Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
process_memory_map
Process memory mapped files and pseudo device/regions.
Column | Type | Description |
---|---|---|
device | text | MA:MI Major/minor device ID |
end | text | Virtual end address (hex) |
inode | integer | Mapped path inode, 0 means uninitialized (BSS) |
offset | bigint | Offset into mapped path |
path | text | Path to mapped file or mapped type |
permissions | text | r=read, w=write, x=execute, p=private (cow) |
pid | integer | Process (or thread) ID |
pseudo | integer | 1 If path is a pseudo path, else 0 |
start | text | Virtual start address (hex) |
See the memory ranges with write permissions assigned to processes.
SELECT * FROM process_memory_map WHERE permissions LIKE '%w%';