osquery-defense-kit/incident_response/process-files.sql

13 lines
401 B
MySQL
Raw Normal View History

-- Returns information about running processes(non-hidden only)
2023-02-23 14:35:38 +00:00
--
-- tags: postmortem
-- platform: linux
SELECT GROUP_CONCAT(processes.pid) AS processes,
GROUP_CONCAT(processes.name) AS names,
file.*, hash.sha256,
magic.data
2023-02-23 14:35:38 +00:00
FROM processes
LEFT JOIN file ON processes.path = file.path
LEFT JOIN hash ON processes.path = hash.path
LEFT JOIN magic ON processes.path = magic.path
GROUP BY processes.path