Title
#general
s

slevchenko

11/09/2021, 10:56 AM
Hi all! I'm trying to compare
/proc/<PID>/cmdline
to
/proc/<PID>/status
for this to work we need to read cmdline and status content, is this even possible with osquery ? To clarify, by comparison I mean just ensuring that both of them contain same
name
keyword
s

seph

11/09/2021, 9:08 PM
By design, osquery generally does not have simple file read abilities. You could review the process table to see if it does what you need. Or try for creative things with the audit subsystem. Or write a table