osquery-extensions
kubequery
osquery-extensions | kubequery | |
---|---|---|
1 | 1 | |
257 | 87 | |
-0.4% | - | |
1.1 | 0.0 | |
about 1 year ago | over 2 years ago | |
C | Go | |
Apache License 2.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
osquery-extensions
-
Endpoint Isolation with osquery ?
It's definitely outside the scope of core osquery (oquery is intended to be a read-only tool). However, there have been efforts to use osquery extensions to allow making changes to the system state. See for example the Trail of Bits fwctl extension table that allows modifying firewall rules.
kubequery
-
An Osquery Field Guide for Log4J Defenders
osquery repo: https://github.com/osquery/osquery kubequery repo:https://github.com/Uptycs/kubequery cloudquery repo: https://github.com/Uptycs/cloudquery
What are some alternatives?
TDengine - TDengine is an open source, high-performance, cloud native time-series database optimized for Internet of Things (IoT), Connected Cars, Industrial IoT and DevOps.
cloudquery - cloudquery powered by Osquery
OSSEC - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
Fleet - Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
systeminformer - A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ http://www.windows-internals.com
prometheus-operator - Prometheus Operator creates/configures/manages Prometheus clusters atop Kubernetes
Fail2Ban - Daemon to ban hosts that cause multiple authentication errors
OSQuery - SQL powered operating system instrumentation, monitoring, and analytics.
cilium - eBPF-based Networking, Security, and Observability