Just wanted to bring this up again
Any feedback would be appreciated
Would it be possible to merge 1-2 (or All 😉 )
Of the PRs mentioned above before the next release or two?
Or if anyone has feedback that would be great
I think these features r pretty cool and I think others would like some of them as well🙃
Just bumping this up again
Just wondering if anyone has any feedback or comments for any of the 6 PRs opened above
I also think that code should generally be split in two parts, one doing the parsing into a structure and then the second part generating the rows based on pre-parsed data
12/01/2021, 2:09 PM
That's disappointing to hear 😢The raw registry table is probably the most important of the PRs I've opened
Mainly from an investigation perspective, its one of the 3 artifacts that r pretty much required in order to do a comprehensive investigationUal adding a WHERE clause makes sense it does return alot (maybe a WHERE clause for log level and/or timestamp?)I'm not sure if fsevents should require a WHERE clause?
If using osquery for investigations it needs to be able to pull back large amounts of data (full file listing, all event logs/UAL, all registry keys for all users
So from an investigation perspective u would want to pull back everythingIt would be great if all of the PRs could get merged
Especially raw registry parsingThere r many EDR tools available that can already parse jumplist/raw registry so it would be great if osquery can also do it to