SQL makes host evidence approachable on 3 operating systems
osquery presents Linux, macOS, and Windows state as tables. A query can list users, find a process whose executable disappeared from disk, join listening ports to processes, or inspect file hashes. That interface is the lasting appeal: an analyst can use SQL instead of learning a different command for each operating-system subsystem. Custom tables and extensions can add data that the built-in schema does not expose.
The project has two main ways to ask those questions. osqueryi is a standalone interactive shell for one machine. osqueryd runs schedules and records how results change. The documentation's USB example runs every 60 seconds and emits a new result only when the device set changes. This makes the daemon useful for monitoring, though query design and collection still belong to the operator.
What happened when we ran it
Our sandbox clone failed on October 2, 2026 before Git produced a checkout or commit SHA. The unprivileged container had 3 CPUs, 8 GB of RAM, and no secrets. With no source tree available, the pipeline could not reach installation, compilation, tests, dependency counting, or an audit. There is no honest passing or failing build result to report.
The supplied lab record says only that git clone failed. It does not include a more specific cause, so blaming network access, authentication, repository size, or system packages would be guesswork. The public README was still available through GitHub's API and is long enough to review. Our product judgment below comes from that documentation, current repository facts, release notes, and issue activity, not from a local executable.
The shell works alone, while a fleet needs another layer
osqueryi does not connect to the daemon and does not require administrator rights. Some tables return fewer results without those rights, and event publishers are disabled by default. That makes the shell a practical investigation tool on a workstation where you can accept partial visibility. It also gives a team a safe place to shape SQL before scheduling it across thousands of endpoints.
Fleet operation is a separate engineering problem. The default daemon reads JSON configuration from the filesystem and writes JSON results locally. Remote use can add 3 HTTP endpoints for enrollment, configuration, and logging, plus a certificate authority and node credentials. Distributed queries require explicit configuration. The README also lists Fleet, Kolide, OSCTRL, and Zentral, while stating that osquery does not endorse, recommend, or test those managers.
Scheduled SQL can consume endpoint resources
The performance guide is unusually direct: poorly formed queries can damage osquery's performance guarantees. Schedules control how often a query runs, while laptops pause the daemon's interval clock during sleep. A query set tested on an always-on server can therefore behave differently on employee laptops. The project supplies a profiling script for CPU, memory, duration, and file descriptors, and recommends measuring a configuration before broad deployment.
Logging choices change the storage bill. Differential mode reports rows added or removed since the previous execution, while snapshots write the whole result set each time. The documentation warns that snapshots can create a large amount of output. Built-in destinations include filesystem, TLS, syslog, Windows Event Log, Kinesis, Firehose, and Kafka. If a remote logger remains unavailable and its RocksDB buffer fills, osquery drops logs.
macOS entitlements and remote TLS impose hard boundaries
A source-built macOS binary can run unsigned, but the es_process_events and es_process_file_events tables stay disabled. Apple requires an entitled, signed executable for those EndpointSecurity APIs. That is a meaningful limit for a security team building its own package. The interactive shell has a similar principle across platforms: permissions determine which rows and tables can reveal useful data.
Remote configuration brings its own boundary. Nodes enroll with a shared secret or client certificate, receive a node key, and present that identity on later requests. The reference TLS API is functional, but the guide describes it mainly as an example and encourages custom plugins for specific services. A failed configuration fetch can stop the client, while a failed logger causes buffered output, so server behavior is part of endpoint reliability.
The October 1 push is current, while release 5.23.1 carries security fixes
GitHub recorded 23,599 stars, a push on October 1, 2026, and 580 combined open issues and pull requests. The latest stable tag, 5.23.1, was published June 24. Its notes include fixes for two Windows heap buffer overflows, a Linux use-after-free, and temporary carve-directory permissions. Open issue 9124 asks for a release containing TLS cipher hardening already merged to the main branch, which shows why release contents matter more than repository activity alone.
The source license offers a choice between Apache-2.0 and GPL-2.0-only. That removes a common adoption obstacle, but it does not supply the fleet backend. Use the bare agent for local investigation, custom integrations, or an existing security data pipeline. Fleet is the closer answer when you need enrollment and policy management. Wazuh or Velociraptor makes more sense when the operator must act on the endpoint after finding something. Until a future sandbox clone succeeds, our missing build evidence remains part of the decision.
