Forensics Osquery · AgentSecOps/SecOpsAgentKit
Investigate security incidents with SQL-based osquery
Uses osquery's SQL interface to query running processes, network connections, and persistence mechanisms across Linux, macOS, and Windows endpoints, supporting incident response, threat hunting, and forensic evidence collection.
Good for
- Hunt for suspicious processes or listening ports
- Check persistence mechanisms like cron jobs
- Collect forensic evidence during incident response
- Source repository
- AgentSecOps/SecOpsAgentKit
- Category
- Coding
Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.
A good place to start
Write an osquery query to find processes running from deleted executables on this Linux endpoint.

Make your next great thing.
Bring a question, a file, or an idea that’s not quite there yet.