osquery-defense-kit/detection/evasion/unexpected-kernel-extension...

18 lines
291 B
MySQL
Raw Normal View History

2022-10-14 18:19:13 +00:00
-- Find unexpected 3rd-party kernel extensions
--
-- false positives:
-- * none known
--
2022-10-14 14:18:23 +00:00
-- platform: darwin
2022-10-14 18:19:13 +00:00
-- tags: persistent seldom kernel
2022-10-14 14:18:23 +00:00
SELECT
*
FROM
kernel_extensions
WHERE
path NOT LIKE '/System/Library/Extensions/%'
AND NOT (
idx = 0
AND name = '__kernel__'
);