KK
07/20/2023, 6:54 AMuser_events table on MacOS? I've enabled the following tables but still am not getting anything:
--audit_allow_config
--audit_allow_user_events
--disable_audit=false
--disable_events=falsesharvil
07/20/2023, 8:39 AM--enable_keyboard_events=true and --enable_mouse_events=true , and osquery will also need relevant macOS permissionsKK
07/20/2023, 8:44 AMsharvil
07/20/2023, 8:47 AMKK
07/20/2023, 9:13 AMsharvil
07/20/2023, 9:43 AM/etc/security/audit_control filesharvil
07/20/2023, 9:44 AMaudit_user file, I don’t know the flags off the top of my head, but I think the man page should have an example for itsharvil
07/20/2023, 9:45 AMKK
07/20/2023, 9:47 AMsharvil
07/20/2023, 9:49 AM