mrkeyoor.com_
Fri 02 Oct 14:57 UTC
Dataevaluationupdated 02 Oct 2026

osquery review

osquery turns operating-system state into SQL tables, so you can ask a laptop or server about its users, processes, ports, files, and hardware with familiar queries. It provides an interactive shell for investigation and a daemon that schedules queries and records changes across time.

Verdict

Our October 2 sandbox could not clone osquery, so this review has no install, build, or test result to balance against the documentation. Use osquery when SQL is the interface your team wants for cross-platform host evidence and you already have a plan for scheduling, enrollment, and logs. Choose Fleet when you need that operating layer, or a response platform when querying alone does not finish the job.

We ran it

Screenshot of osquery (osquery.io)

Answers from our run

Did you run osquery yourself?

No. The repository would not clone into our container, so nothing could be installed or tested. This review is written from the project's own documentation.

Who should not use osquery?

Teams that need a central console out of the box: the README points to separate fleet managers and says the osquery project does not endorse, recommend, or test them.

What are the alternatives to osquery?

Fleet, Wazuh, Velociraptor. Our October 2 sandbox could not clone osquery, so this review has no install, build, or test result to balance against the documentation.

Setup2/5Clone failed for us; fleet setup also needs config, TLS, and logs
Docs5/5Detailed shell, daemon, query, remote, logging, and build guides
Community5/523,599 stars, an October 1 push, and active issue work
Maturity5/5v5.23.1 supports three desktop OS families and ships security fixes

Who it’s for

Security teams that want the same query language across Linux, macOS, and Windows.
Incident responders who need repeatable questions about live host state.
Fleet operators prepared to manage query schedules, endpoint load, enrollment, and log collection.
Developers building custom tables or extensions around a mature C++ agent.

Who it’s NOT for

Teams that need a central console out of the box: the README points to separate fleet managers and says the osquery project does not endorse, recommend, or test them.
Buyers seeking built-in remediation or endpoint isolation: the documented core collects and reports host data rather than taking response actions.
Operators unwilling to profile every production query: the performance guide warns that poorly formed queries can damage endpoint performance.
macOS teams expecting every event table from an unsigned custom build: two EndpointSecurity tables require a signed binary with Apple's entitlement.
Release gates that require our reproduced source result: our sandbox could not clone the repository, so we have no install, build, or test evidence.

Setup reality

NOT RUN: git clone failed in our October 2, 2026 sandbox before it produced a checkout or commit. The container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. With no source tree, there was no install, build, test, dependency, or vulnerability-audit result. The supplied result gives no narrower cause for the clone failure.

The project directs most users to packaged downloads. Building from source requires Git, CMake, Python, a platform compiler toolchain, and dependencies fetched by CMake. A useful daemon deployment also needs a JSON schedule, a logger destination, and a way to manage results.

Local osqueryi use needs no daemon or server, though non-administrator queries may return fewer rows. Remote fleets add TLS endpoints, a certificate authority, enrollment secrets or client certificates, node identity, and log storage. macOS EndpointSecurity tables need an entitled, signed binary.

SQL makes host evidence approachable on 3 operating systems

osquery presents Linux, macOS, and Windows state as tables. A query can list users, find a process whose executable disappeared from disk, join listening ports to processes, or inspect file hashes. That interface is the lasting appeal: an analyst can use SQL instead of learning a different command for each operating-system subsystem. Custom tables and extensions can add data that the built-in schema does not expose.

The project has two main ways to ask those questions. osqueryi is a standalone interactive shell for one machine. osqueryd runs schedules and records how results change. The documentation's USB example runs every 60 seconds and emits a new result only when the device set changes. This makes the daemon useful for monitoring, though query design and collection still belong to the operator.

What happened when we ran it

Our sandbox clone failed on October 2, 2026 before Git produced a checkout or commit SHA. The unprivileged container had 3 CPUs, 8 GB of RAM, and no secrets. With no source tree available, the pipeline could not reach installation, compilation, tests, dependency counting, or an audit. There is no honest passing or failing build result to report.

The supplied lab record says only that git clone failed. It does not include a more specific cause, so blaming network access, authentication, repository size, or system packages would be guesswork. The public README was still available through GitHub's API and is long enough to review. Our product judgment below comes from that documentation, current repository facts, release notes, and issue activity, not from a local executable.

The shell works alone, while a fleet needs another layer

osqueryi does not connect to the daemon and does not require administrator rights. Some tables return fewer results without those rights, and event publishers are disabled by default. That makes the shell a practical investigation tool on a workstation where you can accept partial visibility. It also gives a team a safe place to shape SQL before scheduling it across thousands of endpoints.

Fleet operation is a separate engineering problem. The default daemon reads JSON configuration from the filesystem and writes JSON results locally. Remote use can add 3 HTTP endpoints for enrollment, configuration, and logging, plus a certificate authority and node credentials. Distributed queries require explicit configuration. The README also lists Fleet, Kolide, OSCTRL, and Zentral, while stating that osquery does not endorse, recommend, or test those managers.

Scheduled SQL can consume endpoint resources

The performance guide is unusually direct: poorly formed queries can damage osquery's performance guarantees. Schedules control how often a query runs, while laptops pause the daemon's interval clock during sleep. A query set tested on an always-on server can therefore behave differently on employee laptops. The project supplies a profiling script for CPU, memory, duration, and file descriptors, and recommends measuring a configuration before broad deployment.

Logging choices change the storage bill. Differential mode reports rows added or removed since the previous execution, while snapshots write the whole result set each time. The documentation warns that snapshots can create a large amount of output. Built-in destinations include filesystem, TLS, syslog, Windows Event Log, Kinesis, Firehose, and Kafka. If a remote logger remains unavailable and its RocksDB buffer fills, osquery drops logs.

macOS entitlements and remote TLS impose hard boundaries

A source-built macOS binary can run unsigned, but the es_process_events and es_process_file_events tables stay disabled. Apple requires an entitled, signed executable for those EndpointSecurity APIs. That is a meaningful limit for a security team building its own package. The interactive shell has a similar principle across platforms: permissions determine which rows and tables can reveal useful data.

Remote configuration brings its own boundary. Nodes enroll with a shared secret or client certificate, receive a node key, and present that identity on later requests. The reference TLS API is functional, but the guide describes it mainly as an example and encourages custom plugins for specific services. A failed configuration fetch can stop the client, while a failed logger causes buffered output, so server behavior is part of endpoint reliability.

The October 1 push is current, while release 5.23.1 carries security fixes

GitHub recorded 23,599 stars, a push on October 1, 2026, and 580 combined open issues and pull requests. The latest stable tag, 5.23.1, was published June 24. Its notes include fixes for two Windows heap buffer overflows, a Linux use-after-free, and temporary carve-directory permissions. Open issue 9124 asks for a release containing TLS cipher hardening already merged to the main branch, which shows why release contents matter more than repository activity alone.

The source license offers a choice between Apache-2.0 and GPL-2.0-only. That removes a common adoption obstacle, but it does not supply the fleet backend. Use the bare agent for local investigation, custom integrations, or an existing security data pipeline. Fleet is the closer answer when you need enrollment and policy management. Wazuh or Velociraptor makes more sense when the operator must act on the endpoint after finding something. Until a future sandbox clone succeeds, our missing build evidence remains part of the decision.

Alternatives

ProjectWhat it isPick it when
Fleet gh↗An open device-management platform that gives osquery a central fleet layer.pick this instead when enrollment, policies, live queries, and a web console matter more than using the bare agent.
WazuhAn endpoint security and SIEM platform with monitoring, detection, and response features.pick this instead when you want a broader security platform with alerts and response workflows.
VelociraptorA digital-forensics and incident-response agent built around its own query language.pick this instead when live response and evidence collection are the main jobs.

What people are saying

  1. [velocity-scout] osquery/osquery

Sources

  1. osquery README
  2. Using osqueryi
  3. osquery deployment configuration
  4. osquery remote interface guide
  5. osquery 5.23.1 release
  6. TLS cipher hardening release request

More data reviews

WeFlow · awesome-reasoning-generalization · rocksdb · INSLIB · HowToLiveBetter · TradeGenuis-box · the whole board →