You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Construct virtual table for querying alternate data streams on Windows.
Summary
Similar to the extended attributes table on MacOS, the ADS feature of Windows has a great wealth of information, including potentially where the file came, and even additional malware files themselves. This table would make a great addition/extension to the file table of osquery.
The text was updated successfully, but these errors were encountered:
Feature request
Construct virtual table for querying alternate data streams on Windows.
Summary
Similar to the extended attributes table on MacOS, the ADS feature of Windows has a great wealth of information, including potentially where the file came, and even additional malware files themselves. This table would make a great addition/extension to the
file
table of osquery.The text was updated successfully, but these errors were encountered: