Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
authenticode
File (executable, bundle, installer, disk) code signing status.
Column | Type | Description |
---|---|---|
issuer_name | text | The certificate issuer name |
original_program_name | text | The original program name that the publisher has signed |
path | text | Must provide a path or directory Required in WHERE clause |
result | text | The signature check result |
serial_number | text | The certificate serial number |
subject_name | text | The certificate subject name |
SELECT process.pid, process.path, signature.result FROM processes as process LEFT JOIN authenticode AS signature ON process.path = signature.path;