osquery extensions for Mac inventory and management at Campus.
Exposes a mac_enclosure_color table returning the running Mac's enclosure color (e.g. "Space Black", "Midnight", "Sky Blue").
SELECT * FROM mac_enclosure_color;
-- color | color_code | model | product_type
-- Space Black | 9 | MacBook Pro | Mac16,5Data sources:
MobileGestalt(/usr/lib/libMobileGestalt.dylib) —ProductType,DeviceEnclosureColor.system_profiler SPHardwareDataType -json— Model Name (MobileGestalt's marketing-name keys return "macOS" on recent macOS, so we shell out for this).
The numeric DeviceEnclosureColor is mapped to a color name using the convention popularized by munkireport's iBridge module — the same numeric code maps to different colors on different Mac product lines, so model name disambiguation is required.
Exposes a dot1x table with per-interface 802.1X / EAPOL supplicant state:
EAP method (outer + inner), supplicant state, client status / failure codes,
authenticator MAC, and mode.
SELECT interface, state_name, supplicant_state_name, eap_type_name FROM dot1x;
-- en0 | Running | Authenticated | EAP-TLSThe table implementation lives upstream in
macadmins/osquery-extension PR #113
(tables/dot1x); go.mod pins it to that PR's branch via a replace. This
wrapper registers only dot1x, because fleetd already bundles the other
macadmins tables and loading the full macadmins extension would collide with
them. Delete this extension once a fleetd release ships dot1x itself.
The touchid_system_config and touchid_user_config tables now live in
macadmins/osquery-extension
as of v1.5.1
(see PR #110 and
PR #111). Use the
upstream extension instead of this repo for Touch ID data.
cd mac_enclosure_color
GOOS=darwin go build -o "$(basename "$PWD").ext"Or build everything with make build from the repo root.
osqueryi --extension ./mac_enclosure_color.ext
osquery> SELECT * FROM mac_enclosure_color;Run the unit tests for all extensions with make test.
Drop the .ext binary into your Fleet fleetd agent's extensions directory; orbit auto-loads extensions on startup. Sign and notarize the binary with your Developer ID for clean Gatekeeper handling.
MIT