Open allenhouchins opened 2 weeks ago
Apps installed via the Ubuntu Software app store do not appear to be easily queryable. They do not show up in the deb_packages
table since they are containerized apps and installed at /snap/
in the filesystem.
I searched osquery and found this feature request: https://github.com/osquery/osquery/issues/6091
Create a new table called snap_packages
that contains the output of the command snap list --all
I've created a workaround for now: https://github.com/allenhouchins/fleet-stuff/tree/main/linux-mdm-snap-packages
A queryable table with results similar to this: | Name | Version | Rev | Tracking | Publisher | Notes |
---|---|---|---|---|---|---|
core | 16-2.51.1 | 11060 | latest/stable | canonical✓ | - | |
core18 | 20210722 | 2128 | latest/stable | canonical✓ | base | |
my-snap | 1.0.0 | 22 | latest/stable | mypublisher | disabled |
prospect-pingouin
: https://fleetdm.slack.com/archives/C07GLME5P7C/p1728052663635649snap_packages
table as a table in agent options (auto table construction). Check out the file and setup here.