osquery

Reading Time: < 1 minute

Last Updated: 5/21/2024

This is my landing page for OSQuery. Which is described as an operating system instrumentation framework for Windows, OS X (macOS), and Linux

Introduction – Download agent. Basic Queries

mounts – This post talks about the “mount” table/schema specifically.

Misc – Various smaller pieces which discuss either osquery schema, table, or components.

Python – Using python to call “osquery” module.