slevchenko
11/09/2021, 10:56 AM/proc/<PID>/cmdline to /proc/<PID>/status for this to work we need to read cmdline and status content, is this even possible with osquery ? To clarify, by comparison I mean just ensuring that both of them contain same name keywordseph