osquery
Osquery Python API
Decision gist · record as of 2026-08-14
Yes, if you are already using osquery and need Python bindings to extend it or query it programmatically. The low install friction and permissive license are favorable. However, be aware that maintenance is dormant—no active development or bug fixes are expected—and the classifiers only list Python up to 3.6, so compatibility with newer Python versions is unverified. Use it for stable, established osquery deployments, not for new projects expecting ongoing support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with a pure-Python wheel distribution.
- Maintenance is dormant—last release was 751 days ago—so expect no active bug fixes or feature development, though the package is marked Production/Stable.
License · maintenance · safety
BSD (permissive) — BSD permissive license means you can use, modify, and distribute this package with minimal restrictions, provided you retain the license notice.
last release 2024-07-24 (751 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 231,903 downloads/mo, #9,077 on PyPI
Alternatives
Verify before relying
pip install osquery
import osquery
instance = osquery.SpawnInstance()
instance.open()
result = instance.client.query("select timestamp from time")- Whether pywin32 is required on non-Windows platforms or is a conditional dependency
- Current compatibility with Python versions newer than 3.6 (classifiers list only up to 3.6)
- Whether the package works with modern osquery versions released after the last Python binding update
What it is and what it does
osquery-python is the official Python API for osquery, which exposes an operating system as a queryable relational database. It provides two main capabilities: creating custom osquery extensions by implementing table plugins in Python, and executing SQL queries against osquery instances (either spawned ephemeral processes or existing osqueryd daemons) via Thrift bindings.
The package depends on thrift for RPC communication, future for Python 2/3 compatibility, and pywin32 for Windows support. It is designed for system administrators and security engineers who want to extend osquery's functionality or integrate osquery queries into Python applications. The dormant maintenance status (751 days since last release) means the package is stable but receives no active development.
Use it for
- Build custom osquery table plugins in Python to expose internal APIs or proprietary data as queryable tables.
- Execute SQL queries against a running osqueryd daemon from a Python application to gather system state or security telemetry.
- Spawn ephemeral osquery instances from Python for one-off or batch system queries without managing a separate osquery process.
- Integrate osquery into Python-based security monitoring or incident response workflows via the Thrift client API.
- Extend osquery with Python logic for specialized hardware events, file hashing, or custom system introspection.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using osquery and need Python bindings to extend it or query it programmatically.
The low install friction and permissive license are favorable. However, be aware that maintenance is dormant—no active development or bug fixes are expected—and the classifiers only list Python up to 3.6, so compatibility with newer Python versions is unverified. Use it for stable, established osquery deployments, not for new projects expecting ongoing support.
Install
osquery on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Maintenance is dormant—last release was 751 days ago—so expect no active bug fixes or feature development, though the package is marked Production/Stable.
License in practice
BSD permissive license means you can use, modify, and distribute this package with minimal restrictions, provided you retain the license notice.
Quickstart
pip install osquery
import osquery
instance = osquery.SpawnInstance()
instance.open()
result = instance.client.query("select timestamp from time")
Verify before relying
- Whether pywin32 is required on non-Windows platforms or is a conditional dependency
- Current compatibility with Python versions newer than 3.6 (classifiers list only up to 3.6)
- Whether the package works with modern osquery versions released after the last Python binding update
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesthriftfuturepywin32 |
| Maintenance | Dormant 751 days since the last release |
| First released | |
| Downloads | 231,903 / month, #9,077 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: System AdministratorsLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.6Topic :: Security |
Evidence: osquery-3.1.1-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “osquery python bindings”
- osqueryPython bindings for creating osquery extensions and querying osquery…
- PyQt5-sipPyQt5-sip provides the runtime support module for PyQt5 bindings,…
- PyGObjectPyGObject provides Python bindings for GObject-based libraries such…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also dirsql · aiosql · agate-sql · sqlalchemy-solr · django-query-builder · django-sql-explorer · sqltap · sqlglotc · hmsclient · pymssql