2024-02-09 19:34:57 +00:00
|
|
|
name: Team1
|
|
|
|
|
team_settings:
|
|
|
|
|
path: ./team-settings.yml
|
|
|
|
|
agent_options:
|
|
|
|
|
path: ./agent-options.yml
|
|
|
|
|
controls:
|
|
|
|
|
path: ./controls.yml
|
|
|
|
|
queries:
|
|
|
|
|
- path: ./top.queries.yml
|
|
|
|
|
- path: ./empty.yml
|
|
|
|
|
- name: osquery_info
|
|
|
|
|
query: SELECT * from osquery_info;
|
|
|
|
|
interval: 604800 # 1 week
|
|
|
|
|
platform: darwin,linux,windows,chrome
|
|
|
|
|
min_osquery_version: all
|
|
|
|
|
observer_can_run: false
|
|
|
|
|
automations_enabled: true
|
|
|
|
|
logging: snapshot
|
|
|
|
|
policies:
|
|
|
|
|
- path: ./top.policies.yml
|
|
|
|
|
- path: ./top.policies2.yml
|
|
|
|
|
- path: ./empty.yml
|
2024-05-28 16:44:43 +00:00
|
|
|
- name: 😊😊 Failing $POLICY
|
2024-02-09 19:34:57 +00:00
|
|
|
platform: linux
|
|
|
|
|
description: This policy should always fail.
|
|
|
|
|
resolution: There is no resolution for this policy.
|
|
|
|
|
query: SELECT 1 FROM osquery_info WHERE start_time < 0;
|
2024-09-06 22:10:28 +00:00
|
|
|
- path: ./team_install_software.policies.yml
|
|
|
|
|
software:
|
|
|
|
|
packages:
|
|
|
|
|
- path: ./microsoft-teams.pkg.software.yml
|
|
|
|
|
- url: https://ftp.mozilla.org/pub/firefox/releases/129.0.2/mac/en-US/Firefox%20129.0.2.pkg
|
|
|
|
|
self_service: true
|