hobo
12/03/2018, 8:45 AM钢铁侠
12/03/2018, 1:00 PMsql
select * from process_events
select socket_events.*,process_events.cmdline,process_events.cwd,process_events.pid as pepid from socket_events left join process_events on socket_events.pid=process_events.pid;
but I found that the cmdline
,cwd
,pepid
are all empty in socket_events
.for eaxmple
cmd: curl <https://osquery.io>
name": "process_events",
"@version": "1",
"columns": {
"parent": "21451",
"cwd": "\"/root\"",
"btime": "0",
"auid": "1001",
"egid": "0",
"atime": "1448209686",
"owner_gid": "0",
"owner_uid": "0",
"path": "/usr/bin/curl",
"cmdline": "curl <https://osquery.io>",
"gid": "0",
"pid": "21923",
"ctime": "1461222192",
"time": "1543840554",
"uptime": "28088276",
"mode": "0100755",
"mtime": "1448209686",
"uid": "0",
"euid": "0"
},
"name": "socket_events",
"@version": "1",
"columns": {
"pepid": "",
"local_port": "0",
"cwd": "",
"status": "unknown",
"auid": "1001",
"path": "/usr/bin/curl",
"action": "connect",
"cmdline": "",
"family": "2",
"fd": "3",
"pid": "21923",
"local_address": "",
"remote_port": "443",
"time": "1543840554",
"uptime": "28088276",
"remote_address": "54.193.126.242"
},
as you can see,the socket_events
row has the same pid with the process_events
row,but the cwd
,cmdline
,pepid
are all empty in socket_events
table. it it very strange. this Scenario has happened in all my 10 host.groob
groob
钢铁侠
12/09/2018, 6:45 AMsokcet_events.cpp
source code, I found that
// skip operations on NETLINK_ROUTE sockets
if (saddr[0] == '1' && saddr[1] == '0') {
continue;
}
why is the saddr with 10 the NETLINK_ROUTE sockets?I can not find some info about it,does anybody knows it?Saw Klaus
12/10/2018, 12:39 PMjackjack
12/11/2018, 2:14 AM--audit_allow_sockets
alessandrogario
fritz
12/12/2018, 3:34 PMgroob
Chris R.
12/13/2018, 9:09 PMShawnT
12/14/2018, 5:16 PMBrian Rak
12/14/2018, 8:56 PMalessandrogario
speckled
12/20/2018, 11:24 AMAnadi
12/20/2018, 11:59 AMjulient
12/20/2018, 12:45 PMpacketzero
12/20/2018, 6:54 PMalessandrogario
ccc
12/27/2018, 7:49 PMpacketzero
12/28/2018, 4:35 PMccc
12/28/2018, 8:24 PMdefensivedepth
01/02/2019, 6:21 PMDaveW
01/03/2019, 7:42 PMBen C
01/07/2019, 1:09 AMshed7
01/07/2019, 10:58 AMseph
osquery_schedule
table. https://blog.kolide.com/profiling-osquery-performance-with-kolide-cloud-8e01097469db has some info (and there are probably other blog posts about)alessandrogario
defensivedepth
01/07/2019, 7:21 PMseek3r
01/07/2019, 8:45 PM