Osquery — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
October 24, 2025
Last Seen
December 16, 2025

Osquery is a technology platform tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed October 24, 2025; most recent activity December 16, 2025.

Overview

Osquery is an open-source endpoint visibility platform that exposes operating system information through a SQL-like interface, enabling scalable, real-time inventory, compliance checks, and threat hunting across Windows, macOS, and Linux endpoints. It supports data collection for detection, investigations, and security operations and integrates with SIEMs and EDR tools for rapid insights. The two provided articles focus on Security Onion's Onion AI Assistant releases and do not explicitly mention Osquery.

Related Threat Clusters

Recent Intelligence Reports

  • Security Onion 2.4.200 now available with Major Improvements for our Onion AI Assistant! — Securityonion.Blogspot · December 16, 2025
  • Security Onion 2.4.190 now available including Onion AI Assistant for Pro Customers! — Securityonion.Blogspot · October 24, 2025

CVSS v3.1 Breakdown