Ben Chuanlong Du's Blog

It is never too late to learn.

Query and Monitor OS Information using osquery

Things on this page are fragmentary and immature notes/thoughts of the author. Please read with your own judgement!

  1. List all tables.

    .\osqueryi .tables

  2. Check the schema of a table (e.g., "process").

    .\osqueryi ".schema processes"

Querying System Information

.\osqueryi.exe "select * from system_info"

Querying Docker

Please refer to Manage …

The Best Way to Find Files and Manipulate Them

Things on this page are fragmentary and immature notes/thoughts of the author. Please read with your own judgement!

There are many cool (command-line) tools which can help you quickly find/locate files. Notice that they can all be combined with fzf to make it interactive.

  1. fdfind
  2. find
  3. locate
  4. osquery
  5. fselect
  6. ripgrep

Those tools can be combined with the pipe operator |