osquery/osquery
10:03AM | | | sudo adduser gust |
10:04AM | | | sudo visudo |
Build | | | 17A362 |
Version | | | 10.1.13 |
Patch | | | 6 |
origin | | | Ethiopia |
variety | | | yergachiffe |
address | | | 127.0.0.1 |
hostnames | | | localhost |
10:03AM | | | sudo adduser gust |
10:04AM | | | sudo visudo |
Build | | | 17A362 |
Version | | | 10.1.13 |
Patch | | | 6 |
origin | | | Ethiopia |
variety | | | yergachiffe |
address | | | 127.0.0.1 |
hostnames | | | localhost |
10:03AM | | | sudo adduser gust |
10:04AM | | | sudo visudo |
Build | | | 17A362 |
Version | | | 10.1.13 |
Patch | | | 6 |
origin | | | Ethiopia |
variety | | | yergachiffe |
address | | | 127.0.0.1 |
hostnames | | | localhost |
Osquery uses basic SQL commands to leverage a relational data-model to describe a device.
Frequently, attackers will leave a malicious process running but delete the original binary on disk. This query returns any process whose original binary has been deleted, which could be an indicator of a suspicious process.
Our build infrastructure ensures that newly introduced code is benchmarked and tested. We perform continuous testing for memory leaks, thread safety, and binary reproducibility on all supported platforms.
Windows, macOS, CentOS, and almost every Linux OS released since 2011 are supported with no dependencies. osquery powers some of the most demanding companies, including Facebook.
Osquery is released under the Apache License. Ever since we open-sourced it in 2014, organizations and individuals have contributed an ever-growing list of impressive features, useful tools, and helpful documentation.
See events related to Osquery that are being held in the near future.
Events are listed in reverse chronological order by date
A curated list of community projects to help you use and extend osquery.
4691
843
790
783
520
433
407
297
264
You're not alone when using osquery, please use one of the resources below reach out for help in installing, deploying and using osquery.