Skip to content

Instantly share code, notes, and snippets.

@defensivedepth
Last active March 30, 2024 12:47

Revisions

  1. defensivedepth revised this gist Sep 4, 2018. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion osquery-compromised-mega-chrome-ext.sql
    Original file line number Diff line number Diff line change
    @@ -1,3 +1,3 @@
    -- Joins chrome_extension and users table, looks for Mega chrome identifier and specific version number; should also consider running without the version number, to find all users with Mega extension installed; get it removed prior to it updating.
    -- Joins chrome_extension and users table, looks for Mega chrome identifier and specific version number; should also consider running without the version number, to find all users with Mega extension installed and then get it removed prior to it updating.

    SELECT users.username,chrome_extensions.name,chrome_extensions.version,chrome_extensions.path FROM chrome_extensions JOIN users ON users.uid = chrome_extensions.uid where chrome_extensions.identifier = 'bigefpfhnfcobdlfbedofhhaibnlghod' and chrome_extensions.version = '3.39.4';
  2. defensivedepth revised this gist Sep 4, 2018. No changes.
  3. defensivedepth created this gist Sep 4, 2018.
    3 changes: 3 additions & 0 deletions osquery-compromised-mega-chrome-ext.sql
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,3 @@
    -- Joins chrome_extension and users table, looks for Mega chrome identifier and specific version number; should also consider running without the version number, to find all users with Mega extension installed; get it removed prior to it updating.

    SELECT users.username,chrome_extensions.name,chrome_extensions.version,chrome_extensions.path FROM chrome_extensions JOIN users ON users.uid = chrome_extensions.uid where chrome_extensions.identifier = 'bigefpfhnfcobdlfbedofhhaibnlghod' and chrome_extensions.version = '3.39.4';