raw_inventory
Dump raw read-only inventory of processes, launchd jobs, extensions, kexts, certs, and MDM status. Use to investigate unrecognized items or gather artifacts for signature contributions.
Instructions
Return the raw read-only inventory with NO matching (power users).
Dumps processes, launchd jobs, extensions, kexts, certs and MDM status as collected. Use this to investigate something watchcheck didn't recognize, or to gather artifacts for a new signature contribution.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||