KK
07/20/2023, 6:54 AMuser_events
table on MacOS? I've enabled the following tables but still am not getting anything:
--audit_allow_config
--audit_allow_user_events
--disable_audit=false
--disable_events=false
sharvil
07/20/2023, 8:39 AM--enable_keyboard_events=true
and --enable_mouse_events=true
, and osquery will also need relevant macOS permissionsKK
07/20/2023, 8:44 AMsharvil
07/20/2023, 8:47 AMKK
07/20/2023, 9:13 AMsharvil
07/20/2023, 9:43 AM/etc/security/audit_control
filesharvil
07/20/2023, 9:44 AMaudit_user
file, I don’t know the flags off the top of my head, but I think the man
page should have an example for itsharvil
07/20/2023, 9:45 AMKK
07/20/2023, 9:47 AMsharvil
07/20/2023, 9:49 AM