osqueryi.exe

by osquery (Linux Foundation)
Endpoint Security

Sources: 300M+ executions observed in the wild.

Summary

OSQuery interactive shell. Query-based endpoint visibility tool that exposes operating system data as SQL tables. Used by security teams for endpoint investigation and compliance.

osqueryi.exe is the 161st most commonly executed Windows program in EchoTrail's dataset, observed 103,347 times across enterprise environments. It typically runs from C:\Program Files (x86)\Msp Agent\components\generic-asset-interrogator\0.2.13\osquery\windows_x64\v5.12.1 and it is most often launched by generic-asset-interrogator.exe.

Get this in your tools

The same record for osqueryi.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/osqueryi.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

161st
most commonly executed Windows program
103,347
observed endpoint executions

Behavior

Top Paths

  • C:\Program Files (x86)\Msp Agent\components\generic-asset-interrogator\0.2.13\osquery\windows_x64\v5.12.1100%
  • C:\ProgramData\...<0.01%

Top Hashes (SHA256)

  • d36ce2015da08b6cb638f78516123002984640b9d0237cb7c0e417691096637d100%
  • fbf4e6679d3c5b1b033a5dc707f3a6402346b55fd8baec99e60c22ee57272635<0.01%

Process Ancestry

Top Grandparents

Top Parents

Security Analysis

What does osqueryi.exe normally do?

Part of osquery (Linux Foundation) software.

When is osqueryi.exe suspicious?

Running from unexpected paths.

How do attackers abuse osqueryi.exe?

Not commonly abused.

Detection guidance

No specific detection needed.

False positive notes

Normal operation.

Ask Rocky about osqueryi.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for osqueryi.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.