Repository of sample queries for osquery. Submissions welcomed!
osqueryi
.tables
.schema uptime
select * from uptime;
SELECT filename, path FROM file WHERE directory LIKE '/%%' and filename LIKE '%.1234';
SELECT filename, path, mode FROM file WHERE directory == '/tmp' and mode > '0644';
SELECT filename, path, mode, size FROM file WHERE directory == '/tmp' and size > 5;
select name from apps where bundle_identifier NOT LIKE 'com.apple.%%';
select percent_remaining from battery;
select * from homebrew_packages;
select * from kernel_extensions where name NOT LIKE 'com.apple%';
select memory_type, size from memory_devices;
select * from time;