2022-10-13 13:11:17 +00:00
|
|
|
-- Retrieves all the open files per process in the target system.
|
|
|
|
--
|
2022-10-19 20:19:53 +00:00
|
|
|
-- tags: postmortem
|
2022-10-13 13:11:17 +00:00
|
|
|
-- platform: posix
|
2022-10-19 20:19:53 +00:00
|
|
|
SELECT DISTINCT
|
|
|
|
pof.pid,
|
|
|
|
pof.path,
|
2023-05-16 21:18:39 +00:00
|
|
|
pof.fd,
|
2022-10-19 20:19:53 +00:00
|
|
|
p.name,
|
2023-05-16 21:18:39 +00:00
|
|
|
p.start_time,
|
|
|
|
p.euid,
|
|
|
|
p.parent,
|
|
|
|
p.uid,
|
2022-10-19 20:19:53 +00:00
|
|
|
p.cmdline
|
|
|
|
FROM
|
|
|
|
process_open_files pof
|
|
|
|
LEFT JOIN processes p ON pof.pid = p.pid
|
|
|
|
WHERE
|
|
|
|
pof.path NOT LIKE '/private/var/folders%'
|
|
|
|
AND pof.path NOT LIKE '/System/Library/%'
|
|
|
|
AND pof.path NOT IN ('/dev/null', '/dev/urandom', '/dev/random');
|