https://github.com/osquery/osquery logo
s

Stefano Bonicatti

07/20/2022, 1:27 PM
I would say that that kind of query either you use the
processes
table to match against (but then the process might not be running anymore), or you create 2 separate queries, where each feeds results to a backend, and the query is done in the backend