Hmmm osqueryd.exe keeps reporting itself as a no d...
# general
m
Hmmm osqueryd.exe keeps reporting itself as a no disk executable \Device\HarddiskVolume2\Program Files\osquery\osqueryd\osqueryd.exe
m
what is the query that reports that? Maybe there's a bug
m
I was using the example query for no disk binary on the osquery website but what the issue turned out to be is somehow I ended up with both 4.9 and 5.0.1 on the 1 machine?
m
oh, it's possible that 4.9 has to be stopped and removed before reinstalling
there were some install path changes
Ah yes https://www.trailofbits.com/post/announcing-osquery-5-now-with-endpointsecurity-on-macos we made a little note about this in our blog post in the section
Migrating from osquery 4.x to 5.x