Hello, just for testing purposes, from top of your head, is there some column in osquery tables that typically contains array rather than simple value?
JanRC
08/18/2023, 1:17 PM
Even dns_server_search_order in table interface_details is stored as text. Weird.
s
seph
08/18/2023, 6:02 PM
Almost none. Historically, I don’t think osquery did anything that fancy.
seph
08/18/2023, 6:02 PM
The only thing I can think of, is the very recent
windows_search
table which uses json objects for additional data.