Santosh Shiv
12/08/2021, 6:34 PMTomas Mendia
12/13/2021, 8:07 PMfritz
12/14/2021, 2:50 PMgsettings
, but there is nothing to guarantee that this same device would not use something like swaylock
instead. In order to reliably ascertain the configuration of screenlock in a reasonably diverse Linux ecosystem, an organization would need to decide on a set of acceptable pathways to configuring a screenlock policy on Linux devices, and then you would check for those specific items.fritz
12/14/2021, 3:00 PMAdham Abu Dari
12/16/2021, 5:19 PMeBPF
on our osquery installation and we hit some weird extreme performance impact reaches 100% cpu usage. Has anyone experienced this behavior? What was the workaround?Piyush Anand
12/17/2021, 4:30 AMAP
12/17/2021, 7:37 AMrinknel
12/21/2021, 4:49 AMHello_There
12/22/2021, 6:16 PMJavier
12/22/2021, 7:26 PMMayur Shingote
12/24/2021, 10:43 PMRelWithDebInfo
and Debug
?seph
AP
12/27/2021, 6:25 PMslevchenko
12/28/2021, 8:57 AMDoron Gaznavi
12/28/2021, 2:47 PMGiovanni Giannola
12/30/2021, 9:01 PMAllen
01/03/2022, 10:33 PMJohn S
01/04/2022, 5:53 PMryan
01/04/2022, 8:52 PMosquery> select * from chrome_extension;
Error: no such table: chrome_extension
cssmason
01/07/2022, 9:10 AMslevchenko
01/08/2022, 5:16 PMpath
field, this field is kinda reserved or something, so ATC table can't contain such field in any form not path
nor Path
or PATH
. If custom ATC table contains path
osqueryd returns:
E0108 18:52:27.938575 33708 virtual_table.cpp:584] Error creating virtual table: trusted_binaries (1): SQLITE_ERROR
Ben Haham Hay
01/13/2022, 10:25 AMcssmason
01/13/2022, 4:19 PMStefano Bonicatti
01/14/2022, 11:16 PMsyscall
column too.
So sometimes it's because we haven't seen the needed syscalls to have all the data, otherwise it could also be an issue that has been improved in osquery 5.1.0 if you're not already using that.
Finally it could just be a bug, but one would need to see the code in action.Dulal
01/16/2022, 6:40 AMDulal
01/19/2022, 11:14 AMDhruv Rathod
01/21/2022, 6:28 AMVinu Tom
01/21/2022, 3:31 PMFederico Talentino
01/22/2022, 5:29 PMdram
01/23/2022, 3:56 PM