curl -L | sudo tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery
sudo yum-config-manager --add-repo
sudo yum-config-manager --enable osquery-s3-rpm
sudo yum install osquery
cp /usr/share/osquery/osquery.example.conf /etc/osquery/osquery.conf
/etc/init.d/osqueryd start
osqueryi
查看系统信息
select * from system_info;
查看OS版本
select * from os_version;
看内核信息版本
SELECT * FROM kernel_info;
内存信息
select * from memory_info;
查询用户信息
select * from users;
select * from users where uid=0;
检查计划任务
select * from crontab;
阅读(2699) | 评论(0) | 转发(0) |