n0b00de
03/16/2022, 7:09 PMzwass
n0b00de
03/17/2022, 3:23 PMzwass
select name, cmdline, path, pid from processes where name in ('carbonblackagent', 'cylanceagent', 'crowdstrikeagent')
?Michal Nicpon
03/17/2022, 5:00 PMdrop table if exists x;
create temp table x (
name varchar(255)
);
insert into x (name) values ('clamd');
SELECT * FROM processes p join x on p.name = x.name;
I think you need to drop temporary tables because osquery keeps a single sqlite db connection option. It would fail next time the query runs if you don't clean up.zwass
CREATE TABLE... IF NOT EXISTS