https://github.com/osquery/osquery logo
#general
Title
# general
b

Brandon Mesa

12/15/2022, 6:08 PM
Hey all, anyone know if there's a way to monitor/identify file ownership changes? using the file_events table currently, which logs an entry as "attributes modified" for the given file object, however, this could be permission mode change, ownership, etc. Looking for something that would explicitly indicate ownership change
2 Views