There are 24 repositories under osquery topic.
🚀 Bring your favorite shell wherever you go through the ssh. Xonsh shell, fish, zsh, osquery and so on.
Automate the creation of a lab environment complete with security tooling and logging best practices
Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
A repository for using osquery for incident detection and response
Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Production-ready detection & response queries for osquery
Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event notifications, alerting, and reporting.
osquery extensions by Trail of Bits
Threat Hunting & Incident Investigation with Osquery
Fully automated host & network intrusion detection platform. Detects malware from behavioural patterns rather than signatures and enables deeper visibility than legacy tools.
SIAC is an enterprise SIEM built on open-source technology.
SysEye是一个window上的基于att&ck现代EDR设计**的威胁响应工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
[DEPRECATED] A quickstart demo for Kolide tools
osquery table extension that allows querying of information from the macOS private SystemPolicy.framework
Scripts to return inventory information for use in the JamfPro, heavily leveraging osquery
A starter-kit for a source-controlled, CLI-based osquery management workflow.
Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma
Repository containing Jupyter Notebooks for working with OSQuery tables and data
ALPHA/WIP for OSquery configuration for Mac and Linux Operating Systems
Data files for use with hubble
A Chef Cookbook to install and configure osquery.
A tool to run and validate telemetry for Atomic Red Team tests