allister
05/27/2022, 4:46 PMSELECT CASE
WHEN
(SELECT count(*)
FROM plist
WHERE path = "/Library/Application Support/com.apple.TCC/MDMOverrides.plist") > 0 THEN
(SELECT value
FROM plist
WHERE path = "/Library/Application Support/com.apple.TCC/MDMOverrides.plist"
AND KEY = "com.crowdstrike.falcon.Agent"
AND subkey = "kTCCServiceSystemPolicyAllFiles/Allowed")
ELSE "couldn't read"
END cs_fda_status;
1 means enabled, 0 disabled, NO RESULT means profile/matching key not present, "couldn't read" means no FDA for osqueryd itselfseph
05/27/2022, 8:13 PM