diff --git a/handbook/queries/README.md b/handbook/queries/README.md index d48ea09da6..5ee5c5b46d 100644 --- a/handbook/queries/README.md +++ b/handbook/queries/README.md @@ -26,6 +26,7 @@ Fleet's standard query library includes a growing collection of useful queries f - [Get authorized keys](./get-authorized-keys.md) (macOS, Linux) - [Get OS version](./get-os-version.md) (macOS, Linux, Windows, FreeBSD) - [Get mounts](./get-mounts.md) (macOS, Linux) +- [Get startup items](./get-startup-items.md) (macOS, Linux, Windows, FreeBSD) ### Contributors diff --git a/handbook/queries/get-startup-items.md b/handbook/queries/get-startup-items.md new file mode 100644 index 0000000000..eba1d4cfb0 --- /dev/null +++ b/handbook/queries/get-startup-items.md @@ -0,0 +1,16 @@ +# Get startup items + +Shows applications and binaries set as user/login startup items. + +### Support +macOS, Linux, Windows, FreeBSD + +### Query +```sql +SELECT * FROM startup_items; +``` +### Purpose +Informational + +### Remediation +N/A \ No newline at end of file