Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tables: alternate data streams on Windows #5250

Open
muffins opened this issue Oct 8, 2018 · 0 comments · May be fixed by #8190
Open

tables: alternate data streams on Windows #5250

muffins opened this issue Oct 8, 2018 · 0 comments · May be fixed by #8190

Comments

@muffins
Copy link
Contributor

muffins commented Oct 8, 2018

Feature request

Construct virtual table for querying alternate data streams on Windows.

Summary

Similar to the extended attributes table on MacOS, the ADS feature of Windows has a great wealth of information, including potentially where the file came, and even additional malware files themselves. This table would make a great addition/extension to the file table of osquery.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant