namali
10/27/2022, 6:39 PMsharvil
10/27/2022, 6:50 PMnamali
10/27/2022, 6:54 PM"auto_table_construction": {
"chrome_history": {
"query":"SELECT datetime(last_visit_time/1000000-11644473600, \"unixepoch\") as last_visited, url, title, visit_count FROM urls",
"path":"C:\\Users\\%\\AppData\\Local\\Google\\Chrome\\User Data\\%\\History",
"columns":["last_visited","url","title","visit_count"]
}
}
}
sharvil
10/27/2022, 7:00 PM"Will not autoload extension with unsafe directory permissions: C:\Program Files\osquery\extensions/macadmins.exe"?
I don't think it would impact ATC thoughnamali
10/27/2022, 7:08 PMsharvil
10/27/2022, 7:12 PMnamali
10/27/2022, 7:17 PMsharvil
10/27/2022, 7:17 PMnamali
10/27/2022, 7:21 PMsharvil
10/27/2022, 7:26 PM--verbose
to osqueryi and paste the whole output, and also paste the conf file?namali
10/27/2022, 7:30 PM"auto_table_construction": {
"chrome_history": {
"query":"SELECT datetime(last_visit_time/1000000-11644473600, \"unixepoch\") as last_visited, url, title, visit_count FROM urls",
"path":"C:\\Users\\%\\AppData\\Local\\Google\\Chrome\\User Data\\%\\History",
"columns":["last_visited","url","title","visit_count"]
}
}
}
I1027 12:29:44.617239 3388 init.cpp:357] osquery initialized [version=5.2.2]
I1027 12:29:44.620157 3388 extensions.cpp:438] Found autoloadable extension: C:\Program Files\osquery\extensions/macadmins.exe
I1027 12:29:44.621152 3388 dispatcher.cpp:78] Adding new service: WatcherRunner (000001FEC25738A0) to thread: 3560 (000001FEC25999A0) in process 12556
I1027 12:29:44.625387 3388 dispatcher.cpp:78] Adding new service: ExtensionWatcher (000001FEC250E670) to thread: 11268 (000001FEC2599A80) in process 12556
I1027 12:29:44.625387 3388 dispatcher.cpp:78] Adding new service: ExtensionRunnerCore (000001FEC4419200) to thread: 6224 (000001FEC2599B80) in process 12556
I1027 12:29:44.626385 3388 auto_constructed_tables.cpp:99] Removing stale ATC entries
I1027 12:29:44.626385 6224 interface.cpp:299] Extension manager service starting: \\.\pipe\shell.em
Using a [1mvirtual database[0m. Need help, type '.help'
osquery> E1027 12:29:49.703593 3560 watcher.cpp:702] Cannot create extension process: C:\Program Files\osquery\extensions/macadmins.exe