Packages and tarballs

These packages are built and signed by the osquery development team. They are mostly universal and use a minimal number of run-time library dependencies. This means the binaries are abnormally big (~20MB).

For release notes please visit https://github.com/facebook/osquery/releases.

Downloads

~ $ ls osquery-latest/ | ./hashthem.sh

https://pkg.osquery.io/linux/osquery-2.9.0_1.linux_x86_64.tar.gz

94684419037709386dcaa42e5b519e36370bb640d230f8d3852fb66fe1e23bb0

https://pkg.osquery.io/deb/osquery_2.9.0_1.linux.amd64.deb

898cd16b1df9bc7aeef91542611b0e209ff7e8b0aae273fafbf5ef9f77ed0037

https://pkg.osquery.io/darwin/osquery-2.9.0.pkg

83541f1241a8b92eee9cfa3dd32f384a2fd1c7ca639f138e3ec716e7ec5177a3

https://pkg.osquery.io/rpm/osquery-2.9.0-1.linux.x86_64.rpm

411ec4e7d84ed65e3915993824e424e54aeb358e60596059b268b27f3720b5e3

Build osquery

To take advantage of the most current features and join the osquery development community we like to suggest building from source! Head to GitHub clone and compile.

Build Instructions

$ git clone http://github.com/facebook/osquery.git

$ cd osquery

$ make deps

$ make -j 8

$ ./build/<platform>/osquery/osqueryi

Install yum repository

We publish osquery to a yum repository. The RPMs have extremely few dependencies and should work on *most* x86_64 Linux operating systems. You may install the "auto-repo-add" RPM or add the repository target.

yum Install

$ curl -L https://pkg.osquery.io/rpm/GPG | sudo tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery

$ sudo yum-config-manager --add-repo https://pkg.osquery.io/rpm/osquery-s3-rpm.repo

$ sudo yum-config-manager --enable osquery-s3-rpm

$ sudo yum install osquery

Install apt repository

We publish osquery to an apt repository. The DEBs have extremely few dependencies and should work on *most* x86_64 Linux operating systems.

apt Install

$ export OSQUERY_KEY=1484120AC4E9F8A1A577AEEE97A80C63C9D8B80B

$ sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys $OSQUERY_KEY

$ sudo add-apt-repository "deb [arch=amd64] https://pkg.osquery.io/deb deb main"

$ sudo apt-get update

$ sudo apt-get install osquery

Windows Choco Package

We recommend installing and deploying Windows support using chocolatey. Please let us know if your enterprise could make use of other package formats.

Windows Install

C:\> choco install osquery

Debug packages (also in package repos)

These packages contain debug binaries or the debuginfo symbols. The packages are available in yum/apt using the respective debug name.

Debug Downloads

~ $ ls osquery-debug-latest/ | ./hashthem.sh

https://pkg.osquery.io/deb/osquery-dbg_2.9.0_1.linux.amd64.deb

a4b3c43362b1aff39607b942e81f10d50a0daa51bb32138c9969b1fb7a1c0fdb

https://pkg.osquery.io/darwin/osquery-debug-2.9.0.pkg

3485bbf23d1e11e1bb2406f61b0f087f18b8f1d69b32e41a3c20bb79a1621905

https://pkg.osquery.io/rpm/osquery-debuginfo-2.9.0-1.linux.x86_64.rpm

8ea330e12787f392b3989cb3cb4aaa4c0d2e6ccc60f361d5fa5b6499411d2af0

Previous Releases

We continue to host previous releases of osquery and make them available for download. These are our last three releases for Linux and Darwin.

Previous Releases

~ $ ls osquery-previous-linux/ | ./hashthem.sh

https://pkg.osquery.io/linux/osquery-2.8.0_1.linux_x86_64.tar.gz

ec84b5128769f09a5513bc1d136504ca2f805580b73d602e73d2a90b1a87c80a

https://pkg.osquery.io/linux/osquery-2.7.0_1.linux_x86_64.tar.gz

fdc74b15161a7dacb74dcff7d25a433b838eac3738f5c80be2926d43eb52637a

https://pkg.osquery.io/linux/osquery-2.6.1_1.linux_x86_64.tar.gz

dca2a19bac2d34598e19101989bf53df8dbfc0c071fd2889fc57f0506ad237c5

 

~ $ ls osquery-previous-darwin/ | ./hashthem.sh

https://pkg.osquery.io/darwin/osquery-2.8.0.pkg

642bd56809ea4079263fb8a9be3c9c7b53168c9676882ccd84b013f9c997cbe0

https://pkg.osquery.io/darwin/osquery-2.7.0.pkg

e5eaf91b5582252f136476391cdd17985cc614536f964f38ddf7eb9cb69d0213

https://pkg.osquery.io/darwin/osquery-2.6.1.pkg

4dc6bee0360fc187bd2b0a9c63907280bb5203812f06c5516e644adcbfa7b90e