Join Slack
Channels
general
android_tests
apple-silicon
arm-architecture
auditing-warroom
awallaby
aws
beyond-identity
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
golang
goquery
help-proxy
infrastructure
jobs
kolide
linen-dev
linux
loonsecio
macos
officehours
osctrl
plugins
process-auditing
qingteng
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Is there any way osquery can show the origin of...
# macos
m
MaxosxOsquery
08/23/2020, 4:45 AM
Is there any way osquery can show the origin of file downloaded on Macosx.. Something from lsquarantine dB and browser artifacts or any curl, wget utility tools that was used from a adware/malware script. I'm asking from DFIR perspective..
Open in Slack
Previous
Next