Retrieves the command history, per user, by parsing the shell history files.


Query · osquery

-- Retrieves the command history, per user, by parsing the shell history files.
--
-- tags: postmortem
-- platform: posix
SELECT
  *
FROM
  users
  JOIN shell_history USING (uid);
Raw source Retrieves the command history, per user, by parsing the shell history files. · osquery SQL
Esc
Published by chainguard-dev/osquery-defense-kit ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
-- Retrieves the command history, per user, by parsing the shell history files.
--
-- tags: postmortem
-- platform: posix
SELECT
  *
FROM
  users
  JOIN shell_history USING (uid);

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.