osquery-1/specs/windows/drivers.table
2019-10-28 20:27:06 -04:00

23 lines
985 B
Plaintext

table_name("drivers")
description("Details for in-use Windows device drivers. This does not display installed but unused drivers.")
schema([
Column("device_id", TEXT, "Device ID"),
Column("device_name", TEXT, "Device name"),
Column("image", TEXT, "Path to driver image file"),
Column("description", TEXT, "Driver description"),
Column("service", TEXT, "Driver service name, if one exists"),
Column("service_key", TEXT, "Driver service registry key"),
Column("version", TEXT, "Driver version"),
Column("inf", TEXT, "Associated inf file"),
Column("class", TEXT, "Device/driver class name"),
Column("provider", TEXT, "Driver provider"),
Column("manufacturer", TEXT, "Device manufacturer"),
Column("driver_key", TEXT, "Driver key"),
Column("date", BIGINT, "Driver date"),
Column("signed", INTEGER, "Whether the driver is signed or not")
])
implementation("system/windows/Drivers@genDrivers")
examples([
"select * from drivers",
])