yep, i understand osquery is used on lots of devices and the stuff u said are good points to consider
but as mentioned i think this kind of table would be utilized for specific threat hunting or IR purposes
if a user laptop gets an alert for mimikatz or an analyst identifies an attacker that used mac systemA to logon to mac systemB
those systems could be considered compromised and i think an organization would like to be able to investigate the system and pulling a file listing would be useful (along with lots of other data)
but i understand and agree that osquery should still not thrash the system while the investigation is happening
An extension is an interesting idea, but that would requiring the organization to deploy and making sure the extension is running on all systems.
In addition, if an organization is using the extension investigate malicious activity or an active attacker trying to deploy ransomware or steal data and the watchdog proactively kills it. I think that adds some additional challenges and the organization may just disable to the watchdog. Which if they do wouldn't then just make sense to include in core?
Again I think this would be valuable in core as it would make osquery more useful for full IR investigations (vs triages). For full investigations a full file listing, all event logs, and all registry keys are needed at a minimum in order to do any kind of full and thorough investigations. Along with additional data depending on the os.
There are several similar tools out there that are similar osquery that can collect full file listings
Im not saying the way I thought of is the only way to do it, and the insert table idea is cool and interesting. I just think coming up with a way to get in core would be really great.
But if there is really no way this feature would get included into core, I will accept that 🙂
No worries👍