osquery-defense-kit/incident_response/disk_events_macos.sql

8 lines
113 B
SQL

-- Retrieves disk image (DMG) events
--
-- tags: postmortem
-- platform: darwin
SELECT
*
FROM
authorizations;