Gatekeeper_approved_apps_macos
osquery
Retrieves all the gatekeeper exceptions on a macOS host
Description
ODK (osquery-defense-kit) is unique in that the queries are designed to be used as part of a production detection & response pipeline. The detection queries are formulated to return zero rows during normal expected behavior, so that they may be configured to generate alerts when rows are returned.
Query
-- Retrieves all the gatekeeper exceptions on a macOS host
--
-- tags: postmortem
-- platform: darwin
SELECT
gap.ctime,
gap.mtime,
gap.path,file.mtime,
file.uid,
file.ctime,
file.gid,
hash.sha256,
identifier,
signature.
signature.authorityFROM
AS gap
gatekeeper_approved_apps LEFT JOIN file ON gap.path = file.path
LEFT JOIN hash ON gap.path = hash.path
LEFT JOIN signature ON gap.path = signature.path
GROUP BY
gap.requirement
tags: SStagSS