Why do I like OSQuery?

1 min read
Mainly because it let's me leverage my knowledge of SQL to dig through various boxes without having to learn hundreds of tools or archaic API's to get the job done. Nowhere has this been more obvious than in security response, where hunting for Indicators Of Compromise is normally a very tough challenge, but with OSQuery is relatively easy. Especially when you have well authored query tool kits like these:
0
Subscribe to my newsletter
Read articles from gatewaynode directly inside your inbox. Subscribe to the newsletter, and don't miss out.
Written by
