Title
#macos
Mystery Incorporated

Mystery Incorporated

05/17/2022, 9:08 AM
Hey there osqueryd is listed as a conflicting app by Microsoft Defender for Endpoint
s

sharvil

05/17/2022, 9:12 AM
Probably because Microsoft Defender on macOS itself embeds osquery..
Mystery Incorporated

Mystery Incorporated

05/17/2022, 9:12 AM
Oh rly?
s

sharvil

05/17/2022, 9:12 AM
Yes! It's not widely known, but they do
Mystery Incorporated

Mystery Incorporated

05/17/2022, 9:12 AM
what's my options in this case?
s

sharvil

05/17/2022, 9:12 AM
Look at their .app package structure
9:13 AM
what's my options in this case?
Also not sure why microsoft would do this -- not sure off the top of my head
Mystery Incorporated

Mystery Incorporated

05/17/2022, 9:13 AM
I assume I can't configure their copy to talk to fleet
s

sharvil

05/17/2022, 9:14 AM
worth a try lol, do report back -- I don't have a copy of Microsoft Defender for mac anymore
Mystery Incorporated

Mystery Incorporated

05/17/2022, 9:15 AM
ok i'll have a look
9:35 AM
@sharvil hmm not seeing it unless they rename it?
s

sharvil

05/17/2022, 9:40 AM
I am not sure about now, but they definitely did embed it a while back
m

marnin

05/17/2022, 12:44 PM
I see
Microsoft\ <http://Defender.app/Contents/MacOS/wdavdaemon_enterprise.app/Contents/Frameworks/osqueryi|Defender.app/Contents/MacOS/wdavdaemon_enterprise.app/Contents/Frameworks/osqueryi>
s

sharvil

05/17/2022, 1:33 PM
Yep, I confirmed it's there