osquery
SQL-powered operating system instrumentation and monitoring for Linux, macOS, and Windows.
Open the official app on osquery.io
This tool is hosted by its maintainers. Click below to open osquery.io in a new tab — it's their official demo.
Browse developer tools →What's next with osquery?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is osquery?
osquery is an open-source framework that enables users to query and analyze operating system data using SQL. Developed for Linux, macOS, and Windows, it provides real-time visibility into system processes, files, network connections, and hardware configurations. Security teams, system administrators, and incident responders use osquery to monitor endpoints, detect anomalies, and investigate threats. It addresses challenges in traditional system monitoring by offering a structured, scalable way to collect and analyze low-level OS metrics without requiring deep expertise in system internals. By abstracting raw system data into a SQL-friendly format, osquery simplifies the process of auditing system states, tracking changes, and correlating events across endpoints. Its cross-platform design and extensibility through plugins make it a versatile tool for both proactive security operations and post-incident analysis. The project’s active community and comprehensive documentation further enhance its utility for organizations seeking to integrate operational insights into their security workflows.
How it works
osquery is a SQL-based tool for interrogating and analyzing operating system data. It transforms low-level system information—such as process listings, file systems, and network activity—into structured datasets that can be queried using SQL syntax. Its primary purpose is to enable real-time monitoring and forensic analysis of endpoints. By providing a unified interface to system data, osquery helps users identify configuration drift, detect malicious behavior, and enforce compliance policies across distributed environments. osquery supports querying system processes, registry keys, mounted filesystems, and network connections. For example, users can retrieve a list of running processes with `SELECT * FROM processes` or audit file system changes using `SELECT * FROM file_events`. It also integrates with plugins to extend functionality, such as collecting Windows event logs or monitoring Docker containers.
How to use it
- 1Download osquery from its official website or package repositories. 2. Install the CLI tool and configure it to connect to a local or remote server (e.g., for centralized management). 3. Run queries using the `osqueryi` command-line interface, such as `osqueryi --query 'SELECT * FROM processes'` to inspect active processes. 4. Use the schema documentation to design custom queries for specific use cases, like detecting unauthorized file modifications. Practical tips include leveraging the `--json` flag for structured output, using the `--schedule` option to run periodic checks, and integrating with tools like Elasticsearch for centralized log analysis.
What it can do
- endpoint querying
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/osquery/osquery
- license: Apache-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Limited built-in support for GUI-based interaction; requires CLI proficiency
- Platform-specific plugins may introduce complexity in cross-platform use cases
- Resource-intensive queries can impact system performance on low-end hardware
- Lacks native support for real-time data streaming without additional tooling
- Requires manual setup for centralized management, increasing deployment overhead
Understanding the result
SQL-powered operating system instrumentation and monitoring for Linux, macOS, and Windows.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (Apache-2.0).
- Built with
- (osquery/osquery)
- License
- Apache-2.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with osquery/osquery. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- Apache-2.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Apache-2.0 License
Upstream project
Frequently asked
What is osquery used for?
osquery is used to monitor, audit, and analyze operating system data across Linux, macOS, and Windows. It enables users to query real-time system information such as processes, files, network activity, and hardware states. Security teams use it for threat detection, compliance checks, and forensic analysis, while administrators leverage it for system health monitoring and configuration management.
How does osquery query operating system data?
osquery abstracts low-level system data into a SQL-compatible schema, allowing users to write queries that access structured datasets. For example, it translates raw process information into tables like 'processes' or 'network_connections', which can then be filtered, joined, and analyzed using SQL. This approach enables efficient data exploration without requiring deep knowledge of system internals.
How do I run a basic query to check running processes?
Install osquery and launch the CLI tool with `osqueryi`. Enter the query `SELECT * FROM processes` to retrieve a list of active processes. Use `--json` to output results in structured format. For example: `osqueryi --query 'SELECT pid, name FROM processes WHERE name LIKE "%explorer%"'` filters processes containing "explorer" in their name.
How does osquery compare to Windows Defender or Sysdig?
osquery is a flexible SQL-based framework for custom system monitoring, while Windows Defender focuses on endpoint protection and threat detection. Sysdig, in contrast, is a more comprehensive system monitoring tool with built-in dashboards and alerts. osquery excels in scenarios requiring custom queries or integration with existing SQL-based analytics pipelines.
What should I do if my query returns no results?
Verify the query syntax using the schema documentation at https://osquery.io/schema. Check if the query targets the correct table (e.g., `processes` vs. `file_events`). Ensure the system meets the query’s criteria (e.g., a running process must exist). Use `--verbose` to debug query execution and confirm data availability.