Osquery is an open-source system monitoring tool that uses SQL to expose data related to a device’s operating system as a relational database.
Osquery works on Windows, macOS, and Linux.
osquery
0001-01-01
Osquery is an open-source system monitoring tool that uses SQL to expose data related to a device’s operating system as a relational database.
Osquery works on Windows, macOS, and Linux.
Linux Persistence: atd
2025-04-01 DFIR CTF linux persistence at atd
Linux Persistence: SSH
2025-03-29 DFIR CTF SSH hardening hunting persistence linux persistence hunting hardening SSH PAM