Documentation, source code, API references and community โ your stepping stone into the osctrl and osquery ecosystem.
The complete osctrl documentation: concepts, components, deployment guides and usage.
docs.osctrl.net โDeep dives into osctrl-tls, osctrl-api, osctrl-cli, osctrl-mcp and the operator UI.
Deploy with Docker or natively with the provisioning script, including production guidance.
Deployment docs โThe osctrl repository on GitHub โ Go services, React frontend, deployment configs and tooling. MIT licensed.
jmpsec/osctrl โThe full REST API contract for osctrl-api โ generate clients or explore endpoints.
The complete osctrl-mcp reference โ tool list, authentication model, the hosted /api/v1/mcp endpoint and client configuration examples.
The repository's architecture overview and project structure, plus the docs site source.
ARCHITECTURE.md โRelease notes, binaries and Docker images for every osctrl version.
Releases โosctrl is a security-sensitive project โ vulnerability reporting and responsible disclosure guidelines.
SECURITY.md โContributions are welcome โ fork, open a pull request, or start with an issue for larger changes.
Contributing guide โFind us in the #osctrl channel of the official osquery Slack community.
Request an auto-invite โReport bugs, request features or ask questions on the GitHub issue tracker.
GitHub issues โStar the repository, spread the word, and share how you use osctrl in production.
Star on GitHub โosctrl builds on osquery and speaks MCP โ these references pair well with it.
The SQL-powered operating system instrumentation framework by the osquery foundation.
osquery.io โDeployment, configuration and the remote API that osctrl implements as its TLS endpoint.
osquery docs โBrowse every table and column available for your queries โ osctrl ships schema metadata through 5.23.1.
Schema browser โThe open protocol behind osctrl-mcp โ how AI clients discover and call tools.
Start with the docs, or go straight to a running deployment.