Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
winbaseobj
Lists named Windows objects in the default object directories, across all terminal services sessions. Example Windows ojbect types include Mutexes, Events, Jobs and Semaphors.
Column | Type | Description |
---|---|---|
object_name | text | Object Name |
object_type | text | Object Type |
session_id | integer | Terminal Services Session Id |
select * from winbaseobj where type='Mutant'