor.go
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ package ntfs
// This is an accessor which represents an NTFS filesystem
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/raw_registry/raw_registry.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/registry/registry_windows.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/zip/gzip.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion accessors/zip/zip.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion actions/events.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion actions/vql.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/api.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/artifacts.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/assets.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/auth.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/authenticators/azure.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/authenticators/github.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/authenticators/google.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/clients.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/download.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/handlers.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/proxy.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/query.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/reflect.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/tables/table.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/vfs.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
2 changes: 1 addition & 1 deletion api/vql.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
/*
Velociraptor - Dig Deeper
Copyright (C) 2019-2022 Rapid7 Inc.
Copyright (C) 2019-2024 Rapid7 Inc.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
Expand Down
10 changes: 5 additions & 5 deletions artifacts/definitions/Linux/Detection/Yara/Process.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -92,16 +92,16 @@ sources:
Meta,
String.Name as YaraString,
String.Offset as HitOffset,
upload( accessor='scope',
file='String.Data',
name=format(format="%v-%v_%v_%v",
upload( accessor='scope',
file='String.Data',
name=format(format="%v-%v_%v_%v",
args=[ ProcessName, Pid, String.Offset, ContextBytes ]
)) as HitContext
FROM proc_yara(
pid=Pid,
rules=yara_rules,
context=ContextBytes,
number=NumberOfHits
number=NumberOfHits
)
})
Expand All @@ -122,4 +122,4 @@ sources:
column_types:
- name: HitContext
type: preview_upload
type: preview_upload
Loading

0 comments on commit 5db9bc4

Please sign in to comment.