← All talks

Live Interrogation With Osquery

BSides Augusta · 201825:46121 viewsPublished 2018-10Watch on YouTube ↗
Speakers
Tags
CategoryTechnical
About this talk
Josh Brower (@DefensiveDepth) Osquery is an open source endpoint visibility tool that allows you to query your system as if it is a relational database. We will introduce osquery, and then demonstrate how to use it to interrogate a suspect system. The focus will be on abnormal process attributes as well as common persistence techniques.