Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#general
Title
# general
z
Zachary Case
02/02/2022, 8:19 PM
👋 hey folks, I saw this video
https://asciinema.org/a/302647
on
process_dns_events
table in osquery and I think I remember it being mentioned before in an office hours call, is this something that is/will be added to osquery?
a
alessandrogario
02/02/2022, 10:54 PM
Hey Zachary! I ended up not implementing it since it requires a uprobe to trace glibc
So the major problem there is that if you run a binary that does not use the glibc installed on the system, or has a statically linked glibc
You won't be able to capture it because it will not trigger the uprobe
A dns resolution could also happen with a direct query via socket
7 Views
Post