osqueryi.exe
Sources: 300M+ executions observed in the wild.
Summary
OSQuery interactive shell. Query-based endpoint visibility tool that exposes operating system data as SQL tables. Used by security teams for endpoint investigation and compliance.
osqueryi.exe is the 161st most commonly executed Windows program in EchoTrail's dataset, observed 103,347 times across enterprise environments. It typically runs from C:\Program Files (x86)\Msp Agent\components\generic-asset-interrogator\0.2.13\osquery\windows_x64\v5.12.1 and it is most often launched by generic-asset-interrogator.exe.
Get this in your tools
The same record for osqueryi.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/osqueryi.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files (x86)\Msp Agent\components\generic-asset-interrogator\0.2.13\osquery\windows_x64\v5.12.1100%
- C:\ProgramData\...<0.01%
Top Hashes (SHA256)
- d36ce2015da08b6cb638f78516123002984640b9d0237cb7c0e417691096637d100%
- fbf4e6679d3c5b1b033a5dc707f3a6402346b55fd8baec99e60c22ee57272635<0.01%
Process Ancestry
Top Grandparents
- explorer.exe100%
Top Parents
- cmd.exe<0.01%
Security Analysis
What does osqueryi.exe normally do?
Part of osquery (Linux Foundation) software.
When is osqueryi.exe suspicious?
Running from unexpected paths.
How do attackers abuse osqueryi.exe?
Not commonly abused.
Detection guidance
No specific detection needed.
False positive notes
Normal operation.
Ask Rocky about osqueryi.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for osqueryi.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.