windows
  • a

    allister

    06/24/2022, 1:34 PM
    gotit, thank you all kindly!
  • zwass

    zwass

    06/24/2022, 4:38 PM
    Should that
    patch
    value be
    19044.1767
    ?
  • Mike Myers

    Mike Myers

    06/27/2022, 3:59 PM
    Opened https://github.com/osquery/osquery/issues/7657 about this field and maybe getting something more sensible in there
  • s

    seph

    06/27/2022, 4:33 PM
    Thank you mike
  • a

    allister

    06/28/2022, 5:23 AM
    (Now I have to admit cluelessness about where 21H2 might be found)
  • a

    allister

    06/28/2022, 5:37 AM
    I'm seeing a static table that does the conversion, but
  • a

    allister

    06/28/2022, 5:52 AM
    e.g. on win10 19044 means 21H2
  • a

    allister

    06/28/2022, 6:36 AM
    looks like @seph touched on this a while ago and was thinking along the same lines but while some ideas were tossed around it didn't turn a corner? https://github.com/osquery/osquery/issues/6082 I'll open a new issue
  • a

    allister

    06/28/2022, 6:44 AM
    silly me, that 'version' is also at the same registry path as "DisplayVersion"
  • a

    allister

    06/29/2022, 2:30 AM
  • CyberUnify

    CyberUnify

    07/11/2022, 8:34 AM
    Is it possible to extend osquery to check password policies configurations?
  • CyberUnify

    CyberUnify

    07/11/2022, 9:51 AM
    How to check if specific policy rules (e.g. CIS rules) are applied when there is no registry key mentioned for the check?
  • j

    jimmy

    07/13/2022, 4:08 PM
    im trying to build a new table to osquery, when i try to build my osquery table i get that error msg: C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\MSBuild\Microsoft\VC\v160\Microsoft.CppCommon.targets(241 ,5): warning MSB8064: Custom build for item "C:\osquery\build\CMakeFiles\9a254ea57f62bdae9b095277680f26d7\yara_process. cpp.rule" succeeded, but specified dependency "c:\osquery\specs\yara\yara_process" does not exist. This may cause incre mental build to work incorrectly. [C:\osquery\build\specs\codegen_native_tables.vcxproj] C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\MSBuild\Microsoft\VC\v160\Microsoft.CppCommon.targets(241 ,5): warning MSB8065: Custom build for item "C:\osquery\build\CMakeFiles\9a254ea57f62bdae9b095277680f26d7\yara_process. cpp.rule" succeeded, but specified output "c:\osquery\build\specs\native\yara_process.cpp" has not been created. This m ay cause incremental build to work incorrectly. [C:\osquery\build\specs\codegen_native_tables.vcxproj] C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\MSBuild\Microsoft\VC\v160\Microsoft.CppCommon.targets(241 ,5): warning MSB8064: Custom build for item "C:\osquery\build\CMakeFiles\b7853e62b244e8f5e1536b003bd6bfa3\amalgamated_n ative_tables.cpp.rule" succeeded, but specified dependency "c:\osquery\build\specs\native\yara_process.cpp" does not ex ist. This may cause incremental build to work incorrectly. [C:\osquery\build\specs\codegen_native_tables.vcxproj]
  • a

    abraham linkolan

    07/18/2022, 9:56 AM
    when I'm trying to build osquery I get this error msg "MSBUILD: error MSB1009: Project file does not exist. Switch: ALL_BUILD.vcxproj" do you know how to solve it?
  • j

    jimmy

    07/18/2022, 10:35 AM
    C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\MSBuild\Microsoft\VC\v160\Microsoft.CppCommon.targets(241,5): warning MSB8065: Custo m build for item "C:\osquery\build\CMakeFiles\35e1ce49a7900bded4c800fb28e9385a\osqueryi.exe.rule" succeeded, but specified output "c:\osquery\buil d\osquery\osqueryi.exe" has not been created. This may cause incremental build to work incorrectly. [C:\osquery\build\osquery\create_osqueryi.vcxp roj] I get that msg at yellow after I build osquery as one of the messages when i build osquery, is it ok?
  • i

    Ibra

    08/01/2022, 12:06 AM
    Hi, I've tried looking at the online guides but I can't figure out the steps to install osquery and generate the msi package, where to pass all the files in the screenshot, I saw that within the manage-osquery.ps1 file you can change the name of the service. currently on the company pc's osquery is installed under the path "C:\Program Files\osqueryd" where you see the attached files, I should install another agent that sends the data to another fleet server(that's why I want to change the system service name from osqueryd to something else, so that the 2 agents don't bother each other, what do you recommend to do? Thanks
  • j

    Julia Cox

    08/11/2022, 1:09 PM
    I just noticed that computer accounts (ending in
    $
    ) don't seem to have an SID in the uuid column in the osquery
    users
    table. Is that expected? The uid and username columns are still populated, and I thought they did have SIDs 🤔
  • s

    Slackbot

    08/11/2022, 6:06 PM
    This message was deleted.
  • a

    Andrea

    08/19/2022, 11:03 AM
    Hi everyone, does anyone get the same error trying to fetch aws submodules on windows:
    Submodule path 'libraries/cmake/source/aws-sdk-cpp/src/aws-sdk-cpp/crt/aws-crt-cpp/crt/aws-c-common': checked out 'c258a154bb89db73eff60a467a0750ee5435ebc6'
    fatal: failed to read object b652295078e26f8444c72ee3088f6a1230624827: Filename too long
    I have few of these error. Ofc long paths are set (also on git) any help to fix this is appreciated!
  • Aman Kumar Chagti

    Aman Kumar Chagti

    08/22/2022, 9:45 AM
    how can i update osquery from powershell?
  • Mike Myers

    Mike Myers

    08/22/2022, 4:19 PM
    Perhaps you could use the powershell scripts in the deployment tools directory https://github.com/osquery/osquery/tree/master/tools/deployment/windows_packaging
  • s

    seph

    08/22/2022, 7:06 PM
    osquery does not have an update mechanism. So it depends a lot on how you’ve distributed it. I imagine you could install the msi, but I don’t know
  • Aman Kumar Chagti

    Aman Kumar Chagti

    08/23/2022, 3:22 AM
    yes i installed it using msi file
  • Mike Myers

    Mike Myers

    08/23/2022, 5:08 PM
    In my limited experience building and testing the installer locally, reinstalling osquery with a newer MSI has just worked, but I have not managed a large deployment
  • s

    Slackbot

    08/29/2022, 7:00 PM
    This message was deleted.
  • a

    allister

    09/01/2022, 2:44 PM
    Anybody know the answer to this one? https://twitter.com/Vlad_P53/status/1565308240472186882
  • zwass

    zwass

    10/06/2022, 9:59 PM
    Hey @thor (and anyone else), @Marcos Oviedo is starting on some work to bring ETW events to osquery (hello
    etw_process_events
    table!) and we could use some code review from folks with Windows experience. Any chance you have some time to do a bit of review as he pushes PRs starting in the next couple of weeks?
  • defensivedepth

    defensivedepth

    11/23/2022, 3:01 PM
    Im seeing duplicate data in the
    shimcache
    table - is this expected?
  • defensivedepth

    defensivedepth

    11/29/2022, 6:42 PM
    In relation to ETW events, recent windows process PR. Does ETW have any concept of filtering? Is there any possibility of defining a capture filter ie
    exclude processes that look like svchost.exe -k
    @Marcos Oviedo et al.