Forensics Osquery · AgentSecOps/SecOpsAgentKit

Investigate security incidents with SQL-based osquery

Uses osquery's SQL interface to query running processes, network connections, and persistence mechanisms across Linux, macOS, and Windows endpoints, supporting incident response, threat hunting, and forensic evidence collection.

Good for

  • Hunt for suspicious processes or listening ports
  • Check persistence mechanisms like cron jobs
  • Collect forensic evidence during incident response
Category
Coding

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Write an osquery query to find processes running from deleted executables on this Linux endpoint.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.