Facebook 整的 osquery,想法挺有意思,把操作系统看成一个关系型数据库,对于获取操作系统的信息更加统一了,不过就是啰唆了一点,比如
SELECT name, path, pid FROM processes WHERE on_disk = 0;
还有
SELECT DISTINCT process.name, listening.port, listening.address, process.pid FROM processes AS process JOIN listening_ports AS listening ON process.pid = listening.pid;
有点数据库知识的人应该都能看出这两条语句啥意思
项目也是开源的 https://github.com/facebook/osquery 感兴趣的可以去瞅瞅