## Summary - Adds 152 MITRE ATT&CK framework threat detection queries to the Fleet query library (`docs/queries.yml`) - Queries cover Linux (23), macOS (18), and Windows (36) platforms, plus cross-platform queries - Mapped to specific ATT&CK techniques (T1025, T1033, T1053, T1078, T1548, etc.) - All queries tagged with `MITRE, ATT&CK, threat detection` for easy filtering on the website ## Details Queries are sourced from the [fleet-osquery-attck](https://github.com/MitchF/fleet-osquery-attck) project and cover: - **Discovery**: Process, account, system information, network connections - **Persistence**: Cron jobs, startup items, launch agents/daemons, registry run keys - **Credential Access**: SSH keys, browser credentials, sudoers - **Execution**: Command interpreters, scheduled tasks, shell history - **Defense Evasion**: Rootkit detection, process injection, file integrity - **Lateral Movement**: SSH connections, remote services ## Test plan - [x] Verify `docs/queries.yml` parses correctly during website build (`build-static-content.js`) - [ ] Verify MITRE queries appear on https://fleetdm.com/queries with proper platform filtering - [ ] Verify no slug collisions with existing queries - [ ] Verify contributor profile resolves for `MitchF` GitHub username
Fleet documentation
Welcome to the documentation for Fleet, the lightweight management platform for laptops and servers.
You can also read the Fleet docs over at https://fleetdm.com/docs.
Using Fleet
Resources for using the Fleet UI, fleetctl CLI, and Fleet REST API.
Deploying
Resources for installing Fleet's infrastructure dependencies, configuring Fleet, deploying osquery to hosts, and viewing example deployment scenarios.
Contributing
If you're interested in interacting with the Fleet source code, you'll find information on modifying and building the code here.
If you have any questions, please don't hesitate to File a GitHub issue or join us on Slack. You can find us in the #fleet channel.