> allows your junior sysadmins to take down all your machines at once or cause mystery performance blips that someone else has to diagnose for a year
Sounds like you have extremely poor administrative management of your computer systems.
> allows your junior sysadmins to take down all your machines at once or cause mystery performance blips that someone else has to diagnose for a year
Sounds like you have extremely poor administrative management of your computer systems.
Case in point, a simple "select * from processes" takes a solid 3 seconds of kernel time on my laptop.
Now you might say, "well that's clearly a dumb idea because osquery certainly relies on vtab's colUsed field to avoid querying all sorts of expensive stuff when it doesn't have to so you really should only query what you need" and that's of course 100% true. But it's also a senior developer thought. Easy to see how an inexperienced person might make mistakes like this with any one of the dozens or hundreds of tables offered by osquery and cause performance issues.
In terms of security, well it is clearly a kitchen sink project (there's a prometheus client in there, for example: https://osquery.io/schema/5.11.0/#prometheus_metrics), so there's a huge breadth of interfaces it talks to and files controlled by all sorts of people it parses, and the default does seem to be privileged usage, which is the general ballpark where AV engines and their highly dubious track record live.
The formula osquery uses to report performance: https://github.com/fleetdm/fleet/issues/16123
The raison d'etre of this thing is to allow interactive ad hoc exploration of large-scale systems. It is, in other words, a thoroughly bad idea.
Contributions: https://github.com/osquery/osquery