Presented by:

CPE @ Slack

Fleet visibility with osquery and other f/oss tools

This will be a beginner level talk.

  • This will focus more on a practical application
  • a high level of the tools and their integration
  • ie, this how a functioning ecosystem could work, not heavy into one tool or another
  • fleet endpoints will be inclusive of linux, win, and macOS

Planned outline as:

  • A brief overview of Facebook's osquery
  • The idea of Fleet, a distribution point for osquery
  • Setting up and querying fleet machines (Fleet)
  • Using a syslog server for analysis and reporting, (Graylog)

Links

osquery Fleet Graylog

Date:
2018 April 29 - 03:45
Duration:
45 min
Room:
CC-235
Conference:
LinuxFest Northwest 2018
Language:
Track:
Infrastructure
Difficulty:
Easy

Happening at the same time:

  1. ROSECODE
  2. Start Time:
    2018 April 29 03:45

    Room:
    G-103

  3. Don't Fear the Patent Clause!
  4. Start Time:
    2018 April 29 03:45

    Room:
    CC-114

  5. Incident Response with Live Linux Forensics
  6. Start Time:
    2018 April 29 03:45

    Room:
    CC-200

  7. Privacy on the blockchain
  8. Start Time:
    2018 April 29 03:45

    Room:
    HC-108

  9. Hybrid multi-cloud infrastructure as code using Terraform
  10. Start Time:
    2018 April 29 03:45

    Room:
    CC-208

  11. Arduino, ESP8266 and 433 Mhz Devices
  12. Start Time:
    2018 April 29 03:45

    Room:
    CC-236

  13. Old Dogs & New Tricks
  14. Start Time:
    2018 April 29 03:45

    Room:
    CC-115

  15. Using osquery via Fleet for Client/Server visibility
  16. Start Time:
    2018 April 29 03:45

    Room:
    CC-235

  17. Picking Up the Pieces, Issues And Challenges Controlling Your Data
  18. Start Time:
    2018 April 29 03:45

    Room:
    HC-103 Postgres