Does Windows version of OSquery support Socket_events and Process_events tables? From my understanding it does not...
From Linux :
"platform": "linux",
"schedule": { "process_events":{
"query": "SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events ;",
"interval": 10, "description": "Process events collected from the audit framework" },
"socket_events":{ "query": "SELECT action, auid, family, local_address, local_port, path, pid, remote_address, remote_port, success, time FROM socket_events WHERE remote_address NOT IN ('127.0.0.1', "interval": 10, "description": "Socket events collected from the audit framework" },
-- I am trying to figure out windows equivalent of these queries