Hi đź‘‹ In new MacOS Big Sur version kernel extension (kext) functionality will be partially replaced by systems extensions. Is it going to affect osquery or not?
g
Gavin
11/20/2020, 1:09 PM
It depends , Osquery is Kextless on later versions if you’re up to date you should have no issues on BS , If you’re running an older version or forked version you may have issues best to test in your environment and inspect loaded kexts / install versions etc.
m
Macear
11/20/2020, 1:11 PM
@Gavin ok, thanks for your prompt reply
g
Gavin
11/20/2020, 1:14 PM
This PR may also be of relevance for enhanced Security information in osquery using native EndpointSecurity APIs aka System Extensions
https://github.com/osquery/osquery/pull/6467