04/17/2019, 8:06 PM
Hiya! I’m testing Trail of Bits Google 🎅🏻 extension: https://github.com/osql/extensions/tree/master/santa. I’m trying to write a simple query that just pulls the results of the santa_denied table that the extension adds (
select * from santa_denied
). Is there a way to add a query pack locally to a client even though it receives packs and configs via Kolide?


04/18/2019, 6:14 PM
santa should already have a local database that has the rules stored.
6:14 PM
if you want to see the blocked events based on run, the log also exists on the endpoint already
6:15 PM
you are more than welcome to PM me for more info or post in #extensions