groob
theopolis
theopolis
theopolis
alessandrogario
seph
seph
sundsta
03/16/2020, 9:42 PMprocess_file_events
and socket_events
to macOS and Windows?alessandrogario
Stefano Bonicatti
03/17/2020, 3:16 PMAntoinette
03/17/2020, 8:35 PMStefano Bonicatti
04/07/2020, 9:43 PMfd.hasSafePermissions()
call here: https://github.com/osquery/osquery/blob/a9770451c527eba4cf321fe23c5306beff6ac20b/osquery/filesystem/filesystem.cpp#L527 outside the if, store the status and print status.getMessage()
in VLOG(), because the function returns a message with the failure case, but it's currently ignoredStefano Bonicatti
04/09/2020, 4:12 PMzwass
Chris Broome
04/09/2020, 4:28 PMseph
Stefano Bonicatti
04/09/2020, 11:15 PMStefano Bonicatti
04/10/2020, 3:53 PMStefano Bonicatti
04/14/2020, 4:27 PMthor
seph
theopolis
thor
Chris Broome
05/13/2020, 8:04 PMterracatta
sharvil
05/26/2020, 6:59 PM1. Whether the EndpointSecurity Client must be a system extension?
My understanding is that EndpointSecurity require that clients run as root and have the entitlement, meaning there’s no specific requirement that the client be a system extension. This is in contrast to other subsystems, like system-wide NetworkExtensions, which must be packaged as system extensions.
Mike Myers
06/01/2020, 5:15 PMseph
Update language to use 'allow list' and 'deny list'
, than the details spread over 3 PRs.Stefano Bonicatti
06/07/2020, 12:11 PMtheopolis