Malicious OS processes

CEO

Business Angel
Jun 11, 2025
464
292
208
EU
Performant endpoint visibility

Processes running without a binary on disk
Frequently, attackers will leave a malicious process running but delete the original binary on disk. This query returns any process whose original binary has been deleted, which could be an indicator of a suspicious process

Sponsor Organizations.

Linux foundation
Fleet device management
Caffeine security

Homepage: osquery.io
Downloads: osquery.io/downloads
Documentation: ReadTheDocs
 

JohnnyDoe.is is an uncensored discussion forum
focused on free speech,
independent thinking, and controversial ideas.
Everyone is responsible for their own words.

Quick Navigation

User Menu