Documentation, source code, API references and community โ your stepping stone into the osctrl and osquery ecosystem.
The complete osctrl documentation: concepts, components, deployment guides and usage.
docs.osctrl.net โDeep dives into osctrl-tls, osctrl-api, osctrl-cli and the operator UI.
Deploy with Docker or natively with the provisioning script, including production guidance.
Deployment docs โThe osctrl repository on GitHub โ Go services, React frontend, deployment configs and tooling. MIT licensed.
jmpsec/osctrl โThe full REST API contract for osctrl-api โ generate clients or explore endpoints.
The repository's architecture overview and project structure, plus the docs site source.
ARCHITECTURE.md โRelease notes, binaries and Docker images for every osctrl version.
Releases โosctrl is a security-sensitive project โ vulnerability reporting and responsible disclosure guidelines.
SECURITY.md โContributions are welcome โ fork, open a pull request, or start with an issue for larger changes.
Contributing guide โFind us in the #osctrl channel of the official osquery Slack community.
Request an auto-invite โReport bugs, request features or ask questions on the GitHub issue tracker.
GitHub issues โStar the repository, spread the word, and share how you use osctrl in production.
Star on GitHub โosctrl builds on osquery โ these references pair well with it.
The SQL-powered operating system instrumentation framework by the osquery foundation.
osquery.io โDeployment, configuration and the remote API that osctrl implements as its TLS endpoint.
osquery docs โBrowse every table and column available for your queries โ osctrl ships schema metadata through 5.23.1.
Schema browser โStart with the docs, or go straight to a running deployment.