What is osquery?
osquery exposes an operating system as a high-performance relational database. This allows you to write SQL-based queries to explore operating system data. With osquery, SQL tables represent abstract concepts such as running processes, loaded kernel modules, open network connections, browser plugins, hardware events or file hashes.
osquery is a tool in the Desktop Querying Tools category of a tech stack.
osquery is an open source tool with 16.4K GitHub stars and 1.9K GitHub forks. Here’s a link to osquery's open source repository on GitHub
Who uses osquery?
7 developers on StackShare have stated that they use osquery.
Why developers like osquery?
Here’s a list of reasons why companies and developers use osquery
Be the first to leave a pro
osquery Alternatives & Comparisons
What are some alternatives to osquery?
See all alternatives
It is a free, open-source host-based intrusion detection system. It performs log analysis, integrity checking, registry monitoring, rootkit detection, time-based alerting, and active response.
It is the acronym for three open source projects: Elasticsearch, Logstash, and Kibana. Elasticsearch is a search and analytics engine. Logstash is a server‑side data processing pipeline that ingests data from multiple sources simultaneously, transforms it, and then sends it to a "stash" like Elasticsearch. Kibana lets users visualize data with charts and graphs in Elasticsearch.
Prometheus is a systems and service monitoring system. It collects metrics from configured targets at given intervals, evaluates rule expressions, displays the results, and can trigger alerts if some condition is observed to be true.
It is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.
Pass your query to fsql via command line argument. In general, each query requires a SELECT clause (to specify which attributes should be shown), a FROM clause (to specify the directories to search in), and a WHERE clause (to specify conditions for the files).