Join Slack
Powered by
hi all Is there any way to monitor the use of a dl...
# general
h
Hello_There
04/12/2021, 1:24 PM
hi all Is there any way to monitor the use of a dll or the execution of a dll? I am looking to monitor the use or execution of "wininet.dll"
✅ 1
m
Mike Myers
04/12/2021, 4:48 PM
Hi. No, currently osquery doesn't have a table that audits DLL load events
h
Hello_There
04/12/2021, 5:44 PM
glad you for the feedback
w
Will Teller
04/13/2021, 10:40 AM
As Sysmon (ID 7) can log image loads, including DLLs (though can be resource intensive apparently), could not osquery pull-in such event logs?
m
Mike Myers
04/13/2021, 3:45 PM
You could use osquery as a log forwarder? Like with
windows_eventlog
table maybe?
3
Views
Open in Slack
Previous
Next