Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
kernel_extensions
macOS's kernel extensions, both loaded and within the load search path.
Column | Type | Description |
---|---|---|
idx | integer | Extension load tag or index |
linked_against | text | Indexes of extensions this extension is linked against |
name | text | Extension label |
path | text | Optional path to extension bundle |
refs | integer | Reference count |
size | bigint | Bytes of wired memory used by extension |
version | text | Extension version |
Identify third-party kernel extensions.
SELECT * FROM kernel_extensions WHERE name NOT LIKE 'com.apple%' AND name NOT LIKE '__kernel__';