osquery-defense-kit/incident_response/suid_bin.sql

9 lines
130 B
MySQL
Raw Normal View History

-- Retrieves setuid-enabled executables in well-known paths
2022-10-13 13:11:17 +00:00
--
-- platform: posix
-- tags: postmortem
SELECT
2022-10-17 23:06:17 +00:00
*
FROM
2022-10-17 23:06:17 +00:00
suid_bin;