Skip to content

osquery

Forensics & Incident Response

A SQL‑powered framework for querying and monitoring operating system data on Linux, macOS, and Windows

C++ Latest 5.23.1 · 1mo ago Security brief →

Features

  • Exposes OS state as relational tables accessible via SQL queries
  • Supports ad‑hoc querying with osqueryi and scheduled monitoring with osqueryd
  • Extensible plugin architecture for custom tables and data sources

Recent releases

View all 3 releases →
Upgrade now
5.23.1 Security relevant

Heap overflow + use‑after‑free fixes

Upgrade now
5.23.0 Mixed
RCE / SSRF Dependencies

Vulnerability fixes + expat upgrade

Upgrade now
5.22.1 Mixed
Breaking upgrade

macOS fix + toolchain + carver enhancements

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
23,402
Forks
2,581
Languages
C++ C CMake

Install & Platforms

Platforms
linux macos windows

Community & Support

Beta — feedback welcome: [email protected]