Releases: RasterSec/fleetdm-osquery-defense-kit
Releases · RasterSec/fleetdm-osquery-defense-kit
FleetDM Queries v20260210-1089334
FleetDM-compatible queries from osquery-defense-kit
Based on upstream commit: 1089334 (2025-08-13)
Query counts
| Category | Count |
|---|---|
| Detection | 163 |
| Incident Response | 101 |
| Policy | 5 |
| Total | 269 |
Usage
Download the YAML files and import to FleetDM:
fleetctl apply -f chainguard-all.ymlOr import individual categories:
fleetctl apply -f chainguard-detection.yml
fleetctl apply -f chainguard-incident-response.yml
fleetctl apply -f chainguard-policy.ymlScheduled Queries
Use these files if you want scheduled intervals:
# Detection rules every 5 minutes
fleetctl apply -f chainguard-detection-5min.yml
# Incident response rules every 10 minutes
fleetctl apply -f chainguard-incident-response-10min.yml