osquery-defense-kit/detection/persistence/unexpected-kernel-extensions.sql
2022-10-13 14:59:32 -04:00

13 lines
244 B
SQL

-- Display a list of non-Apple kernel extensions, which are exceedingly rare.
-- platform: darwin
SELECT
*
FROM
kernel_extensions
WHERE
path NOT LIKE '/System/Library/Extensions/%'
AND NOT (
idx = 0
AND name = '__kernel__'
);