osquery-defense-kit/incident_response/process_memory_map.sql
2023-02-23 09:35:38 -05:00

17 lines
248 B
SQL

-- Retrieves the memory map per process
-- platform: posix
-- tags: postmortem
SELECT pid,
permissions,
offset,
inode,
path,
pseudo
FROM process_memory_map
WHERE path != ""
GROUP BY pid,
permissions,
offset,
inode,
path,
pseudo;