osquery is an open-source operating system instrumentation framework. It offers a high-performance relational database interface and SQL-based querying capabilities to help users explore live endpoint telemetry. With a focus on efficiency and visibility, it streamlines infrastructure monitoring for security and IT teams.
identifier "io.osquery.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "3522FA9PXF"