osquery-defense-kit/incident_response/es_process_events.sql

6 lines
122 B
SQL

-- Dump a list of process execution events from EndpointSecurity
--
-- platform: darwin
SELECT * FROM es_process_events;