Osquery: The Basics

3

pid

5

56

180

programs

data

19

Creative Artist

Query: select path, key, name from registry where key = 'HKEY_USERS';

S-1-5-21-1966530601-3185510712-10604624-1009

Query: select * from ie_extensions; 

C:\Windows\System32\ieframe.dll

Query: select name,install_location from programs where name LIKE '%wireshark%';

Wireshark 3.6.8 64-bit

userassist

DiskWipe.exe

ProtonVPN

214

batstartup.bat

C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\batstartup.bat