Hi everyone, I have been using OSQUERY for a long time but I haven’t had a need for this before until today. A friend of mine has asked is there a way to create unique unique process ID using osquery similar to the UUID. I know there is a UPID field but it’s empty.
There are a sqlite query that could generate a uuid but that could make the query complex and i didn’t know how to generate one per process.
Having that would be great to make sure you always have unique process similar to modern EDR tools .