Zercurity

Quickstart

  • Getting Started
    • Registration
    • Enroll your first Asset
      • Installer OSX
      • Installer Linux (Debian)
      • Installer Linux (RHEL)
      • Installer Windows (Standalone)
      • Installer Windows (Active Directory)
      • Installer Docker (Ubuntu)
      • Installer Docker (CentOS)
    • Assets

Application Documentation

  • Companies
    • Table view
    • Create company
  • Teams
    • Table view
    • Create team
  • Users
    • Table view
    • Create user
  • Dashboard
  • Events
    • Table view
  • Enroll Asset
    • Installer OSX
    • Installer Linux (Debian)
    • Installer Linux (RHEL)
    • Installer Windows (Standalone)
    • Installer Windows (Active Directory)
    • Installer Docker (Ubuntu)
    • Installer Docker (CentOS)
  • Assets
    • Table view
    • Asset view
    • Asset processes
    • Asset applications
    • Asset packages
    • Asset networking
    • Asset hard drives
    • Asset usb devices
    • Asset locations
  • Devices
    • Table view
  • Applications
    • Table view
  • Certificates
    • Table view
  • Packages
    • Package view
    • Vulnerabilities view
    • Versions view
  • Query Assets
    • Scheduled queries view
    • Create scheduled query
    • Live queries view
    • Workbench view
    • Logs view
    • Query results
    • Osquery examples
      • Get hashes of running binaries
      • Get open process sockets
      • Mac OSX Firewall enabled
  • Application Whitelisting/Blacklisting
    • Table view
    • Create ruleset
    • Ruleset view
    • Created rule
  • Settings
    • Billing
    • Billing seats
      • What are seats?
      • Adding seats

Asset Query Schema

  • Asset Query Schema 3.3.0
    • account_policy_data
      • Table schema
      • Query examples
    • acpi_tables
      • Table schema
    • ad_config
      • Table schema
    • alf
      • Table schema
    • alf_exceptions
      • Table schema
    • alf_explicit_auths
      • Table schema
    • alf_services
      • Table schema
    • app_schemes
      • Table schema
    • appcompat_shims
      • Table schema
      • Query examples
    • apps
      • Table schema
    • apt_sources
      • Table schema
    • arp_cache
      • Table schema
    • asl
      • Table schema
    • augeas
      • Table schema
      • Query examples
    • authenticode
      • Table schema
      • Query examples
    • authorization_mechanisms
      • Table schema
      • Query examples
    • authorizations
      • Table schema
      • Query examples
    • authorized_keys
      • Table schema
      • Query examples
    • autoexec
      • Table schema
    • battery
      • Table schema
    • bitlocker_info
      • Table schema
    • block_devices
      • Table schema
    • browser_plugins
      • Table schema
      • Query examples
    • carbon_black_info
      • Table schema
    • carves
      • Table schema
      • Query examples
    • certificates
      • Table schema
    • chocolatey_packages
      • Table schema
    • chrome_extensions
      • Table schema
      • Query examples
    • cpu_info
      • Table schema
    • cpu_time
      • Table schema
    • cpuid
      • Table schema
    • crashes
      • Table schema
      • Query examples
    • crontab
      • Table schema
    • cups_destinations
      • Table schema
    • cups_jobs
      • Table schema
    • curl
      • Table schema
      • Query examples
    • curl_certificate
      • Table schema
      • Query examples
    • deb_packages
      • Table schema
    • device_file
      • Table schema
    • device_firmware
      • Table schema
    • device_hash
      • Table schema
    • device_partitions
      • Table schema
    • disk_encryption
      • Table schema
    • disk_events
      • Table schema
    • disk_info
      • Table schema
    • dns_resolvers
      • Table schema
    • docker_container_labels
      • Table schema
      • Query examples
    • docker_container_mounts
      • Table schema
      • Query examples
    • docker_container_networks
      • Table schema
      • Query examples
    • docker_container_ports
      • Table schema
      • Query examples
    • docker_container_processes
      • Table schema
      • Query examples
    • docker_container_stats
      • Table schema
      • Query examples
    • docker_containers
      • Table schema
      • Query examples
    • docker_image_labels
      • Table schema
      • Query examples
    • docker_images
      • Table schema
      • Query examples
    • docker_info
      • Table schema
      • Query examples
    • docker_network_labels
      • Table schema
      • Query examples
    • docker_networks
      • Table schema
      • Query examples
    • docker_version
      • Table schema
      • Query examples
    • docker_volume_labels
      • Table schema
      • Query examples
    • docker_volumes
      • Table schema
      • Query examples
    • drivers
      • Table schema
      • Query examples
    • ec2_instance_metadata
      • Table schema
      • Query examples
    • ec2_instance_tags
      • Table schema
      • Query examples
    • elf_dynamic
      • Table schema
      • Query examples
    • elf_info
      • Table schema
      • Query examples
    • elf_sections
      • Table schema
      • Query examples
    • elf_segments
      • Table schema
      • Query examples
    • elf_symbols
      • Table schema
      • Query examples
    • etc_hosts
      • Table schema
    • etc_protocols
      • Table schema
    • etc_services
      • Table schema
    • event_taps
      • Table schema
    • example
      • Table schema
      • Query examples
    • extended_attributes
      • Table schema
    • fan_speed_sensors
      • Table schema
    • fbsd_kmods
      • Table schema
    • file
      • Table schema
      • Query examples
    • file_events
      • Table schema
    • firefox_addons
      • Table schema
      • Query examples
    • gatekeeper
      • Table schema
    • gatekeeper_approved_apps
      • Table schema
    • groups
      • Table schema
      • Query examples
    • hardware_events
      • Table schema
    • hash
      • Table schema
      • Query examples
    • homebrew_packages
      • Table schema
    • ie_extensions
      • Table schema
    • intel_me_info
      • Table schema
    • interface_addresses
      • Table schema
    • interface_details
      • Table schema
      • Query examples
    • interface_ipv6
      • Table schema
    • iokit_devicetree
      • Table schema
    • iokit_registry
      • Table schema
    • iptables
      • Table schema
    • kernel_extensions
      • Table schema
    • kernel_info
      • Table schema
    • kernel_integrity
      • Table schema
    • kernel_modules
      • Table schema
    • kernel_panics
      • Table schema
    • keychain_acls
      • Table schema
      • Query examples
    • keychain_items
      • Table schema
    • known_hosts
      • Table schema
      • Query examples
    • kva_speculative_info
      • Table schema
      • Query examples
    • last
      • Table schema
    • launchd
      • Table schema
    • launchd_overrides
      • Table schema
    • listening_ports
      • Table schema
    • lldp_neighbors
      • Table schema
    • load_average
      • Table schema
      • Query examples
    • logged_in_users
      • Table schema
    • logical_drives
      • Table schema
      • Query examples
    • logon_sessions
      • Table schema
      • Query examples
    • magic
      • Table schema
    • managed_policies
      • Table schema
    • md_devices
      • Table schema
    • md_drives
      • Table schema
    • md_personalities
      • Table schema
    • mdfind
      • Table schema
      • Query examples
    • memory_array_mapped_addresses
      • Table schema
    • memory_arrays
      • Table schema
    • memory_device_mapped_addresses
      • Table schema
    • memory_devices
      • Table schema
    • memory_error_info
      • Table schema
    • memory_info
      • Table schema
    • memory_map
      • Table schema
    • mounts
      • Table schema
    • msr
      • Table schema
    • nfs_shares
      • Table schema
    • npm_packages
      • Table schema
      • Query examples
    • ntdomains
      • Table schema
      • Query examples
    • ntfs_acl_permissions
      • Table schema
    • nvram
      • Table schema
    • oem_strings
      • Table schema
    • opera_extensions
      • Table schema
      • Query examples
    • os_version
      • Table schema
    • osquery_events
      • Table schema
    • osquery_extensions
      • Table schema
    • osquery_flags
      • Table schema
    • osquery_info
      • Table schema
    • osquery_packs
      • Table schema
    • osquery_registry
      • Table schema
    • osquery_schedule
      • Table schema
    • package_bom
      • Table schema
      • Query examples
    • package_install_history
      • Table schema
    • package_receipts
      • Table schema
      • Query examples
    • patches
      • Table schema
      • Query examples
    • pci_devices
      • Table schema
    • physical_disk_performance
      • Table schema
    • pipes
      • Table schema
      • Query examples
    • pkg_packages
      • Table schema
    • platform_info
      • Table schema
    • plist
      • Table schema
      • Query examples
    • portage_keywords
      • Table schema
    • portage_packages
      • Table schema
    • portage_use
      • Table schema
    • power_sensors
      • Table schema
      • Query examples
    • powershell_events
      • Table schema
      • Query examples
    • preferences
      • Table schema
      • Query examples
    • process_envs
      • Table schema
      • Query examples
    • process_events
      • Table schema
    • process_file_events
      • Table schema
    • process_memory_map
      • Table schema
      • Query examples
    • process_namespaces
      • Table schema
      • Query examples
    • process_open_files
      • Table schema
      • Query examples
    • process_open_sockets
      • Table schema
      • Query examples
    • processes
      • Table schema
      • Query examples
    • programs
      • Table schema
      • Query examples
    • prometheus_metrics
      • Table schema
    • python_packages
      • Table schema
      • Query examples
    • quicklook_cache
      • Table schema
    • registry
      • Table schema
      • Query examples
    • routes
      • Table schema
    • rpm_package_files
      • Table schema
    • rpm_packages
      • Table schema
    • safari_extensions
      • Table schema
      • Query examples
    • sandboxes
      • Table schema
    • scheduled_tasks
      • Table schema
      • Query examples
    • selinux_events
      • Table schema
    • services
      • Table schema
      • Query examples
    • shadow
      • Table schema
      • Query examples
    • shared_folders
      • Table schema
    • shared_memory
      • Table schema
    • shared_resources
      • Table schema
      • Query examples
    • sharing_preferences
      • Table schema
    • shell_history
      • Table schema
      • Query examples
    • signature
      • Table schema
      • Query examples
    • sip_config
      • Table schema
      • Query examples
    • smart_drive_info
      • Table schema
    • smbios_tables
      • Table schema
    • smc_keys
      • Table schema
      • Query examples
    • socket_events
      • Table schema
    • ssh_configs
      • Table schema
      • Query examples
    • startup_items
      • Table schema
    • sudoers
      • Table schema
    • suid_bin
      • Table schema
    • syslog_events
      • Table schema
    • system_controls
      • Table schema
    • system_info
      • Table schema
    • temperature_sensors
      • Table schema
    • time
      • Table schema
    • time_machine_backups
      • Table schema
      • Query examples
    • time_machine_destinations
      • Table schema
      • Query examples
    • ulimit_info
      • Table schema
      • Query examples
    • uptime
      • Table schema
    • usb_devices
      • Table schema
    • user_events
      • Table schema
    • user_groups
      • Table schema
    • user_interaction_events
      • Table schema
    • user_ssh_keys
      • Table schema
      • Query examples
    • users
      • Table schema
      • Query examples
    • video_info
      • Table schema
    • virtual_memory_info
      • Table schema
      • Query examples
    • wifi_networks
      • Table schema
    • wifi_status
      • Table schema
    • wifi_survey
      • Table schema
    • winbaseobj
      • Table schema
      • Query examples
    • windows_crashes
      • Table schema
      • Query examples
    • windows_events
      • Table schema
      • Query examples
    • wmi_bios_info
      • Table schema
      • Query examples
    • wmi_cli_event_consumers
      • Table schema
      • Query examples
    • wmi_event_filters
      • Table schema
      • Query examples
    • wmi_filter_consumer_binding
      • Table schema
      • Query examples
    • wmi_script_event_consumers
      • Table schema
      • Query examples
    • xprotect_entries
      • Table schema
    • xprotect_meta
      • Table schema
    • xprotect_reports
      • Table schema
    • yara
      • Table schema
      • Query examples
    • yara_events
      • Table schema
    • yum_sources
      • Table schema

Developer Resources

  • API
  • Release Notes
    • 26/10/2018
    • 10/09/2018
    • 27/06/2018
    • 19/06/2018
    • 14/06/2018
    • 04/06/2018
    • 28/05/2018
    • 14/05/2018
    • 01/04/2018
    • 11/03/2018
    • 07/03/2018
    • 05/03/2018
    • 05/01/2018
    • 27/11/2017
    • 19/11/2017

Getting Help

  • Contact us
Zercurity
  • Docs »
  • Welcome to Zercurity’s documentation!
  • View page source

Welcome to Zercurity’s documentation!¶

This document will guide you through the ins and outs of using Zercurity. We’ve only just started working on the documentation so bare with us as we put it together!

Quickstart

  • Getting Started
    • Registration
    • Enroll your first Asset
    • Assets

Application Documentation

  • Companies
    • Table view
    • Create company
  • Teams
    • Table view
    • Create team
  • Users
    • Table view
    • Create user
  • Dashboard
  • Events
    • Table view
  • Enroll Asset
    • Installer OSX
    • Installer Linux (Debian)
    • Installer Linux (RHEL)
    • Installer Windows (Standalone)
    • Installer Windows (Active Directory)
    • Installer Docker (Ubuntu)
    • Installer Docker (CentOS)
  • Assets
    • Table view
    • Asset view
    • Asset processes
    • Asset applications
    • Asset packages
    • Asset networking
    • Asset hard drives
    • Asset usb devices
    • Asset locations
  • Devices
    • Table view
  • Applications
    • Table view
  • Certificates
    • Table view
  • Packages
    • Package view
    • Vulnerabilities view
    • Versions view
  • Query Assets
    • Scheduled queries view
    • Create scheduled query
    • Live queries view
    • Workbench view
    • Logs view
    • Query results
    • Osquery examples
  • Application Whitelisting/Blacklisting
    • Table view
    • Create ruleset
    • Ruleset view
    • Created rule
  • Settings
    • Billing
    • Billing seats

Asset Query Schema

  • Asset Query Schema 3.3.0

Developer Resources

  • API
  • Release Notes
    • 26/10/2018
    • 10/09/2018
    • 27/06/2018
    • 19/06/2018
    • 14/06/2018
    • 04/06/2018
    • 28/05/2018
    • 14/05/2018
    • 01/04/2018
    • 11/03/2018
    • 07/03/2018
    • 05/03/2018
    • 05/01/2018
    • 27/11/2017
    • 19/11/2017

Getting Help

  • Contact us
Next

© Copyright 2018, Zercurity.

Built with Sphinx using a theme provided by Read the Docs.
<