Retrieves all the values for the loginwindow process in the target OSX system.


Query · osquery

-- Retrieves all the values for the loginwindow process in the target OSX system.
--
--
-- tags: postmortem
-- platform: darwin
select
  key,
  subkey,
  value
from
  plist
where
  path = '/Library/Preferences/com.apple.loginwindow.plist';
Raw source Retrieves all the values for the loginwindow process in the target OSX system. · osquery SQL
Esc
Published by chainguard-dev/osquery-defense-kit ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
-- Retrieves all the values for the loginwindow process in the target OSX system.
--
--
-- tags: postmortem
-- platform: darwin
select
  key,
  subkey,
  value
from
  plist
where
  path = '/Library/Preferences/com.apple.loginwindow.plist';

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.