I agree that having this visibility right into Osquery and not have to rely on external tools such as sysmon is the way to go.
Regarding the osq-ext-bin extension, I looked into it in the past. The extension is doing a great job on providing extra visibility on windows. The only drawback is that the extension installs a new windows kernel driver to retrieve the visibility data, which is not ideal imo for a couple of reasons (unexpected crashes, system state changed, compatibility, etc)