There are 23 repositories under osquery topic.
Automate the creation of a lab environment complete with security tooling and logging best practices
A repository for using osquery for incident detection and response
Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Production-ready detection & response queries for osquery
Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event notifications, alerting, and reporting.
osquery extensions by Trail of Bits
Threat Hunting & Incident Investigation with Osquery
Fully automated host & network intrusion detection platform. Detects malware from behavioural patterns rather than signatures and enables deeper visibility than legacy tools.
SIAC is an enterprise SIEM built on open-source technology.
SysEye是一个window上的基于att&ck现代EDR设计**的威胁响应工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
[DEPRECATED] A quickstart demo for Kolide tools
osquery table extension that allows querying of information from the macOS private SystemPolicy.framework
A starter-kit for a source-controlled, CLI-based osquery management workflow.
Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma
ALPHA/WIP for OSquery configuration for Mac and Linux Operating Systems
Data files for use with hubble
Repository containing Jupyter Notebooks for working with OSQuery tables and data
A Chef Cookbook to install and configure osquery.
A tool to run and validate telemetry for Atomic Red Team tests