Skip to content

Conversation

jwindley
Copy link
Contributor

@jwindley jwindley commented Sep 8, 2025

Adding a couple of MacOS detections (first of many, hopefully), using data captured from TA-osquery.

@ljstella
Copy link
Contributor

ljstella commented Sep 8, 2025

Testing is failing - Testing environment does not currently have the osquery TA for this dataset, a new release hasn't been cut on that repo, and the app itself is archived from Splunkbase (don't think it'll be unarchived either due to changes in Splunk Works) - We'll need an actual release package of that TA and getting it into the config before testing can pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants