Hi! I compiled the osquery extensions from trailofbits, and I have been trying to use the darwin_unified_log one. It loads correctly (seen with -verbose), but when I query the table it should generate, the table is always empty, can anyone help me out with this one?
12/18/2020, 6:41 PM
@Garret do you have the macOS extensions built? Is this something you can confirm?
12/18/2020, 7:35 PM
I have the extension built, let me fire up my vm
ooooh. okay, it definitely does not work, and looking at the code, I don’t think it’s ever worked, there’s a pretty clear logic error in there 😬