{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":531211589,"defaultBranch":"main","name":"osquery-defense-kit","ownerLogin":"chainguard-dev","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2022-08-31T18:33:46.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/87436699?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1711721793.0","currentOid":""},"activityList":{"items":[{"before":"a0c49efb3fc021b2cf7852fb4fe32d4b3940d7ec","after":"4601b6c2fa3a3c4713c01dfe81eda8aa59af1e26","ref":"refs/heads/main","pushedAt":"2024-05-24T01:25:22.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #366 from tstromberg/fpr-may22\n\nfpr: Fedora Silverblue, MHLinkServer, Elastic, ptyxis, Zed","shortMessageHtmlLink":"Merge pull request #366 from tstromberg/fpr-may22"}},{"before":"6dd798c4a083e42341419a01911bb6e01ffe321b","after":"a0c49efb3fc021b2cf7852fb4fe32d4b3940d7ec","ref":"refs/heads/main","pushedAt":"2024-04-29T13:33:45.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #365 from tstromberg/fpr-apr25\n\nmark command-events & execdir-events as 'extra' due to high CPU usage","shortMessageHtmlLink":"Merge pull request #365 from tstromberg/fpr-apr25"}},{"before":"2f790f040847db623e86e36622dcd2d8ae332069","after":"6dd798c4a083e42341419a01911bb6e01ffe321b","ref":"refs/heads/main","pushedAt":"2024-04-26T20:14:37.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #364 from tstromberg/fpr-apr25\n\nfpr: MHLink, k3d, BlueFin, query tuning","shortMessageHtmlLink":"Merge pull request #364 from tstromberg/fpr-apr25"}},{"before":"dd6b2e43fb113f72b4130ab234c0354b2889a85d","after":"2f790f040847db623e86e36622dcd2d8ae332069","ref":"refs/heads/main","pushedAt":"2024-03-29T14:13:55.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #363 from tstromberg/springbreak\n\nFPR: Docker, Yubikey, Aerospace, WhatsApp, nuclei, etc.","shortMessageHtmlLink":"Merge pull request #363 from tstromberg/springbreak"}},{"before":"a673c28222b845775ee90488f46fb6e2ce732786","after":"dd6b2e43fb113f72b4130ab234c0354b2889a85d","ref":"refs/heads/main","pushedAt":"2024-03-15T23:10:28.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #360 from jedsalazar/pr/jed/harden-runner-osq-dk\n\nAdd Harden Runner audit configs","shortMessageHtmlLink":"Merge pull request #360 from jedsalazar/pr/jed/harden-runner-osq-dk"}},{"before":"6eb5b9ebdb4b24b8959f6ecdcd3e5464143d83d2","after":"a673c28222b845775ee90488f46fb6e2ce732786","ref":"refs/heads/main","pushedAt":"2024-03-15T23:07:10.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #362 from tstromberg/kandji\n\nPerformance tuning, mark some Linux queries as 'extra'","shortMessageHtmlLink":"Merge pull request #362 from tstromberg/kandji"}},{"before":"7c5599c07d396279d14ebee5f97006482a008307","after":"6eb5b9ebdb4b24b8959f6ecdcd3e5464143d83d2","ref":"refs/heads/main","pushedAt":"2024-03-15T19:35:44.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #361 from tstromberg/kandji\n\nAllow Kandji to do weird things with expect","shortMessageHtmlLink":"Merge pull request #361 from tstromberg/kandji"}},{"before":"72f182847504c24f7d7d365c8511b0fbe8a5461f","after":"7c5599c07d396279d14ebee5f97006482a008307","ref":"refs/heads/main","pushedAt":"2024-03-07T21:34:35.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #359 from tstromberg/fpr-mar7\n\nfpr: snapd, cups, ubuntu, etc","shortMessageHtmlLink":"Merge pull request #359 from tstromberg/fpr-mar7"}},{"before":"51ecee8d9b511e0378b22ed9c7e2c78cf9bdbd8f","after":"72f182847504c24f7d7d365c8511b0fbe8a5461f","ref":"refs/heads/main","pushedAt":"2024-02-26T22:29:47.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #358 from tstromberg/fpr-feb26\n\nfpr: Docker Desktop, code-oss, incus, geoclue, etc","shortMessageHtmlLink":"Merge pull request #358 from tstromberg/fpr-feb26"}},{"before":"d1f6aede22e15aed0712a5999c3c8e1db06f9c9a","after":"51ecee8d9b511e0378b22ed9c7e2c78cf9bdbd8f","ref":"refs/heads/main","pushedAt":"2024-02-23T21:27:36.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #357 from tstromberg/feb16-fpr\n\nfpr: Incus, Firefox, mbim, networkd, incus","shortMessageHtmlLink":"Merge pull request #357 from tstromberg/feb16-fpr"}},{"before":"6b5d7445053667275d44d7f11921ba56a74bc163","after":"d1f6aede22e15aed0712a5999c3c8e1db06f9c9a","ref":"refs/heads/main","pushedAt":"2024-02-23T20:10:23.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #356 from tstromberg/ktaint\n\nIgnore taint code 4096 (out-of-tree driver)","shortMessageHtmlLink":"Merge pull request #356 from tstromberg/ktaint"}},{"before":"0d5467e72da69bf03a2a4eb5c17e487d7e75e1fd","after":"6b5d7445053667275d44d7f11921ba56a74bc163","ref":"refs/heads/main","pushedAt":"2024-02-16T22:24:41.000Z","pushType":"pr_merge","commitsCount":5,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #355 from tstromberg/feb16-fpr\n\nfpr: Elastic, IR, Velociraptor, BitDefender, incus, Adguard","shortMessageHtmlLink":"Merge pull request #355 from tstromberg/feb16-fpr"}},{"before":"9b66ef1d293e1c8d3121beb810198f853d6e499c","after":"0d5467e72da69bf03a2a4eb5c17e487d7e75e1fd","ref":"refs/heads/main","pushedAt":"2024-02-05T15:51:26.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #354 from tstromberg/fpr-feb5\n\nfpr: Elastic Defend, gcloud, Warp, etc","shortMessageHtmlLink":"Merge pull request #354 from tstromberg/fpr-feb5"}},{"before":"23a0e572df963db1f8b243353f405288135ecc92","after":"9b66ef1d293e1c8d3121beb810198f853d6e499c","ref":"refs/heads/main","pushedAt":"2024-02-05T14:20:19.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #353 from tstromberg/spctl\n\nAdd TTP details from https://www.sentinelone.com/blog/backdoor-activa…","shortMessageHtmlLink":"Merge pull request #353 from tstromberg/spctl"}},{"before":"0d94ed9f6aa7a361181ebacfafd4d30beec032f5","after":"23a0e572df963db1f8b243353f405288135ecc92","ref":"refs/heads/main","pushedAt":"2024-01-26T19:25:09.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #352 from tstromberg/fpr-jan22\n\nmassive fpr: Rapid7, Elastic, everything","shortMessageHtmlLink":"Merge pull request #352 from tstromberg/fpr-jan22"}},{"before":"2da9171f43e3e9ebbe1d32a6040978b9a0483ccf","after":"0d94ed9f6aa7a361181ebacfafd4d30beec032f5","ref":"refs/heads/main","pushedAt":"2024-01-22T15:42:55.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #351 from tstromberg/fpr-jan22\n\nFpr jan22","shortMessageHtmlLink":"Merge pull request #351 from tstromberg/fpr-jan22"}},{"before":"54fc45e787db17d9913ce9782d44c63af05dc262","after":"2da9171f43e3e9ebbe1d32a6040978b9a0483ccf","ref":"refs/heads/main","pushedAt":"2024-01-22T15:42:18.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #350 from jedsalazar/pr/jed/pin-action-digests-osquery-defense-kit\n\npin to shas and upgrade actions workflows and osquery client","shortMessageHtmlLink":"Merge pull request #350 from jedsalazar/pr/jed/pin-action-digests-osq…"}},{"before":"eaf42fbcd7a86331f5f56598e67de507498f6655","after":"54fc45e787db17d9913ce9782d44c63af05dc262","ref":"refs/heads/main","pushedAt":"2024-01-18T22:18:43.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #349 from tstromberg/fpr-jan18-2\n\nfpr: snap, mutedeck, idea, Chrome exts","shortMessageHtmlLink":"Merge pull request #349 from tstromberg/fpr-jan18-2"}},{"before":"944b9b7bcdec9626d348b9f7869b5469d4f1c701","after":"eaf42fbcd7a86331f5f56598e67de507498f6655","ref":"refs/heads/main","pushedAt":"2024-01-10T16:21:02.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #348 from tstromberg/rapid7-elastic-bob\n\nfpr: elastic, rapid7, zwift","shortMessageHtmlLink":"Merge pull request #348 from tstromberg/rapid7-elastic-bob"}},{"before":"568cb3c988a3e351b93492e6457bf92a86ab41b8","after":"944b9b7bcdec9626d348b9f7869b5469d4f1c701","ref":"refs/heads/main","pushedAt":"2024-01-10T14:48:49.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #347 from tstromberg/new-times\n\nSet a time limit of 8s for query output","shortMessageHtmlLink":"Merge pull request #347 from tstromberg/new-times"}},{"before":"de2bdd3fd76da7682c9c84a3283c0c29d948ac64","after":"568cb3c988a3e351b93492e6457bf92a86ab41b8","ref":"refs/heads/main","pushedAt":"2024-01-10T14:42:59.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #346 from tstromberg/fix-kolide-err\n\nRename current_time column to now_ts to avoid Kolide import issue","shortMessageHtmlLink":"Merge pull request #346 from tstromberg/fix-kolide-err"}},{"before":"46defeab6f257f6ce3db885209c4ab0e7ff92ad2","after":"de2bdd3fd76da7682c9c84a3283c0c29d948ac64","ref":"refs/heads/main","pushedAt":"2024-01-09T22:23:04.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #345 from tstromberg/fix-yara-err\n\nrecently downloaded go-crypt: Fix YARA error","shortMessageHtmlLink":"Merge pull request #345 from tstromberg/fix-yara-err"}},{"before":"1462745390d5d6439e6d1784e9a8fe6728b2aec9","after":"46defeab6f257f6ce3db885209c4ab0e7ff92ad2","ref":"refs/heads/main","pushedAt":"2024-01-09T21:57:34.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #344 from tstromberg/simpler-make\n\nSimplify makefile, reduce config targets to 4","shortMessageHtmlLink":"Merge pull request #344 from tstromberg/simpler-make"}},{"before":"16dd48b2f58e09b591bf6ae820edd2cee748ddea","after":"1462745390d5d6439e6d1784e9a8fe6728b2aec9","ref":"refs/heads/main","pushedAt":"2024-01-09T21:21:03.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #343 from tstromberg/fpr-jan9\n\nfpr: syncthing, sourcegraph, phantombuster, iterm, cody, stickers","shortMessageHtmlLink":"Merge pull request #343 from tstromberg/fpr-jan9"}},{"before":"d02d01b62d4293d862dd5c691fac3cc990bd163a","after":"16dd48b2f58e09b591bf6ae820edd2cee748ddea","ref":"refs/heads/main","pushedAt":"2024-01-09T00:08:57.000Z","pushType":"pr_merge","commitsCount":5,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #342 from tstromberg/fpr-jan5\n\nfpr: Elastic Defend, Rapid7 InsightIDR & others","shortMessageHtmlLink":"Merge pull request #342 from tstromberg/fpr-jan5"}},{"before":"3914fa7e407ca7ebd0c5b4e6f5d5af1c1660f0de","after":"d02d01b62d4293d862dd5c691fac3cc990bd163a","ref":"refs/heads/main","pushedAt":"2024-01-08T20:56:01.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #341 from tstromberg/osqtool-141\n\nUpgrade osqtool to v1.4.1","shortMessageHtmlLink":"Merge pull request #341 from tstromberg/osqtool-141"}},{"before":"79bbdb025706f4a40fd580ee4205d2e289616f34","after":"3914fa7e407ca7ebd0c5b4e6f5d5af1c1660f0de","ref":"refs/heads/main","pushedAt":"2023-12-26T19:49:20.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"jedsalazar","name":"Jed Salazar","path":"/jedsalazar","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/15161603?s=80&v=4"},"commit":{"message":"Merge pull request #340 from jedsalazar/pr/jed/add-macdown-exception\n\nAdd Macdown as an exception to minimal-socket-client-macos","shortMessageHtmlLink":"Merge pull request #340 from jedsalazar/pr/jed/add-macdown-exception"}},{"before":"f8cc56cfdea94a0074cac7c2e229a46825931ca4","after":"79bbdb025706f4a40fd580ee4205d2e289616f34","ref":"refs/heads/main","pushedAt":"2023-12-15T22:30:29.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #339 from tstromberg/combined-detection\n\nmake: Add combined-detection.conf & osqtool versioning","shortMessageHtmlLink":"Merge pull request #339 from tstromberg/combined-detection"}},{"before":"b5f61f48479d2f47f4e6d00c845edf67ccb587e7","after":"f8cc56cfdea94a0074cac7c2e229a46825931ca4","ref":"refs/heads/main","pushedAt":"2023-12-15T22:21:05.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #338 from tstromberg/dec15\n\nfpr: A little bit of everything","shortMessageHtmlLink":"Merge pull request #338 from tstromberg/dec15"}},{"before":"1aaf59c36cafb71fda74eb57dac793c0a401b6e3","after":"b5f61f48479d2f47f4e6d00c845edf67ccb587e7","ref":"refs/heads/main","pushedAt":"2023-12-12T17:57:55.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #337 from tstromberg/linuxperf\n\nexotic events linux: optimize query for reduced system CPU","shortMessageHtmlLink":"Merge pull request #337 from tstromberg/linuxperf"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEUpMcLgA","startCursor":null,"endCursor":null}},"title":"Activity · chainguard-dev/osquery-defense-kit"}