Brandon
03/25/2021, 12:15 AMCptOfEvilMinions
03/25/2021, 2:38 PMdns_lookup_events
.
I think that table is only available on Uptyc’s Osquery agent only, I don’t see that table listed on the open source version of Osquery: https://osquery.io/schema/4.7.0/
However, if your on a Windows platform you can enumerate the DNS cache with the dns_cache
table.Mike Myers
03/25/2021, 4:06 PMBrandon
03/25/2021, 4:42 PMterracatta
03/25/2021, 6:54 PMBrandon
03/25/2021, 11:04 PMWS
03/26/2021, 12:13 AMdns_lookup_events
and http_event
built into native osquery. in a remote world w/ covid, having that data come from the endpoint and not tied to a specific office or physical location, is huge.Brandon
03/26/2021, 1:34 PMOpenPlgx
03/31/2021, 11:43 AM