Osquery is an open-source system monitoring tool that uses SQL to expose data related to a device’s operating system as a relational database.
Osquery works on Windows, macOS, and Linux.
osquery
0001-01-01
Osquery is an open-source system monitoring tool that uses SQL to expose data related to a device’s operating system as a relational database.
Osquery works on Windows, macOS, and Linux.
Linux Persistence: Startup Scripts
2024-11-10 DFIR CTF linux persistence systemd SysV init startup script
Linux Persistence: Cron
2024-11-10 DFIR CTF linux persistence cron
Linux Persistence: User Accounts
2021-06-27 DFIR linux persistence