
Endpoint Security (Antivirus/EPP)

Exposes operating system information as a relational database queryable with SQL, making system interrogation accessible to analysts.
Event-based tables capture system changes in real-time including file modifications, process launches, and network connections.
Monitors specified files and directories for changes with hashing and attribute tracking for detecting unauthorized modifications.
Consistent SQL interface across Windows, macOS, Linux, and FreeBSD enabling unified fleet querying regardless of OS.
Gathers detailed performance data including CPU, memory, disk, and network statistics for capacity planning and anomaly detection.
Pre-built queries assess security configurations against benchmarks like CIS with continuous compliance monitoring capabilities.
Innovative SQL interface for system information
Fully open source with active community
Works across Windows, macOS, and Linux
Lightweight with minimal system impact
Easy integration with other security tools
Visibility tool rather than complete EDR solution
Limited automated response capabilities
Requires SQL and system knowledge
Requires additional tools for fleet management
Be the first to share your experience with Osquery.
Reduce costs and increase revenue with OpenFrame innovative open source solutions. Coming soon…