Title
#windows
z

Zweasta

06/04/2020, 8:07 PM
Just like using "iptables" table to find the open ports and firewall rules for linux, is there a way to find out firewall rules and open ports for windows using osquery?
sundsta

sundsta

06/04/2020, 8:20 PM
Not easily at the moment. You’d have to parse the registry keys
z

Zweasta

06/04/2020, 8:24 PM
Can you give some screenshots of how to do that ?
sundsta

sundsta

06/04/2020, 8:43 PM
Docs are here for pulling info from the Windows registry: https://osquery.io/schema/4.3.0#registry
z

Zweasta

06/04/2020, 8:49 PM
Thanks