mikermcneil03/17/2022, 1:56 AM
Mike Myers03/18/2022, 1:58 AM
Mike Myers03/18/2022, 2:10 AM
but to get events, better to be used as
which is when the "building on top of osquery" gets difficult
mikermcneil03/18/2022, 2:13 AM
Mike Myers03/18/2022, 2:36 AM
Anything come to mind as far as a low-hanging fruit for making it easier for anyone to build and use their own extensions successfully?With a reasonable SDK (go, python, maybe even ruby. Not c++) IMO the real difficulty is in understanding the model for how everything works. Like, I can make a go extension in an hour. But I’m pretty deeply versed in the osquery ecosystem, so I’m not exactly an average user.