mikermcneil
01/28/2023, 12:17 AMxprotect_meta table might be wrong:
https://fleetdm.com/tables/xprotect_meta
But when I query some Macs, I see "com.viewanysearch", which looks pretty sketchy, with its minimum version listed as "any". Should this actually say:- The minimum allowed plugin version.min_version
- The minimum banned plugin versionmin_version
mikermcneil
01/28/2023, 12:27 AMcom.anysearch thing which is presumably effectively a virus)mikermcneil
01/28/2023, 12:30 AMzwass
zwass
zwass
mikermcneil
01/28/2023, 12:54 AMzwass
zwass
mikermcneil
01/28/2023, 12:57 AMmin_version is actually min_version blocked
Looks like it's set for some other random things like flash player and Java:zwass
ExtensionBlacklist entries (which is where the anysearch is). They do set it for PluginBlacklist where it might actually be correct as documented.zwass
mikermcneil
01/28/2023, 1:00 AMzwass