From day-to-day fleet visibility to deep incident response, osctrl turns your osquery deployment into an operational security platform.
Know exactly what is running across your infrastructure. Every node enrolled with osctrl reports in over the osquery TLS remote API, giving you a live inventory of your fleet.
Benefit: a single source of truth for what's deployed, where it is, and whether it's healthy — without agents beyond osquery itself.
Ask any question of any endpoint, in SQL, right now. Distributed on-demand queries let you hunt for indicators across the whole fleet or a targeted subset of nodes.
Benefit: reduce the time between "we think we're affected" and "here is the list of affected hosts" from days to minutes.
When something goes wrong, osctrl gives responders direct, controlled access to the evidence — without SSH keys or remote desktop sessions.
pwd, cd, ls, stat, ps, sql and more, backed by osquerygetBenefit: responders collect artifacts and inspect hosts safely — read-only, permission-checked and fully audited.
Continuously measure the security posture of your fleet using scheduled queries, and surface the results directly in the operator UI.
Benefit: evidence for auditors and dashboards for engineers, generated from the same osquery data you already collect.
Everything an operator can do in the UI is available programmatically. osctrl is built API-first, so it slots into your existing tooling.
osctrl-api) with JWT authentication and an OpenAPI specificationosctrl-cli for scripting, CI/CD and administrationBenefit: treat your endpoint telemetry as infrastructure — provisioned, queried and monitored by code.
Separate business units, platforms or trust zones into isolated environments, each with its own enrollment secrets, configuration and query schedules.
Benefit: one osctrl deployment serves your whole organization while keeping teams and fleets cleanly separated.
Deploy osctrl in minutes with Docker and see it with your own fleet.