-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support for Office MRU (most recently used) entries #6587
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think in this case we can call this office_mru
since the mru
abbreviation is common enough. What do you think? Do people usually refer to this data as "MRU"?
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
osquery/tables/applications/windows/office_most_recently_used.cpp
Outdated
Show resolved
Hide resolved
50ce5a3
to
49ea512
Compare
49ea512
to
1b66443
Compare
Hey @puffyCid, I made some changes, do you mind checking if the table still works? I do not have office installed and my Windows VM is a little flaky. |
thanks @theopolis for the changes. i pulled the changes, re-compiled osquery, and the table still works. |
This PR adds support for parsing Windows Office and Office365 MRU entries.
These entries contain recently opened Office documents as well as the time the document was last opened.
Sample query below:
Let me know if there are any issues that need to be fixed