is there an extension for osquery that includes fo...
# windows
v
is there an extension for osquery that includes forensics capabilities? for eg, a table that shows appcompat results?
z
Polylogyx was making some osquery windows extensions with additional capabilities. Sorry I can't give you more details.
v
thanks.
o
Thanks @zwass. @Vijay, please feel welcome to look at some of the example scripts at https://github.com/polylogyx/plgx-esp-sdk/tree/master/example_scripts/advance_scripts You will find one for appcompat cache parsing too... feel welcome to move the PolyLogyx related discussion to #polylogyx-extension channel.
m
@Vijay we also wrote an NTFS metadata table extension https://github.com/trailofbits/osquery-extensions/tree/master/ntfs_forensics
v
is there a release version of it?
m
There hasn't been a recent binary tagged as a release, no, but it should build from source
v
great. thanks