Jeff Singleton
04/07/2020, 3:13 PMalessandrogario
04/07/2020, 3:19 PMJeff Singleton
04/07/2020, 3:24 PMalessandrogario
04/07/2020, 3:27 PMJeff Singleton
04/07/2020, 3:28 PMalessandrogario
04/07/2020, 3:29 PMJeff Singleton
04/07/2020, 3:34 PMalessandrogario
04/07/2020, 3:35 PMJeff Singleton
04/07/2020, 3:35 PMalessandrogario
04/07/2020, 3:36 PMJeff Singleton
04/07/2020, 3:38 PMalessandrogario
04/07/2020, 3:39 PMJeff Singleton
04/07/2020, 3:41 PMalessandrogario
04/07/2020, 3:42 PMJeff Singleton
04/07/2020, 3:42 PMalessandrogario
04/07/2020, 3:42 PMJeff Singleton
04/07/2020, 3:43 PMalessandrogario
04/07/2020, 3:43 PM/etc/osquery/osquery.flags.default
)Jeff Singleton
04/07/2020, 3:47 PMalessandrogario
04/07/2020, 3:47 PMJeff Singleton
04/07/2020, 3:49 PMalessandrogario
04/07/2020, 3:49 PMosqueryi --flagfile /etc/osquery/osquery.flag
you should in theory be able to query user_events and process_eventsJeff Singleton
04/07/2020, 3:55 PMalessandrogario
04/07/2020, 3:56 PMJeff Singleton
04/07/2020, 3:57 PM