https://github.com/osquery/osquery logo
#fleet
Title
# fleet
b

Brandon Helms

06/29/2022, 12:01 AM
has anyone built a CIS benchmark pack for fleet?
z

zwass

06/29/2022, 12:10 AM
It's being planned for Q3 cc @Guillaume
🦜 4
🎖️ 1
c

CyberUnify

08/02/2022, 8:19 AM
how is this working @zwass @Guillaume?
g

Guillaume

08/02/2022, 1:56 PM
Hi @CyberUnify! Starting in about 2 weeks you should start seeing queries in our public library for this. What we will do will likely be picking the most important/impactfucl parts of CIS, so don’t expect coverage of the entire set but rather the best parts, starting with macOS
And when I say “starting in about 2 weeks” - I don’t mind they will all drop at once but they will start to get added 🙂 if you have specific things you care about feel free to let me know here so I can prioritize them
c

CyberUnify

08/08/2022, 8:06 AM
Thank you for updates! I consider most important to be the CIS coverage for Windows Server suite
b

Brandon Helms

08/10/2022, 8:50 PM
@CyberUnify windows was pretty easy to implement at my last company because most of it was reg queries. you should be able to that easily. MacOS I found harder because of all the crazy plists and non standard ways to validate.
c

CyberUnify

08/17/2022, 2:23 PM
@Brandon Helms yes, but there are still 70 policy rules that cannot be checked automatically by registry keys
b

Brandon Helms

08/17/2022, 8:01 PM
@CyberUnify I think when we did it we weren't able to build queries for about 200 policy rules.... but I believe we had over 1200 rules for Windows 10
9 Views