About osquery
osquery is an instrumentation, monitoring and analytics framework that lets you ask questions about an operating system using SQL. It makes the machine look like a high-performance relational database, so instead of writing scripts for each platform you query tables describing things like processes, kernel modules, network sockets, browser extensions, hardware events and file hashes.
It works on Linux, macOS and Windows. New tables are added through a simple plugin and extensions API, and a public schema reference documents the available tables. The README illustrates its expressiveness with sample queries such as listing users or finding processes whose binaries were deleted from disk. Resources include documentation on ReadTheDocs, downloads, Stack Overflow and a Slack community, and topics tag it for security, intrusion detection and monitoring.
osquery is written in C++ and its license is listed as 'Other' on GitHub, so check the repository for the exact terms. It runs locally on each endpoint, and organizations typically deploy it across a fleet and collect results with their own tooling. It suits security teams, IT administrators and detection engineers who want consistent endpoint visibility.
Key features
- SQL queries over operating system data
- Tables for processes, network connections and kernel modules
- Linux, macOS and Windows support
- Plugin and extensions API for new tables
- Public schema documentation
- Suitable for fleet-wide endpoint monitoring
Good fit for
- →Endpoint security investigation
- →Inventory of software and hardware across machines
- →Threat hunting with SQL
- Built with
- C++
- Tags
- security
- monitoring
- sql
- endpoint
- intrusion-detection
- cpp
- analytics
- osquery
Open-source alternatives to osquery
See all
Fleet
Security
Open device management
OSSvs Jamf★ 6.9k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
CrowdSec
Security
Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with
MITvs Cloudflare★ 15k
Suricata
Security
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network
GPL-2.0vs Palo Alto Networks★ 6.7k
OSSEC
Security
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis,
GPL-2.0vs CrowdStrike★ 5.1k
Gitleaks
Security
Find secrets with Gitleaks 🔑
MITvs GitGuardian★ 30k
SaaS alternatives to osquery
See all
Tanium
Security
Endpoint management and security platform
SaaS
Ivanti
Security
IT and security management software for endpoints, patching and service management
SaaS
NinjaOne
Security
Endpoint management and remote monitoring software for IT teams and MSPs
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Akeyless
Security
SaaS secrets management and machine identity platform for apps and pipelines
SaaS

