Osquery



  • Manufacturer: osquery project
  • Version: 4.1.2
  • Website: https://osquery.io/

Description

Osquery is an operating system instrumentation framework for Windows, OS X (macOS), Linux, and FreeBSD. The tools make low-level operating system analytics and monitoring both performant and intuitive. Osquery exposes an operating system as a high-performance relational database. Osquery is a free open source, powerful and cross-platform SQL-based operating system instrumentation, monitoring, and analytics framework for Linux, FreeBSD, Windows, and Mac/OS X systems, built by Facebook. It is a simple and easy-to-use operating system explorer. Manufacturer: osquery project; Version: 4.1.2; Website: Description. Osquery exposes an operating system as a high-performance relational database. This allows you to write SQL-based queries to explore operating system data. Data Model Coverage driver. Osquery is an open-source tool originally developed at Facebook that exposes operating system configuration data in the form of relational database tables. By issuing SQL-like queries against these tables, users can collect valuable data about the current state of the system as well as changes applied to it over time. What Is Osquery. Osquery is a powerful security tool that provides a table-like interface to endpoint information that can be queried using SQL. It is an operating system instrumentation, monitoring, and analytics” framework powered by SQL.

osquery exposes an operating system as a high-performance relational database. This allows you to write SQL-based queries to explore operating system data.

Osquery packs

Data Model Coverage

driver

base_addressfqdnhostnameimage_pathmd5_hashmodule_namepidsha1_hashsha256_hashsignature_validsigner
load
unload

Osqueryd

file

companycontentcreation_timefile_extensionfile_gidfile_groupfile_namefile_pathfile_uidfile_userfqdnhostnameimage_pathlink_targetmd5_hashmime_typemodepidppidprevious_creation_timesha1_hashsha256_hashsignature_validsigneruiduser
acl_modify
create
delete
modify
read
timestomp
write

flow

Osquery Github

application_protocolcontentdest_fqdndest_hostnamedest_ipdest_portend_timeexefqdnhostnameimage_pathin_bytesnetwork_directionout_bytespacket_countpidppidproto_infosrc_fqdnsrc_hostnamesrc_ipsrc_portstart_timetcp_flagstransport_protocoluiduser
end
message
start
Osquery daemon and shell

process

SchemaOsquery
access_levelcall_tracecommand_linecurrent_working_directoryenv_varsexefqdnguidhostnameimage_pathintegrity_levelmd5_hashparent_command_lineparent_exeparent_guidparent_image_pathpidppidsha1_hashsha256_hashsidsignature_validsignertarget_addresstarget_guidtarget_nametarget_piduiduser
access
create
terminate

Analytic Coverage





Comments are closed.