osquery-defense-kit/incident_response/known_hosts.sql

7 lines
191 B
SQL

-- Retrieves chrome extensions that execute on a broad set of URLs.
-- tags: postmortem
-- platform: posix
SELECT known_hosts.*
FROM users
JOIN known_hosts ON users.uid = known_hosts.uid