Packages and tarballs

These packages are built and signed by the osquery development team. They are mostly universal and use a minimal number of run-time library dependencies. This means the binaries are abnormally big (~20MB).

For release notes please visit https://github.com/facebook/osquery/releases.

Downloads

~ $ ls osquery-latest/ | ./hashthem.sh

https://pkg.osquery.io/linux/osquery-2.10.2_1.linux_x86_64.tar.gz

7871ad268bccc9a84760c365ce3f1d1832ef75e06d5d27273cb6237980c50d43

https://pkg.osquery.io/deb/osquery_2.10.2_1.linux.amd64.deb

29cf0e55d79021397d999472f619f1733b186167db30480e9015dad54211d157

https://pkg.osquery.io/darwin/osquery-2.10.2.pkg

3251f677b4735b37aa29b685225bc87aa4d906912432a595753517f298edc472

https://pkg.osquery.io/rpm/osquery-2.10.2-1.linux.x86_64.rpm

32d719fab707ce26bf8fde90fe0e17fb23c9c4ccd47e0917856aece8356a46c8

Build osquery

To take advantage of the most current features and join the osquery development community we like to suggest building from source! Head to GitHub clone and compile.

Build Instructions

$ git clone http://github.com/facebook/osquery.git

$ cd osquery

$ make deps

$ make -j 8

$ ./build/<platform>/osquery/osqueryi

Install yum repository

We publish osquery to a yum repository. The RPMs have extremely few dependencies and should work on *most* x86_64 Linux operating systems. You may install the "auto-repo-add" RPM or add the repository target.

yum Install

$ curl -L https://pkg.osquery.io/rpm/GPG | sudo tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery

$ sudo yum-config-manager --add-repo https://pkg.osquery.io/rpm/osquery-s3-rpm.repo

$ sudo yum-config-manager --enable osquery-s3-rpm

$ sudo yum install osquery

Install apt repository

We publish osquery to an apt repository. The DEBs have extremely few dependencies and should work on *most* x86_64 Linux operating systems.

apt Install

$ export OSQUERY_KEY=1484120AC4E9F8A1A577AEEE97A80C63C9D8B80B

$ sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys $OSQUERY_KEY

$ sudo add-apt-repository "deb [arch=amd64] https://pkg.osquery.io/deb deb main"

$ sudo apt-get update

$ sudo apt-get install osquery

Windows Choco Package

We recommend installing and deploying Windows support using chocolatey. Please let us know if your enterprise could make use of other package formats.

Windows Install

C:\> choco install osquery

Debug packages (also in package repos)

These packages contain debug binaries or the debuginfo symbols. The packages are available in yum/apt using the respective debug name.

Debug Downloads

~ $ ls osquery-debug-latest/ | ./hashthem.sh

https://pkg.osquery.io/deb/osquery-dbg_2.10.2_1.linux.amd64.deb

4217d086dec64e6544f6d9c613e6d39557d2f4cf343188b3ed47d926145ba7d4

https://pkg.osquery.io/darwin/osquery-debug-2.10.2.pkg

9c7b5e3ffd2082556feff124e4ac2658f2706e44edf9885d6d0d8f4273c3f26d

https://pkg.osquery.io/rpm/osquery-debuginfo-2.10.2-1.linux.x86_64.rpm

c4ae75d842340d059d4c8ee7a76085b84394a2f796fb42cfa1b2b7ffb62a08be

Previous Releases

We continue to host previous releases of osquery and make them available for download. These are our last three releases for Linux and Darwin.

Previous Releases

~ $ ls osquery-previous-linux/ | ./hashthem.sh

https://pkg.osquery.io/linux/osquery-2.10.0_1.linux_x86_64.tar.gz

dddceec84c002c46dd3cf2bc009dc8df4430e052631ff519b4665222ec018eb8

https://pkg.osquery.io/linux/osquery-2.9.0_1.linux_x86_64.tar.gz

94684419037709386dcaa42e5b519e36370bb640d230f8d3852fb66fe1e23bb0

https://pkg.osquery.io/linux/osquery-2.8.0_1.linux_x86_64.tar.gz

ec84b5128769f09a5513bc1d136504ca2f805580b73d602e73d2a90b1a87c80a

 

~ $ ls osquery-previous-darwin/ | ./hashthem.sh

https://pkg.osquery.io/darwin/osquery-2.10.0.pkg

b30499ed09ddf649d6c49b49413b71e57183e786f82e65f2b8234e1a10d4ebf7

https://pkg.osquery.io/darwin/osquery-2.9.0.pkg

83541f1241a8b92eee9cfa3dd32f384a2fd1c7ca639f138e3ec716e7ec5177a3

https://pkg.osquery.io/darwin/osquery-2.8.0.pkg

642bd56809ea4079263fb8a9be3c9c7b53168c9676882ccd84b013f9c997cbe0