Layne
03/13/2024, 7:36 PMFG
03/13/2024, 7:39 PMFG
03/13/2024, 7:40 PMLayne
03/13/2024, 7:41 PMFG
03/13/2024, 8:03 PMFG
03/13/2024, 8:30 PMSELECT count(*) AS count,
path,
CASE WHEN path LIKE '/Library/SystemExtensions/%/com.crowdstrike.falcon.Agent.systemextension/Contents/MacOS/com.crowdstrike.falcon.Agent'
THEN 'RUNNING'
ELSE 'ERROR'
END
status,
'macOSCrowdStrikeCheckProcess' AS query_type
FROM processes
WHERE path LIKE '/Library/SystemExtensions/%/com.crowdstrike.falcon.Agent.systemextension/Contents/MacOS/com.crowdstrike.falcon.Agent';
for windows it was similar:
SELECT services.*,
'WindowsCrowdStrikeCheckProcess' AS query_type
FROM services
WHERE name LIKE 'CSFalconService';
you could do the CASE and add a string as well.Dherder
03/14/2024, 4:28 PMFG
03/14/2024, 4:43 PMFG
03/14/2024, 4:44 PMLayne
03/14/2024, 5:46 PM