Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
xprotect_reports
Database of XProtect matches (if user generated/sent an XProtect report).
Column | Type | Description |
---|---|---|
name | text | Description of XProtected malware |
time | text | Quarantine alert time |
user_action | text | Action taken by user after prompted |
See all Xprotect activity reports, if any are present. This indicates potentially malicious software was blocked by Xprotect.
SELECT * FROM xprotect_reports;