OSQueryBasicQuery

Returns the results from a basic OSQuery query on a remote Linux machine. For more information read documentation at https://osquery.readthedocs.io/

Type
python
Pack
OSQuery

Source

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401
import json
import shlex


# ssh command to run, json format, param = query to execute.
# {0} is filled with a shlex.quote()-escaped value at call-site.
COMMAND = "osqueryi --json {0}"


def main():
    systems = argToList(demisto.args().get("system"))
    query = demisto.args().get("query")

    res = []
    error_res = []

    if query and systems:
        for system in systems:
            safe_query = shlex.quote(str(query))
            temp_res = demisto.executeCommand("RemoteExec", {"cmd": COMMAND.format(safe_query), "system": system})
            if isError(temp_res[0]):
                temp_res_contents = temp_res[0]["Contents"]
                error_res += [
                    {
                        "Type": entryTypes["error"],
                        "ContentsFormat": formats["text"],
                        "Contents": f'An Error occurred on remote system:"{system}". Error={temp_res_contents}.',
                    }
                ]
            else:
                data = json.loads(temp_res[0]["Contents"])
                res += [
                    {
                        "ContentsFormat": formats["markdown"],
                        "Type": entryTypes["note"],
                        "Contents": tblToMd(f"{system} results:", data),
                    }
                ]

    demisto.results(res + error_res)


if __name__ in ("__main__", "__builtin__", "builtins"):
    main()

README

Returns the results from a basic OSQuery query on a remote Linux machine.
For more information read this documentation.

Script Data


Name Description
Script Type python
Tags OSQuery

Dependencies


This script uses the following commands and scripts.

Inputs


Argument Name Description
system The system to remote execute on. This can be a list of systems.
query The osquery query to execute on the remote system.

Outputs


There are no outputs for this script.

Examples

!OSQueryBasicQuery system=test_system query="select liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;"

Returns logged in users details from a remote system using OSQuery.

!OSQueryBasicQuery system=test_system query="select distinct pid, family, protocol, local_address, local_port, remote_address, remote_port, path from process_open_sockets where path <> '' or remote_address <> '';"

Returns open sockets details from a remote system using OSQuery.

!OSQueryBasicQuery system=test_system query="select * from processes;"

Returns processes details from a remote system using OSQuery.

!OSQueryBasicQuery system=test_system query="select * from users;"

Returns Users Table from a remote system using OSQuery.