Title
#windows
clippy

clippy

04/10/2018, 6:07 PM
@666reda here's the script I use to set my flags file (osqueryd looks for an osquery.flags and osquery.flags.default)
Stop-Service -Name "osqueryd"

$secret_filename = "c:\ProgramData\osquery\osquery.secret"
$secret_content = "example-secret"

if (Test-Path -Path $secret_filename) {
    Remove-Item $secret_filename
    Write-Host "Removed Secrets file"
}

[IO.File]::WriteAllLines($secret_filename, $secret_content)

$default_flagpath = "C:\ProgramData\osquery\osquery.flags.default"

if (Test-Path -Path $default_flagpath) {
    Remove-item -Path $default_flagpath
    Write-Host "Removed default flags file"
}

$content = "--config_plugin=tls
--enroll_secret_path=C:\Programdata\osquery\osquery.secret
--enroll_tls_endpoint=/node/enroll
--config_tls_endpoint=/node/configure
--tls_hostname=<http://example.domain.endpoint.com|example.domain.endpoint.com>
--config_refresh=300
--config_tls_accelerated_refresh=300
--config_tls_max_attempts=9999"
[IO.File]::WriteAllLines($default_flagpath, $content)

$flagpath = "c:\ProgramData\osquery\osquery.flags"

if (Test-Path -Path $flagpath) {
    Remove-Item -Path $flagpath
    Write-Host "Removed flags file"
}

New-Item -Path C:\ProgramData\osquery\osquery.flags -ItemType SymbolicLink -Value C:\ProgramData\osquery\osquery.flags.default

Start-Service -Name "osqueryd"
666reda

666reda

04/11/2018, 10:28 AM
what is the name+extension of this file ?
clippy

clippy

04/11/2018, 5:27 PM
This is a power shell script. (.ps1)