Testing, you can get somewhere with `/usr/bin/dscl...
# general
s
Testing, you can get somewhere with
/usr/bin/dscl . -read /Users/root Password
but I don't think you can tell intentionally set from exploited. And that's not in osquery either