Download osquery Mac 4.9.0 – Download Free

Download osquery Mac 4.9.0 – Download Free

Download Free osquery Mac 4.9.0 – Download

Run queries manually on your system or schedule regular inspections to detect possible intrusions or infrastructure-related issues

New features in osquery 4.9.0:

  • new function:
  • Add file system logrotate function (#7015)
  • Add non-functional EndpointSecurity-based process events to macOS (code signing needs to be updated in 5.0) (#7046)

Read the full change log

Inquire It is a framework that allows you to run queries on the operating system through the shell console, and may detect intrusion attempts and other problems. The tool treats the operating system as a high-performance relational database, so you can collect data with the help of SQL queries.

An easy-to-install solution that keeps a close eye on your infrastructure

The osquery tool can be deployed via the command line, using the Homebrew package installer, or with the help of pre-built binaries. The next step is to start osquery in standalone mode through the terminal and enter the query.

Considering that the osquery software package also deploys the osqueryd monitoring daemon with integrated scheduling capabilities. After the user configures the service correctly, it can automatically query the system status and record the result.

Monitor changes in the state of the infrastructure

osquery provides a SQL interface for exploring your operating system and collecting centralized information about various parameters, from login users and password changes to connected USB devices, abnormal security settings, and so on.

In addition to detecting possible security issues (for example, you do not know the active listening port), osquery can also help you diagnose and resolve performance issues.

Make sure to check the API table available online, which lists all the tables and types available in the osqueryi shell. At the same time, you can consult online resources featuring SQL grammar.

Use SQL interface to query system status

osquery treats the operating system as a relational database and provides command-line tools for running SQL queries to extract information about the status of various parameters.

In addition, osquery comes with a daemon tool that can be configured to automatically run queries and record the results to help you detect security or performance issues.

Submit

Infrastructure query monitoring system activity detection intrusion infrastructure query monitoring system