Hey how to get dns-lookup events in Linux osquery and match it with process table.. Anyone tried before?
Prateek Kumar Nischal
10/28/2021, 11:05 AM
I haven’t specifically tried it, but you could get some starting point by using the socket events and then looking for dns queries, UDP maybe.. practically all DNS should end up in UDP but some huge ones could fallback to TCP..
or filter out all events with the destination with IPs in the resolv.conf