osquery-defense-kit/incident_response/running_apps_macos.sql

8 lines
124 B
SQL

-- Retrieves currently running applications
--
-- tags: postmortem often
-- platform: darwin
SELECT
*
FROM
running_apps;