heroui logo

Osquery Agent Outdated

Panther Rules

View Source
Summary
The Osquery Agent Outdated detection rule monitors whether the installed version of the Osquery agent is outdated compared to the current recommended version, which is 5.10.2. This rule is part of a compliance initiative intended to ensure that systems running Osquery are updated to this version to mitigate potential security vulnerabilities associated with older versions. The rule is configured to log results based on the actions taken by the Osquery agent and expects to have records that can either indicate that the Osquery version is out of date or confirm it is up to date. The expected outcomes are verified using specified test conditions that check against the agent's reported version in the logs. If an outdated version is detected, the runbook suggests updating the Osquery agent to ensure compliance and security.
Categories
  • Endpoint
  • Linux
  • macOS
Data Sources
  • Process
  • Application Log
Created: 2022-09-02