Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add OSQuery #318

Open
wants to merge 2 commits into
base: develop
Choose a base branch
from
Open

Add OSQuery #318

wants to merge 2 commits into from

Conversation

SolitudePy
Copy link

Hello, this PR includes 2 commits:

  • OSQuery stripped binary version 5.15 which is included as part of the original osquery rpm package, binary size is about 82MB which is close to Github file size limit.
  • osquery/osquery.yaml artifact, 17 custom queries relevant to linux live response, it is outputting in json format(there is also csv, json_pretty which can be customized pretty easily be the end user)

I tested it on RHEL 8.6 and it worked fine, finished executing after 13 seconds, the size of the output files was about 3.2MB unzipped.

I suppose I should add few documentations, credits to OSQuery et cetera, but I'm not quite sure where, I would like to with your guidance, thanks!

@Pierre-Gronau-ndaal
Copy link
Contributor

is it right that your binary is supporting only 64 bit on x86 ?

https://github.com/osquery/osquery/releases

@SolitudePy
Copy link
Author

@Pierre-Gronau-ndaal it is not my binary, but from what I've seen it supports arm as well

@Pierre-Gronau-ndaal
Copy link
Contributor

@Pierre-Gronau-ndaal it is not my binary, but from what I've seen it supports arm as well

according to Releases they offer arm as well - mmh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants