Zachary Case

02/02/2022, 8:19 PM
👋 hey folks, I saw this video https://asciinema.org/a/302647 on
table in osquery and I think I remember it being mentioned before in an office hours call, is this something that is/will be added to osquery?


02/02/2022, 10:54 PM
Hey Zachary! I ended up not implementing it since it requires a uprobe to trace glibc
10:56 PM
So the major problem there is that if you run a binary that does not use the glibc installed on the system, or has a statically linked glibc
10:56 PM
You won't be able to capture it because it will not trigger the uprobe
10:56 PM
A dns resolution could also happen with a direct query via socket