Facing this issue while running the tailsofbits OSQuery extension in MAC
E0408 18:26:08.503185 189222912 registry_factory.cpp:179] table registry HostDenylist plugin caused exception: Failed to create the firewall object
Error: Failed to create the firewall object
The code snapshot of trailsofbuts fwctl code
IFirewall& GetFirewall() {
static bool conf_dir_init_status = InitializeConfigurationFolder();
if (!conf_dir_init_status) {
throw std::runtime_error(
"Failed to initialize the firewall configuration folder");
}
static std::unique_ptr<IFirewall> firewall;
static IFirewall::Status firewall_init_status =
trailofbits::CreateFirewallObject(firewall);
if (!firewall_init_status.success()) {
throw std::runtime_error("Failed to create the firewall object");
}
return *firewall.get();
}
m
Mike Myers
04/09/2021, 7:00 PM
Are you running osquery as root?
n
Nerd
04/10/2021, 6:42 AM
Yes @Mike Myers, running in following manner
sudo ./osqueryi --allow_unsafe --extensions_default_index=false --disable_extensions=false --extension ../external/extension_trailofbits/trailofbits_osquery_extensions.ext