osquery-1/specs/darwin/kernel_extensions.table
Teddy Reed a105924804 Move specs to a top-level path, add query examples
1. Example queries will run with an (optional) integration test.
2. Fix bad accesses with OS X package BOMs
3. Move spec files from ./osquery/tables/specs to ./specs
4. Remove server parsers (netlib) from client builds.
2015-06-03 10:39:05 -07:00

14 lines
612 B
Plaintext

table_name("kernel_extensions")
description("OS X's kernel extensions, both loaded and within the load search path.")
schema([
Column("idx", INTEGER, "Extension load tag or index"),
Column("refs", INTEGER, "Reference count"),
Column("size", BIGINT, "Bytes of wired memory used by extension"),
Column("name", TEXT, "Extension label"),
Column("version", TEXT, "Extension version"),
Column("linked_against", TEXT,
"Indexes of extensions this extension is linked against"),
Column("path", TEXT, "Optional path to extension bundle")
])
implementation("kextstat@genKernelExtensions")