osquery-defense-kit/incident_response/process_memory_map.sql
Thomas Stromberg 41d83350a1
make reformat
2023-05-08 13:20:47 -04:00

24 lines
255 B
SQL

-- Retrieves the memory map per process
-- platform: posix
-- tags: postmortem
SELECT
pid,
permissions,
offset
,
inode,
path,
pseudo
FROM
process_memory_map
WHERE
path != ""
GROUP BY
pid,
permissions,
offset
,
inode,
path,
pseudo;