https://github.com/osquery/osquery logo
#general
Title
# general
h

Hello_There

04/12/2021, 1:24 PM
hi all Is there any way to monitor the use of a dll or the execution of a dll? I am looking to monitor the use or execution of "wininet.dll"
1
m

Mike Myers

04/12/2021, 4:48 PM
Hi. No, currently osquery doesn't have a table that audits DLL load events
h

Hello_There

04/12/2021, 5:44 PM
glad you for the feedback
w

Will Teller

04/13/2021, 10:40 AM
As Sysmon (ID 7) can log image loads, including DLLs (though can be resource intensive apparently), could not osquery pull-in such event logs?
m

Mike Myers

04/13/2021, 3:45 PM
You could use osquery as a log forwarder? Like with
windows_eventlog
table maybe?
3 Views