osquery-defense-kit/incident_response/processes.sql

9 lines
100 B
SQL

-- Currently running programs
--
-- tags: postmortem
-- platform: posix
SELECT
*
FROM
processes