aldente
03/07/2024, 10:08 PMselect * from file where path like '/Users/%/Desktop/%'
) via the fleet UI and looking for some guidance. i’ve followed the osquery docs to silently push out FDA access with our MDM (JAMF)aldente
03/07/2024, 10:10 PM〰 ~ 🌷 ps aux | grep osquery
root 59875 0.6 0.2 409986736 41904 ?? SN 3:22PM 0:39.19 /opt/osquery/lib/osquery.app/Contents/MacOS/osqueryd
root 59874 0.0 0.1 409227552 13088 ?? SNs 3:22PM 0:01.11 /opt/osquery/lib/osquery.app/Contents/MacOS/osqueryd --flagfile=/private/var/osquery/osquery.flags
aldente
03/07/2024, 10:10 PMsudo osqueryi
, just not in fleetaldente
03/07/2024, 10:11 PMBrock Walters
03/08/2024, 2:47 AMaldente
03/11/2024, 6:51 PMDherder
03/12/2024, 3:26 PMDherder
03/12/2024, 3:26 PMaldente
03/12/2024, 3:33 PMDherder
03/12/2024, 4:02 PMaldente
03/12/2024, 4:12 PMio.osquery.agent
did not enable me to query protected tables via Fleet with our current config 😕Dherder
03/12/2024, 4:49 PMio.osquery.agent
as the bundle id?aldente
03/12/2024, 5:37 PM> codesign -dr - /opt/osquery/lib/osquery.app/Contents/MacOS/osqueryd
Executable=/opt/osquery/lib/osquery.app/Contents/MacOS/osqueryd
Executable=/opt/osquery/lib/osquery.app/Contents/MacOS/osqueryd
designated => identifier "io.osquery.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "3522FA9PXF"