nyanshak
08/10/2020, 10:40 PMprocess_envs
table and Windows uses default_environment
(as far as I can tell).SELECT COALESCE(
(SELECT value from process_envs where key = 'OSQUERY_ENV'),
(SELECT variable from default_environment where key = 'OSQUERY_ENV'),
null
) AS env where env != '';
default_environment
and Windows can't run queries against process_envs
table{
"decorators": {
"load": [
"SELECT value as env from process_envs where key = 'OSQUERY_ENV';",
"SELECT variable as env from default_environment where key = 'OSQUERY_ENV';"
]
}
}