osquery-defense-kit/incident_response/es_process_events.sql

8 lines
125 B
SQL

-- Dump a list of process execution events from EndpointSecurity
--
-- platform: darwin
SELECT
*
FROM
es_process_events;