Macos - Re-Opened Applications
This search looks for processes referencing the plist files that determine which applications are re-opened when a user reboots their machine.
Macos - Re-Opened Applications Help
In order to properly run this search, Splunk needs to ingest process data from your osquery deployed agents with the splunk.conf pack enabled. Also the TA-OSquery must be deployed across your indexers and universal forwarders in order to have the data populate the Endpoint data model.
Open in Search