Endpoint Forensics - Osquery
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**Value proposition**
Enable analysts and responders to perform deep forensic analysis directly from Elastic Security Osquery Manager by enhancing osquery-based endpoint visibility, performance, and usability. This includes expanding forensic coverage via new osquery tables (browser history, amcache, jumplists, MFT) and improving the in-product osquery interface with new out-of-the-box queries and packs to streamline investigative workflows as well as new scheduler (date & time configuration) and a export results function.
**Expected outcome**
- Elastic Security users can run faster and more intuitive forensic queries through a redesigned osquery UI, benefiting from improved performance, richer data, and reduced query complexity.
- Analysts will be able to access critical forensic artifacts (new tables: browser history, amcache, jumplists, MFT) without switching tools, accelerating triage and investigation within the Elastic platform.
- New scheduling with date and time configuration for packs in addition to current scheduling intervals.
- Analyst will be able to export osquery results in CSV and/or JSON format.
**Key user stories / use cases**
- As an incident responder, I want to query forensic artifacts like Amcache or browser history from the Elastic UI to determine process execution sources.
- As a forensic analyst, I want prebuilt queries for common artifacts so I can focus on analysis rather than syntax.
- As a SOC investigator, I want faster and more reliable osquery execution across large environments to support time-sensitive incident response.
- As a threat hunter, I want to pivot from an alert to forensic context directly, without needing external forensic tools.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.