osquery-defense-kit/incident_response/disk_events_macos.sql

9 lines
118 B
SQL

-- Retrieves disk image (DMG) events
--
-- tags: postmortem events
-- platform: darwin
SELECT
*
FROM
disk_events;