Tyler Fisher
01/23/2020, 4:23 PMosquery> select name,value from osquery_flags where name = "extensions_socket";
+-------------------+-------------------------+
| name | value |
+-------------------+-------------------------+
| extensions_socket | /root/.osquery/shell.em |
+-------------------+-------------------------+
It looks like extensions are enabled:
osquery> select name, value from osquery_flags where name like '%ext%';
+----------------------------+------------------------------+
| name | value |
+----------------------------+------------------------------+
| disable_extensions | false |
| enable_extensions_watchdog | false |
| extension | |
| extensions_autoload | /etc/osquery/extensions.load |
| extensions_interval | 3 |
| extensions_require | |
| extensions_socket | /root/.osquery/shell.em |
| extensions_timeout | 3 |
+----------------------------+------------------------------+