What problem does it solve?
Security teams lack visibility into endpoint state across Windows, macOS, and Linux fleets, making it hard to detect fileless malware, unauthorized persistence, rogue listening ports, and compliance drift without deploying heavy agents.
Core Features & Use Cases
- Osquery Installation & Configuration: Step-by-step setup for Linux, Windows, and macOS with a production-ready osquery.conf including scheduled queries for processes, ports, persistence, users, crontabs, and SUID binaries.
- Threat Hunting Queries: Ready-to-use SQL queries for detecting fileless processes, unexpected listening ports, unauthorized SSH keys, external connections, and unsigned Windows executables.
- Fleet Management Integration: Guidance for enrolling agents into FleetDM or Kolide with TLS, plus log forwarding to SIEM pipelines.
- Use Case: A security engineer rolls out osquery across a 500-endpoint fleet, schedules differential queries for persistence mechanisms mapped to MITRE ATT&CK T1547, and streams results into a SIEM for threat hunting.
Quick Start
Ask the AI to generate an osquery configuration with scheduled queries that monitor running processes, listening ports, and persistence mechanisms on your Linux endpoints.