Yassine CHAOUCHE
07/20/2022, 12:59 PMYassine CHAOUCHE
07/20/2022, 1:01 PMYassine CHAOUCHE
07/20/2022, 1:02 PMI0720 14:00:55.600761 25136 auditdnetlink.cpp:648] Failed to set the netlink owner
until I quit osqueryiStefano Bonicatti
07/20/2022, 1:02 PMStefano Bonicatti
07/20/2022, 1:03 PMStefano Bonicatti
07/20/2022, 1:03 PMYassine CHAOUCHE
07/20/2022, 1:03 PMYassine CHAOUCHE
07/20/2022, 1:04 PMYassine CHAOUCHE
07/20/2022, 1:04 PMStefano Bonicatti
07/20/2022, 1:04 PMYassine CHAOUCHE
07/20/2022, 1:05 PMYassine CHAOUCHE
07/20/2022, 1:06 PMYassine CHAOUCHE
07/20/2022, 1:06 PMMalformed syscall event. The saddr field in the AUDIT_SOCKADDR record could not be parsed: "00000000000000000000000000000000"
Yassine CHAOUCHE
07/20/2022, 1:06 PMStefano Bonicatti
07/20/2022, 1:10 PMYassine CHAOUCHE
07/20/2022, 1:12 PMYassine CHAOUCHE
07/20/2022, 1:12 PMYassine CHAOUCHE
07/20/2022, 1:12 PMYassine CHAOUCHE
07/20/2022, 1:13 PMYassine CHAOUCHE
07/20/2022, 1:13 PMYassine CHAOUCHE
07/20/2022, 1:14 PMStefano Bonicatti
07/20/2022, 1:14 PMaudit_allow_process_events
Yassine CHAOUCHE
07/20/2022, 1:15 PMYassine CHAOUCHE
07/20/2022, 1:16 PMStefano Bonicatti
07/20/2022, 1:16 PMYassine CHAOUCHE
07/20/2022, 1:16 PM$ sudo osqueryi --disable_audit=false --audit_allow_config=true --events_max=50000 --audit_allow_sockets --disable_events=false
Using a virtual database. Need help, type '.help'
osquery> select action, process_events.path, cmdline, socket_events.status, remote_address, remote_port, datetime(socket_events.time,'unixepoch') from socket_events join process_events on socket_events.pid = process_events.pid;
osquery> select action, process_events.path, cmdline, socket_events.status, remote_address, remote_port, datetime(socket_events.time,'unixepoch') from socket_events join process_events on socket_events.pid = process_events.pid;
+---------+---------------+-----------------+-------------+-----------------+-------------+------------------------------------------+
| action | path | cmdline | status | remote_address | remote_port | datetime(socket_events.time,'unixepoch') |
+---------+---------------+-----------------+-------------+-----------------+-------------+------------------------------------------+
| connect | /usr/bin/curl | curl <http://google.com|google.com> | in_progress | 142.250.200.238 | 80 | 2022-07-20 12:59:12 |
+---------+---------------+-----------------+-------------+-----------------+-------------+------------------------------------------+
osquery>
$
Stefano Bonicatti
07/20/2022, 1:18 PM--events_optimize=false
?Yassine CHAOUCHE
07/20/2022, 1:23 PMYassine CHAOUCHE
07/20/2022, 1:23 PMYassine CHAOUCHE
07/20/2022, 1:23 PM