Is osquery able to detect what files/folders in a system are accessed including just a READ?
I would like to find out the entire set of files/folders or other assets accessed without knowing the list beforehand. Most other monitor tools you have to know what you want to monitor first. Anyone with example will be appreciated.
03/15/2021, 11:00 PM
the answer might depend on which OS you're running
03/15/2021, 11:03 PM
linux. I am new to osquery. I am doing an research on the tool for profiling application running on linux (what resources an running application is actually accessing/changing in a linux system, we can just assume redhat enterprise or any type of linux for an example).
03/15/2021, 11:17 PM
Ok, I think Linux has two subsystems that osquery can use for file event monitoring: iNotify (