TiloBox
Back to directory
osquery project preview

osquery

SQL powered operating system instrumentation, monitoring, and analytics by Linux Foundation.

LicenseApache-2.0
GitHub stars22.5k
Last commit1 weeks ago
Tags5 topics
Sql Os MonitoringEndpoint SecurityCppLinux FoundationSecurity
Overview

Why consider osquery?

osquery is an open-source operating system instrumentation framework created by Facebook and maintained by the Linux Foundation. Written in C++, it exposes OS attributes (running processes, loaded kernel modules, open sockets, hardware) as SQL tables.

Guided learning

Learn osquery by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of osquery

osquery allows security engineers and sysadmins to query infrastructure state using simple SQL commands.

Quickstart

bash
1# Interactive SQL query shell
2osqueryi "SELECT pid, name, path FROM processes WHERE on_disk = 0;"

osquery is licensed under the Apache License Version 2.0.

Related tools

More options with a similar category or technology profile.

osquery FAQs

osquery is listed as a Devops Infrastructure tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository and official website for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

osquery is listed under the Apache-2.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

osquery is listed as an alternative to Datadog Security. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.