https://github.com/osquery/osquery logo
Title
k

Kunal

12/06/2022, 5:30 AM
Hi, I'm using FIM for windows. Is there a way I can query for file-modification events which also gives the name of the process which modified it ? Thanks
z

zwass

12/06/2022, 6:34 PM
I don't think that's possible on Windows with osquery today. It might be supported in the newer ETW-based file events table that we are planning: https://github.com/osquery/osquery/issues/7836#issue-1473557810.
k

Kunal

12/07/2022, 11:14 AM
Thanks for the update. Could you give an idea when this feature would be available in OSquery ?
z

zwass

12/07/2022, 4:06 PM
There is no timeline as of now.