Adrian Junge11/23/2022, 2:10 PM
mikermcneil11/23/2022, 5:06 PM
and then join against it. The table could just be a static list. That would let you manage it via osquery extension in code and use Fleet to deploy the latest extension whenever you make changes.
That said, it's probably easier just to hard-code them into the query, and invest in making the format nice and some SQL comments.
Guillaume11/23/2022, 5:07 PM
mikermcneil11/23/2022, 5:08 PM
Yeah and keep in mind creating tables on osquery will work but they will not exist when osqueryd next restarts,Unless you create a custom osquery extension and add tables that way.
Adrian Junge11/24/2022, 8:57 AM