osquery-defense-kit/incident_response/processes.sql

28 lines
335 B
MySQL
Raw Normal View History

-- Currently running programs, only the columns that are not constantly changing
2022-10-17 21:11:15 +00:00
--
-- tags: postmortem often
2022-10-17 21:11:15 +00:00
-- platform: posix
SELECT
pid,
name,
path,
cmdline,
state,
cwd,
root,
uid,
gid,
euid,
egid,
suid,
sgid,
on_disk,
start_time,
parent,
pgroup,
threads,
nice,
cgroup_path
FROM
processes