Zweasta
06/19/2020, 11:29 PMreturn code 78
mean in osquery ?Jams
06/20/2020, 3:07 AMZweasta
06/20/2020, 3:13 AMprocess = subprocess.run(['osqueryi', '--json', 'select * from os_version'], stdout=subprocess.PIPE, stderr=subprocess.STDOUT, universal_newlines=True)
Zweasta
06/20/2020, 3:14 AMprint(process.stdout)
gives no output and when I checked the return code it says 78
Zweasta
06/20/2020, 3:15 AMJams
06/20/2020, 3:34 AMZweasta
06/20/2020, 3:49 AMZweasta
06/20/2020, 3:49 AMJams
06/20/2020, 4:29 AMosqueryd
with filesystem or tls logging.Jams
06/20/2020, 4:32 AMsubprocess.Popen(command, stdout=subprocess.PIPE, stderr=subprocess.PIPE, shell=use_shell, universal_newlines=True)
Zweasta
06/20/2020, 11:49 AM$osqueryi --json 'select * from os_version'
[
{"build":"","codename":"","major":"7","minor":"8","name":"CentOS Linux","patch":"2003","platform":"rhel","platform_like":"rhel","version":"CentOS Linux release 7.8.2003 (Core)"}
]
Zweasta
06/20/2020, 11:49 AM$echo $?
78
Zweasta
06/20/2020, 12:14 PM"]"
in the above output) it hangs for 2 seconds
and the osqueryi process ends. But, when I check the return code - It says 78seph
seph
touch no-exec
osqueryd --ephemeral --extension `pwd`/no-exec --allow-unsafe
seph
seph
seph
Zweasta
07/24/2020, 6:52 PM--config_plugin=filesystem --config_path=/dev/null
seph
Zweasta
07/24/2020, 7:11 PMseph
Zweasta
07/24/2020, 7:13 PMtheopolis
seph
theopolis
seph