From 6625f6ffbb14e3f36ce4c3f8efabbd8979bfd928 Mon Sep 17 00:00:00 2001 From: Jay Mundrawala Date: Mon, 22 Jul 2024 13:53:36 -0500 Subject: [PATCH] Use unique uids for linux incident response These are clashing with the linux inventory --- core/mondoo-linux-incident-response.mql.yaml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/core/mondoo-linux-incident-response.mql.yaml b/core/mondoo-linux-incident-response.mql.yaml index 0f8f70c..1049254 100644 --- a/core/mondoo-linux-incident-response.mql.yaml +++ b/core/mondoo-linux-incident-response.mql.yaml @@ -19,31 +19,31 @@ packs: title: Installed kernels filters: mondoo.capabilities.contains("run-command") mql: kernel.installed - - uid: mondoo-linux-kernel-info + - uid: mondoo-linux-incident-response-kernel-info title: Running kernel version filters: mondoo.capabilities.contains("run-command") mql: kernel.info - - uid: mondoo-linux-kernel-modules + - uid: mondoo-linux-incident-response-kernel-modules title: Kernel modules mql: kernel.modules { name loaded } - uid: mondoo-linux-incident-response-processes title: Running processes filters: mondoo.capabilities.contains("run-command") mql: processes { pid command } - - uid: mondoo-linux-mounts + - uid: mondoo-linux-incident-response-mounts title: Mounted devices mql: mount.list { path fstype device options } - - uid: mondoo-linux-listening-ports - title: All listening ports + - uid: mondoo-linux-incident-response-listening-ports + title: Listening ports filters: mondoo.capabilities.contains("run-command") mql: ports.listening - - uid: mondoo-linux-uptime + - uid: mondoo-linux-incident-response-uptime title: Operating system uptime filters: mondoo.capabilities.contains("run-command") mql: os.uptime - - uid: mondoo-linux-installed-packages + - uid: mondoo-linux-incident-response-installed-packages title: Installed packages mql: packages { name version arch installed } - - uid: mondoo-linux-running-services + - uid: mondoo-linux-incident-response-running-services title: Running services mql: services.where(running == true) { name running enabled masked type }