In a recent blog post, we discussed some of the issues with proprietary agents and the challenges they pose to enterprises. For example, most security solutions deploy separate and proprietary agents for audit and cloud compliance, with threat hunting tools or vulnerability scanning software, and incident response.
Solution silos with proprietary agents result in significant performance issues, escalating licensing costs, conflicts with other services running on the endpoints, maintenance headaches, difficulties with upgrades, and certification issues.
Moreover, it is difficult for most enterprises to break away from this paradigm, resulting in an array of point solutions implemented to cover the desired security functions across varied computing environments.
Because of this, most enterprises suffer from three main challenges in addition to agent fatigue:
Additionally, the irony of this strategy is that using multiple proprietary agents likely increases vulnerability in the long run.
Instead of the siloed, “one agent per function” approach, engineers at Facebook decided to create an open, universal agent that could extract and normalize data from any operating system across a variety of computing environments. They called it osquery and in 2014 started an open source project on GitHub that has attracted well over 200 talented contributors to-date.
In addition to the ability to normalize system data and expose it as a relational database, osquery also uses SQL, one of the most popular and widely utilized database query languages. This means that you can now ask the same question, in the same way, across any mix of operating systems.
Osquery offers a disruption to and rethinking of the endpoint agent and security metrics using the structured approach of SQL with tables. With osquery, you have a single agent and an open universal source of tabular data that can be applied to solve a broad range of security use cases, accessed through a single interface via a standard query language.
Analyst firms, like 451 Research, have also taken notice of osquery and its unique placein the endpoint and cloud security markets with senior information security analyst Fernando Montenegro sharing, “Osquery is a very powerful co
Osquery introduces the opportunity for collaboration across teams, eases learning curves, and can begin addressing the challenge of reducing the complexity of security infrastructure.
However, to fully realize the potential of osquery, organizations still need:
We see this as a tremendous opportunity - harnessing the potential of osquery and delivering it as a robust enterprise-grade security analytics platform that addresses security functions across the enterprise. This is much like the approach Salesforce adopted to address cross-functional business operations.
Salesforce took the business operations market by storm - translating broad and complex business problems across sales, marketing, finance, and customer success into solutions using SQL to extract and then present data in meaningful ways. Inspired equally by the Salesforce approach and the challenges of today’s security practitioners, we have implemented a holistic approach using osquery and SQL to power the Uptycs Security Analytics Platform.
Our vision is to provide a cross-operating system solution for fleet visibility, intrusion detection, vulnerability management, and audit/compliance by providing meaningful views of data using SQL.
We believe this addresses the four most salient pain points of the fragmented security space:
Fernando Montenegro of 451 Research shares a further observation that, “The increased popularity of osquery as an open source agent may indicate what the future of endpoint security could look like: organizations collaborating on technology that address a wider variety of their security needs. Uptycs is betting on osquery for upending endpoint security - their combination of open source agent with cloud-based analytics opens up a number of possibilities.”
(Read more in the exclusive 451 Research Market Impact report: “
Uptycs emerges from stealth betting on SQL-based osquery for upending endpoint security.”)
We are excited to continue working with organizations of varying size and exploring ways to enable the fastest path to osquery value. Sometimes this means starting with a focused use case and expanding outward as the broader value of the Uptycs Security Analytics Platform is recognized. Sometimes it is a more rapid and expansive adoption of osquery for several security use cases.
We’d love to hear about your experience with osquery and the opportunities you see for how it can help deliver on the promise of upending endpoint visibility and addressing cloud workload security and monitoring.
Learn more about osquery: