Software Alternatives & Reviews

osquery VS Samhain

Compare osquery VS Samhain and see what are their differences

osquery logo osquery

Utilities, Application Utilities, and Desktop Querying Tools

Samhain logo Samhain

The Samhain host-based intrusion detection system (HIDS) provides file integrity checking and log...
  • osquery Landing page
    Landing page //
    2021-08-21
  • Samhain Landing page
    Landing page //
    2021-10-07

osquery videos

Kolide & OSQuery: How to Build Solid Queries and Packs for Detection and Threat Hunting

More videos:

  • Review - Using osquery & MITRE ATT&CK to Provide Analytics for Incident Response and Threat Hunting
  • Review - How Stripe is actioning the osquery API at scale [osquery@scale]

Samhain videos

Samhain - Initium Review - Track By Track Analysis

More videos:

  • Review - Samhain Review - Puppet Combo's Latest Experience
  • Review - Samhain - November Coming Fire - Review and Analysis

Category Popularity

0-100% (relative to osquery and Samhain)
Security & Privacy
34 34%
66% 66
Monitoring Tools
58 58%
42% 42
Cyber Security
30 30%
70% 70
Tool
0 0%
100% 100

User comments

Share your experience with using osquery and Samhain. For example, how are they different and which one is better?
Log in or Post with

Social recommendations and mentions

Based on our record, osquery seems to be more popular. It has been mentiond 18 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

osquery mentions (18)

  • Show HN: Natural Language to SQL "Text-to-SQL" API by Dataherald
    The largest we have successfully deployed is on the OSQuery schema https://osquery.io/ which is 277 tables and lots of business context (malwares, vulnerabilities, Windows registry keys, etc). - Source: Hacker News / 3 months ago
  • Alternative to Endpoint Protector?
    From a self hosted standpoint OSQuery or Wazuh are your best bets for monitoring USB devices. Windows makes blocking really challenging and I’m not aware of any “free” solutions that attempt it. Source: 12 months ago
  • Firewall rules beyond "deny incoming, enable only the ports that you need"
    Configure auditd to monitor host activity: https://izyknows.medium.com/linux-auditd-for-threat-detection-d06c8b941505 or osquery: https://osquery.io/ (or similar software: filebeat for example). Source: about 1 year ago
  • Best Websites For Coders
    OS Query : Easily ask questions about your Linux, Windows, and macOS infrastructure. - Source: dev.to / over 1 year ago
  • Tool that let you know see EXE file on multiple PC?
    Osquery + Fleet. https://osquery.io/ https://fleetdm.com/, using the two allows you to build a query to answer what ever questions you (or an auditor) might have about your environment. Source: over 1 year ago
View more

Samhain mentions (0)

We have not tracked any mentions of Samhain yet. Tracking of Samhain recommendations started around Mar 2021.

What are some alternatives?

When comparing osquery and Samhain, you can also consider the following products

Tripwire - Open Source Tripwire software is a security and data integrity tool useful for monitoring and...

Suricata - Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine.

Ossec - OSSEC is an Open Source Host-based Intrusion Detection System.

SonicWall Capture Advanced Threat Protection - SonicWall Capture Advanced Threat Protection is a new cloud-based sandbox service that helps to provide continuous security against complex threats by leveraging intelligence and automation to proactively protect organizations from advanced attacks,…

AIDE - AIDE (Advanced Intrusion Detection Environment) is a file and directory integrity checker.

Zeek - Buy and sell gift vouchers