etsang
03/30/2021, 7:58 PMnyanshak
03/31/2021, 2:57 PM/home/app
?"
The process_open_files
table isn't a great way to answer this question as it only shows currently-open files.
Based on what I think you're trying to do, you're probably looking for FIM ("file integrity monitoring"): https://osquery.readthedocs.io/en/stable/deployment/file-integrity-monitoring/