Title
#windows
v

Vijay

05/18/2020, 9:48 PM
is there an extension for osquery that includes forensics capabilities? for eg, a table that shows appcompat results?
zwass

zwass

05/18/2020, 9:51 PM
Polylogyx was making some osquery windows extensions with additional capabilities. Sorry I can't give you more details.
v

Vijay

05/18/2020, 9:52 PM
thanks.
o

OpenPlgx

05/19/2020, 9:02 AM
Thanks @zwass. @Vijay, please feel welcome to look at some of the example scripts at https://github.com/polylogyx/plgx-esp-sdk/tree/master/example_scripts/advance_scripts You will find one for appcompat cache parsing too... feel welcome to move the PolyLogyx related discussion to #polylogyx-extension channel.
Mike Myers

Mike Myers

05/22/2020, 6:38 PM
@Vijay we also wrote an NTFS metadata table extension https://github.com/trailofbits/osquery-extensions/tree/master/ntfs_forensics
v

Vijay

05/22/2020, 6:40 PM
is there a release version of it?
Mike Myers

Mike Myers

05/22/2020, 6:41 PM
There hasn't been a recent binary tagged as a release, no, but it should build from source
v

Vijay

05/22/2020, 6:41 PM
great. thanks