cmdline#

$ target-query <path/to/target> -f cmdline
Details#

Module

os.unix.linux.cmdline.CmdlinePlugin

Output

records

Module documentation

No documentation

Function documentation

Return the complete command line for all processes.

If, after an execve(2), the process modifies its argv strings, those changes will show up here. This is not the same thing as modifying the argv array.

Think of this output as the command line that the process wants you to see.

Yields CmdlineRecord with the following fields:

hostname (string): The target hostname. domain (string): The target domain. ts (datetime): The starttime of the process. name (string): The name of the process. pid (int): The process ID of the process. cmdline (string): The complete commandline of the process.