https://github.com/osquery/osquery logo
Title
k

Kiwito

02/27/2023, 9:29 AM
I have checked all messages about
last_opened_time from apps
but I couldn't find the answer. Some apps results as
-1
even though they are open. Is this a known issue? I also checked gitlab issues but I couldn't see anything.
a

allister

03/01/2023, 4:30 AM
Pardon the lag, I looked at this a good long while ago. You are best served by not trusting that attribute as if the app is patched through drag/drop or an auto-updater that swaps all bits the date can/will be reset to empty, and instead using NSWorkspace launch/'activate'/quit monitoring with a daemon like the one built into munki, or the invocation watching that Santa does for e.g. command line-heavy tools like Docker