https://github.com/osquery/osquery logo
#general
Title
# general
s

smarsh

05/29/2019, 2:50 PM
Hi - I am tracking an issue on the chrome browser extensions table failing to return results https://github.com/facebook/osquery/issues/5563 is there another issue related i can track Ive noticed this one isnt yet assigned. I use the chrome extensions results in conjunction with crxcavator.io to understand overall risk and it has proved to be extremely helpful
j

Jams

05/29/2019, 4:50 PM
Does crxcavator.io provide an offline DB?
s

smarsh

05/29/2019, 5:15 PM
I have only used it via the API look up feature
Doesnt look like it does
j

Jams

05/29/2019, 6:23 PM
An extension might be nice to query crxcavator.io based on the results of discovered chrome extensions.
d

defensivedepth

05/31/2019, 1:00 PM
@Jams @smarsh How are you integrating the crxcavator data? I have been using a simple logstash filter: https://defensivedepth.com/2019/02/28/osquery-enriching-chrome-extension-data/
s

smarsh

05/31/2019, 1:06 PM
I have used it via the API - when we get the browser extension, query crxcavator to pin point the ‘riskier’ extensions - ill have to look into the logstach filter
3 Views