zwass
nNipsx
06/12/2018, 1:34 PMnNipsx
06/12/2018, 1:34 PMnNipsx
06/12/2018, 1:34 PMzwass
nNipsx
06/12/2018, 1:37 PMnNipsx
06/12/2018, 1:37 PMnNipsx
06/12/2018, 1:37 PMzwass
nNipsx
06/12/2018, 1:38 PMnNipsx
06/12/2018, 1:39 PMnNipsx
06/12/2018, 1:39 PMzwass
nNipsx
06/12/2018, 1:39 PMnNipsx
06/12/2018, 1:39 PMzwass
nNipsx
06/12/2018, 1:40 PMnNipsx
06/12/2018, 1:40 PMzwass
nNipsx
06/12/2018, 1:40 PMzwass
nNipsx
06/12/2018, 1:42 PMnNipsx
06/12/2018, 2:45 PMzwass
/tmp/osquery_result
on the Fleet server by defaultzwass
--osquery_result_log_file
nNipsx
06/12/2018, 2:48 PMnNipsx
06/12/2018, 2:48 PMzwass
select * from time
with an interval of 30 seconds. Make sure the pack actually targets some hostsnNipsx
06/12/2018, 2:55 PMzwass
nNipsx
06/12/2018, 6:18 PMnNipsx
06/12/2018, 6:18 PMnNipsx
06/12/2018, 6:18 PMnNipsx
06/12/2018, 6:24 PMnNipsx
06/12/2018, 6:24 PMnNipsx
06/12/2018, 6:25 PMnNipsx
06/13/2018, 3:50 PM