skills/smithery.ai/forensics-osquery

forensics-osquery

Installation
SKILL.md

osquery Forensics & Incident Response

Overview

osquery transforms operating systems into queryable relational databases, enabling security analysts to investigate compromises using SQL rather than traditional CLI tools. This skill provides forensic investigation workflows, common detection queries, and incident response patterns for rapid evidence collection across Linux, macOS, and Windows endpoints.

Core capabilities:

  • SQL-based system interrogation for process, network, file, and user analysis
  • Cross-platform forensic artifact collection (Linux, macOS, Windows)
  • Live system analysis without deploying heavyweight forensic tools
  • Threat hunting queries mapped to MITRE ATT&CK techniques
  • Scheduled monitoring with osqueryd for continuous detection
  • Integration with SIEM and incident response platforms

Quick Start

Interactive Investigation (osqueryi)

Installs
1
First Seen
Apr 6, 2026
forensics-osquery from smithery.ai