Join Slack
Powered by
Hi, I'm using FIM for windows. Is there a way I ca...
# fim
k
Kunal
12/06/2022, 5:30 AM
Hi, I'm using FIM for windows. Is there a way I can query for file-modification events which also gives the name of the process which modified it ? Thanks
z
zwass
12/06/2022, 6:34 PM
I don't think that's possible on Windows with osquery today. It might be supported in the newer ETW-based file events table that we are planning:
https://github.com/osquery/osquery/issues/7836#issue-1473557810
.
k
Kunal
12/07/2022, 11:14 AM
Thanks for the update. Could you give an idea when this feature would be available in OSquery ?
z
zwass
12/07/2022, 4:06 PM
There is no timeline as of now.
13
Views
Open in Slack
Previous
Next