Hey all, not sure if this is possible but figured ...
# sql
j
Hey all, not sure if this is possible but figured this was a good place to ask.. Looking to create a query to view the contents of a .zip file that has no password.. anyone heard of something like this? ๐Ÿ™‚
I'm not sure if this is feasible with OSQuery or SQL, but I figured it was worth asking in case someone way more intelligent than I knows of something! :)
s
I donโ€™t think Iโ€™ve seen one. I could imagine writing one ๐Ÿคท
j
I am not highly skilled or confident in my writing abilities for OSQuery that's for sure. lol ๐Ÿ˜…
b
would need a lot of work as I just pulled on the common metadata from from files within an archive but based on this idea I quickly hacked something up https://github.com/burdzwastaken/osquery-zip-table/ output: https://gist.github.com/burdzwastaken/bfde5a1ae9008977067cd451f88211cc might spend some more time on it this weekend polishing it off a tad more
๐Ÿ™Œ๐Ÿพ 1
๐Ÿ™Œ 1