Skip to content

Commit

Permalink
Use unique uids for linux incident response (#156)
Browse files Browse the repository at this point in the history
These are clashing with the linux inventory
  • Loading branch information
jaym authored Jul 22, 2024
1 parent 90c660d commit 81486bf
Showing 1 changed file with 8 additions and 8 deletions.
16 changes: 8 additions & 8 deletions core/mondoo-linux-incident-response.mql.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,31 +19,31 @@ packs:
title: Installed kernels
filters: mondoo.capabilities.contains("run-command")
mql: kernel.installed
- uid: mondoo-linux-kernel-info
- uid: mondoo-linux-incident-response-kernel-info
title: Running kernel version
filters: mondoo.capabilities.contains("run-command")
mql: kernel.info
- uid: mondoo-linux-kernel-modules
- uid: mondoo-linux-incident-response-kernel-modules
title: Kernel modules
mql: kernel.modules { name loaded }
- uid: mondoo-linux-incident-response-processes
title: Running processes
filters: mondoo.capabilities.contains("run-command")
mql: processes { pid command }
- uid: mondoo-linux-mounts
- uid: mondoo-linux-incident-response-mounts
title: Mounted devices
mql: mount.list { path fstype device options }
- uid: mondoo-linux-listening-ports
title: All listening ports
- uid: mondoo-linux-incident-response-listening-ports
title: Listening ports
filters: mondoo.capabilities.contains("run-command")
mql: ports.listening
- uid: mondoo-linux-uptime
- uid: mondoo-linux-incident-response-uptime
title: Operating system uptime
filters: mondoo.capabilities.contains("run-command")
mql: os.uptime
- uid: mondoo-linux-installed-packages
- uid: mondoo-linux-incident-response-installed-packages
title: Installed packages
mql: packages { name version arch installed }
- uid: mondoo-linux-running-services
- uid: mondoo-linux-incident-response-running-services
title: Running services
mql: services.where(running == true) { name running enabled masked type }

0 comments on commit 81486bf

Please sign in to comment.