Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
beyond-identity
fleet
vendor-feeds
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#general
Title
# general
h
Hello_There
04/12/2021, 1:24 PM
hi all Is there any way to monitor the use of a dll or the execution of a dll? I am looking to monitor the use or execution of "wininet.dll"
✅ 1
m
Mike Myers
04/12/2021, 4:48 PM
Hi. No, currently osquery doesn't have a table that audits DLL load events
h
Hello_There
04/12/2021, 5:44 PM
glad you for the feedback
w
Will Teller
04/13/2021, 10:40 AM
As Sysmon (ID 7) can log image loads, including DLLs (though can be resource intensive apparently), could not osquery pull-in such event logs?
m
Mike Myers
04/13/2021, 3:45 PM
You could use osquery as a log forwarder? Like with
windows_eventlog
table maybe?
3 Views