Deprecated. Use OSQueryBasicQuery with query='select liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;' instead.
OS Query
- Details
- Content
- Dependencies
- Version History
Run OS query on a linux system.
Name | Description |
---|---|
OSQueryLoggedInUsers | |
OSQueryOpenSockets | Deprecated. Use OSQueryBasicQuery with query='select distinct pid, family, protocol, local_address, local_port, remote_address, remote_port, path from process_open_sockets where path |
OSQueryProcesses | Deprecated. Use OSQueryBasicQuery with query='select * from processes' instead. |
OSQueryBasicQuery | Returns the results from a basic OSQuery query on a remote Linux machine. |
OSQueryUsers | Deprecated. Use OSQueryBasicQuery with query='select * from users;' instead. |
Name | Description |
---|---|
OSQueryUsers | Deprecated. Use OSQueryBasicQuery with query='select * from users;' instead. |
OSQueryOpenSockets | Deprecated. Use OSQueryBasicQuery with query='select distinct pid, family, protocol, local_address, local_port, remote_address, remote_port, path from process_open_sockets where path |
OSQueryBasicQuery | Returns the results from a basic OSQuery query on a remote Linux machine. |
OSQueryProcesses | Deprecated. Use OSQueryBasicQuery with query='select * from processes' instead. |
OSQueryLoggedInUsers | Deprecated. Use OSQueryBasicQuery with query='select liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;' instead. |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Common Scripts | By: Cortex XSOAR |
Pack Name | Pack By |
---|
Pack Name | Pack By |
---|---|
Cortex REST API | By: Cortex XSOAR |
Base | By: Cortex XSOAR |
Common Scripts | By: Cortex XSOAR |
PUBLISHER
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Cortex | |
Created | November 9, 2020 | |
Last Release | November 28, 2024 |