Query and Monitor OS Information using osquery

Things on this page are fragmentary and immature notes/thoughts of the author. Please read with your own judgement!

  1. List all tables.

    .\osqueryi .tables

  2. Check the schema of a table (e.g., "process").

    .\osqueryi ".schema processes"

Querying System Information

.\osqueryi.exe "select * from system_info"

Querying Docker

Please refer to Manage Docker Images and Containers for more details.

Information About Network Cards

osqueryi 'select * from interface_details'

friendly_name, description and manufacturer information are not populated yet.

osqueryi 'select interface, friendly_name, description, manufacturer from interface_details'

