osquery-defense-kit/incident_response/files-dev.sql

8 lines
197 B
SQL

-- Returns a list of file information from /dev (non-hidden only)
--
-- tags: postmortem
-- platform: posix
SELECT *
FROM file
JOIN hash ON file.path = hash.path
WHERE file.path LIKE "/dev/%%";