mirror of
https://github.com/chainguard-dev/osquery-defense-kit
synced 2025-02-02 18:51:37 +00:00
Add support for .pkg files
This commit is contained in:
parent
1bd030a2f2
commit
dd3149a34b
@ -27,6 +27,7 @@ WHERE
|
||||
(
|
||||
mdfind.query = "kMDItemWhereFroms != '' && kMDItemFSName == '*.iso'"
|
||||
OR mdfind.query = "kMDItemWhereFroms != '' && kMDItemFSName == '*.dmg'"
|
||||
OR mdfind.query = "kMDItemWhereFroms != '' && kMDItemFSName == '*.pkg'"
|
||||
)
|
||||
AND ea.key = 'where_from'
|
||||
AND file.btime > (strftime('%s', 'now') -86400)
|
||||
|
Loading…
Reference in New Issue
Block a user