Adrian Junge
11/23/2022, 2:10 PMmikermcneil
11/23/2022, 5:06 PM1und1_allowed_processes
and then join against it. The table could just be a static list. That would let you manage it via osquery extension in code and use Fleet to deploy the latest extension whenever you make changes.
That said, it's probably easier just to hard-code them into the query, and invest in making the format nice and some SQL comments.Guillaume
11/23/2022, 5:07 PMmikermcneil
11/23/2022, 5:08 PMYeah and keep in mind creating tables on osquery will work but they will not exist when osqueryd next restarts,Unless you create a custom osquery extension and add tables that way.
Adrian Junge
11/24/2022, 8:57 AM