Facebook announced on Tuesday the availability of an osquery version that can be used by security teams to quickly identify and analyze threats on their Windows networks.
Osquery is an instrumentation framework designed to allow users to easily and efficiently explore their operating system via SQL-based queries. Basically, osquery exposes the operating system as a relational database where processes, network connections, loaded kernel modules, hardware events and browser plugins are represented in SQL tables that can be easily queried.
Leave a reply