osquery-defense-kit/incident_response/process_memory_map.sql

24 lines
255 B
MySQL
Raw Normal View History

-- Retrieves the memory map per process
-- platform: posix
-- tags: postmortem
2023-05-08 17:20:47 +00:00
SELECT
pid,
permissions,
2023-05-08 17:20:47 +00:00
offset
,
inode,
path,
pseudo
2023-05-08 17:20:47 +00:00
FROM
process_memory_map
WHERE
path != ""
GROUP BY
pid,
permissions,
2023-05-08 17:20:47 +00:00
offset
,
inode,
path,
2023-05-08 17:20:47 +00:00
pseudo;