Jeff Singleton
04/07/2020, 3:13 PMalessandrogario
Jeff Singleton
04/07/2020, 3:24 PMJeff Singleton
04/07/2020, 3:26 PMalessandrogario
alessandrogario
alessandrogario
Jeff Singleton
04/07/2020, 3:28 PMalessandrogario
Jeff Singleton
04/07/2020, 3:34 PMalessandrogario
alessandrogario
Jeff Singleton
04/07/2020, 3:35 PMJeff Singleton
04/07/2020, 3:36 PMalessandrogario
alessandrogario
alessandrogario
Jeff Singleton
04/07/2020, 3:38 PMJeff Singleton
04/07/2020, 3:39 PMalessandrogario
alessandrogario
alessandrogario
alessandrogario
Jeff Singleton
04/07/2020, 3:41 PMalessandrogario
Jeff Singleton
04/07/2020, 3:42 PMalessandrogario
Jeff Singleton
04/07/2020, 3:43 PMalessandrogario
alessandrogario
alessandrogario
/etc/osquery/osquery.flags.default
)Jeff Singleton
04/07/2020, 3:47 PMalessandrogario
alessandrogario
Jeff Singleton
04/07/2020, 3:49 PMalessandrogario
osqueryi --flagfile /etc/osquery/osquery.flag
you should in theory be able to query user_events and process_eventsalessandrogario
Jeff Singleton
04/07/2020, 3:55 PMJeff Singleton
04/07/2020, 3:56 PMalessandrogario
Jeff Singleton
04/07/2020, 3:57 PM