hi everyone👋
I just released a osquery extension I've been working on for a bit, lief-osquery,
https://github.com/puffyCid/lief-osquery
Its an extension that lets u parse PE and MACHO file formats (similar to elf tables for the linux version of osquery).
It uses LIEF (Library to Instrument Executable Formats,
https://lief.quarkslab.com/) to parse the executable files and displays a variety information (imported/exported functions, basic binary info, libraries used, binary sections, and sig information for PE files)
Its pretty simple right now if anyone has suggestions/feedback on things to change or add let me know!
Thanks!