|
|
|
|
|
by skissane
2493 days ago
|
|
osquery is cool. But, as far as I know, it doesn't expose the filesystem as a database, it is closer to /proc-as-a-database. (osquery can monitor specific files, in particular security-sensitive files, and expose events related to those files in SQL tables; but I don't think that facility is scalable from certain specific files to the entire filesystem.) |
|
As that page describes, the "query" command (or its equivalent GUI) can be used to write filesystem queries, e.g.: