osquery-defense-kit/incident_response/sandboxes_macos.sql

9 lines
131 B
SQL

-- Lists the application bundle that owns a sandbox label.
--
-- tags: postmortem
-- platform: darwin
SELECT
*
FROM
sandboxes;