Software Alternatives & Reviews

Samhain VS osquery

Compare Samhain VS osquery and see what are their differences

Samhain logo Samhain

The Samhain host-based intrusion detection system (HIDS) provides file integrity checking and log...

osquery logo osquery

Utilities, Application Utilities, and Desktop Querying Tools
  • Samhain Landing page
    Landing page //
    2021-10-07
  • osquery Landing page
    Landing page //
    2021-08-21

Samhain videos

Samhain - Initium Review - Track By Track Analysis

More videos:

  • Review - Samhain Review - Puppet Combo's Latest Experience
  • Review - Samhain - November Coming Fire - Review and Analysis

osquery videos

Kolide & OSQuery: How to Build Solid Queries and Packs for Detection and Threat Hunting

More videos:

  • Review - Using osquery & MITRE ATT&CK to Provide Analytics for Incident Response and Threat Hunting
  • Review - How Stripe is actioning the osquery API at scale [osquery@scale]

Category Popularity

0-100% (relative to Samhain and osquery)
Security & Privacy
65 65%
35% 35
Cyber Security
69 69%
31% 31
Monitoring Tools
42 42%
58% 58
Tool
100 100%
0% 0

User comments

Share your experience with using Samhain and osquery. For example, how are they different and which one is better?
Log in or Post with

Social recommendations and mentions

Based on our record, osquery seems to be more popular. It has been mentiond 18 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

Samhain mentions (0)

We have not tracked any mentions of Samhain yet. Tracking of Samhain recommendations started around Mar 2021.

osquery mentions (18)

  • Show HN: Natural Language to SQL "Text-to-SQL" API by Dataherald
    The largest we have successfully deployed is on the OSQuery schema https://osquery.io/ which is 277 tables and lots of business context (malwares, vulnerabilities, Windows registry keys, etc). - Source: Hacker News / 3 months ago
  • Alternative to Endpoint Protector?
    From a self hosted standpoint OSQuery or Wazuh are your best bets for monitoring USB devices. Windows makes blocking really challenging and I’m not aware of any “free” solutions that attempt it. Source: 12 months ago
  • Firewall rules beyond "deny incoming, enable only the ports that you need"
    Configure auditd to monitor host activity: https://izyknows.medium.com/linux-auditd-for-threat-detection-d06c8b941505 or osquery: https://osquery.io/ (or similar software: filebeat for example). Source: about 1 year ago
  • Best Websites For Coders
    OS Query : Easily ask questions about your Linux, Windows, and macOS infrastructure. - Source: dev.to / over 1 year ago
  • Tool that let you know see EXE file on multiple PC?
    Osquery + Fleet. https://osquery.io/ https://fleetdm.com/, using the two allows you to build a query to answer what ever questions you (or an auditor) might have about your environment. Source: over 1 year ago
View more

What are some alternatives?

When comparing Samhain and osquery, you can also consider the following products

Suricata - Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine.

Tripwire - Open Source Tripwire software is a security and data integrity tool useful for monitoring and...

SonicWall Capture Advanced Threat Protection - SonicWall Capture Advanced Threat Protection is a new cloud-based sandbox service that helps to provide continuous security against complex threats by leveraging intelligence and automation to proactively protect organizations from advanced attacks,…

Ossec - OSSEC is an Open Source Host-based Intrusion Detection System.

Zeek - Buy and sell gift vouchers

AIDE - AIDE (Advanced Intrusion Detection Environment) is a file and directory integrity checker.