zwass
_events
tables will be collecting events as long as osqueryd
is running, and then when you query them you will get all the events since the last query was executed.Mustafa
08/09/2018, 6:01 PMzwass
usb_events
table? I can only find usb_devices
which is not event based. There is also hardware_events
which is event based.Mustafa
08/09/2018, 6:04 PMzwass
usb_devices
gives you the state when the query is runhardware_events
will catch all events