Luis Gomez
05/26/2021, 7:15 AMosquery_schedule
have a last_executed = 0
? I have enabled the osx-attack pack but no queries seem to be running, I left the default Intervals and I'm using filesystem logging. If this is not the right place to ask this let me know where thanks! :)Luis Gomez
05/26/2021, 7:16 AMallister
05/26/2021, 8:44 AMallister
05/26/2021, 8:44 AMLuis Gomez
05/26/2021, 8:50 AMLuis Gomez
05/26/2021, 8:50 AMLuis Gomez
05/26/2021, 8:51 AM➜ ~ sudo osqueryctl status
com.facebook.osqueryd is running. pid: 10799
allister
05/26/2021, 8:52 AMallister
05/26/2021, 8:54 AMallister
05/26/2021, 8:55 AMallister
05/26/2021, 8:56 AMLuis Gomez
05/26/2021, 8:57 AMosquery_schedule
tableLuis Gomez
05/26/2021, 8:58 AMlast_executed = 0
?Luis Gomez
05/26/2021, 8:58 AMosqueryd.results.log
which is fineLuis Gomez
05/26/2021, 8:58 AMLuis Gomez
05/26/2021, 8:58 AMLuis Gomez
05/26/2021, 8:59 AMLuis Gomez
05/26/2021, 8:59 AMLuis Gomez
05/26/2021, 8:59 AMallister
05/26/2021, 9:00 AMLuis Gomez
05/26/2021, 9:00 AMLuis Gomez
05/26/2021, 9:00 AMallister
05/26/2021, 9:01 AMLuis Gomez
05/26/2021, 9:04 AMlast_executed
column in the osquery_schedule
was doing that but not sure anymoreLuis Gomez
05/26/2021, 9:05 AMLuis Gomez
05/26/2021, 9:05 AMLuis Gomez
05/26/2021, 9:05 AMallister
05/26/2021, 9:49 AMallister
05/26/2021, 9:49 AMLuis Gomez
05/26/2021, 10:11 AMzwass
osquery_schedule
in osqueryi
?Luis Gomez
05/26/2021, 4:02 PMLuis Gomez
05/26/2021, 4:03 PMSELECT * from osquery_schedule WHERE last_executed > 0 ;
running this query in osqueryi
gives nothingLuis Gomez
05/26/2021, 4:06 PMLuis Gomez
05/26/2021, 4:08 PMLuis Gomez
05/26/2021, 4:08 PMzwass
zwass
zwass
Luis Gomez
05/26/2021, 4:32 PMLuis Gomez
05/26/2021, 4:32 PMzwass
osquery_schedule
table, but that new .connect
command is a good option for ad-hoc analysis)Luis Gomez
05/26/2021, 4:44 PM