Skip to content

Latest commit

 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Campus osquery extensions

osquery extensions for Mac inventory and management at Campus.

Extensions

mac_enclosure_color

Exposes a mac_enclosure_color table returning the running Mac's enclosure color (e.g. "Space Black", "Midnight", "Sky Blue").

SELECT * FROM mac_enclosure_color;
-- color        | color_code | model        | product_type
-- Space Black  | 9          | MacBook Pro  | Mac16,5

Data sources:

  • MobileGestalt (/usr/lib/libMobileGestalt.dylib) — ProductType, DeviceEnclosureColor.
  • system_profiler SPHardwareDataType -json — Model Name (MobileGestalt's marketing-name keys return "macOS" on recent macOS, so we shell out for this).

The numeric DeviceEnclosureColor is mapped to a color name using the convention popularized by munkireport's iBridge module — the same numeric code maps to different colors on different Mac product lines, so model name disambiguation is required.

dot1x

Exposes a dot1x table with per-interface 802.1X / EAPOL supplicant state: EAP method (outer + inner), supplicant state, client status / failure codes, authenticator MAC, and mode.

SELECT interface, state_name, supplicant_state_name, eap_type_name FROM dot1x;
-- en0 | Running | Authenticated | EAP-TLS

The table implementation lives upstream in macadmins/osquery-extension PR #113 (tables/dot1x); go.mod pins it to that PR's branch via a replace. This wrapper registers only dot1x, because fleetd already bundles the other macadmins tables and loading the full macadmins extension would collide with them. Delete this extension once a fleetd release ships dot1x itself.

touchid — moved upstream

The touchid_system_config and touchid_user_config tables now live in macadmins/osquery-extension as of v1.5.1 (see PR #110 and PR #111). Use the upstream extension instead of this repo for Touch ID data.

Build

cd mac_enclosure_color
GOOS=darwin go build -o "$(basename "$PWD").ext"

Or build everything with make build from the repo root.

Test

osqueryi --extension ./mac_enclosure_color.ext
osquery> SELECT * FROM mac_enclosure_color;

Run the unit tests for all extensions with make test.

Deploy with Fleet

Drop the .ext binary into your Fleet fleetd agent's extensions directory; orbit auto-loads extensions on startup. Sign and notarize the binary with your Developer ID for clean Gatekeeper handling.

License

MIT

About

osquery extensions for Mac inventory and management at Campus

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages