Deprecated. Use OSQueryBasicQuery with query='select * from processes' instead.
OS Query
- Details
- Content
- Dependencies
- Version History
Run OS query on a linux system.
| Name | Description |
|---|---|
| OSQueryProcesses | |
| OSQueryLoggedInUsers | Deprecated. Use OSQueryBasicQuery with query='select liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;' instead. |
| OSQueryUsers | Deprecated. Use OSQueryBasicQuery with query='select * from users;' instead. |
| OSQueryOpenSockets | Deprecated. Use OSQueryBasicQuery with query='select distinct pid, family, protocol, local_address, local_port, remote_address, remote_port, path from process_open_sockets where path |
| OSQueryBasicQuery | Returns the results from a basic OSQuery query on a remote Linux machine. |
| Name | Description |
|---|---|
| OSQueryBasicQuery | Returns the results from a basic OSQuery query on a remote Linux machine. |
| OSQueryOpenSockets | Deprecated. Use OSQueryBasicQuery with query='select distinct pid, family, protocol, local_address, local_port, remote_address, remote_port, path from process_open_sockets where path |
| OSQueryUsers | Deprecated. Use OSQueryBasicQuery with query='select * from users;' instead. |
| OSQueryProcesses | Deprecated. Use OSQueryBasicQuery with query='select * from processes' instead. |
| OSQueryLoggedInUsers | Deprecated. Use OSQueryBasicQuery with query='select liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;' instead. |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Common Scripts | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|
| Pack Name | Pack By |
|---|---|
| Cortex REST API | By: Cortex XSOAR |
| Common Scripts | By: Cortex XSOAR |
| Base | By: Cortex XSOAR |
PUBLISHER
PLATFORMS
INFO
| Certification | Certified | Read more |
| Supported By | Cortex | |
| Created | November 9, 2020 | |
| Last Release | July 8, 2025 |
