osquery
A SQL-powered framework that exposes an operating system as a relational database for monitoring, security investigation and analytics on Linux, macOS and Windows.
- GitHub stars
- 24k
- Last commit
- yesterday
- Latest release
- 5.23.1
- Self-hosted
- Yes

osquery is an instrumentation, monitoring and analytics framework that lets you ask questions about an operating system using SQL. It makes the machine look like a high-performance relational database, so instead of writing scripts for each platform you query tables describing things like processes, kernel modules, network sockets, browser extensions, hardware events and file hashes.
It works on Linux, macOS and Windows. New tables are added through a simple plugin and extensions API, and a public schema reference documents the available tables. The README illustrates its expressiveness with sample queries such as listing users or finding processes whose binaries were deleted from disk. Resources include documentation on ReadTheDocs, downloads, Stack Overflow and a Slack community, and topics tag it for security, intrusion detection and monitoring.
osquery is written in C++ and its license is listed as 'Other' on GitHub, so check the repository for the exact terms. It runs locally on each endpoint, and organizations typically deploy it across a fleet and collect results with their own tooling. It suits security teams, IT administrators and detection engineers who want consistent endpoint visibility.
Key features
- SQL queries over operating system data
- Tables for processes, network connections and kernel modules
- Linux, macOS and Windows support
- Plugin and extensions API for new tables
- Public schema documentation
- Suitable for fleet-wide endpoint monitoring

