With Windows now supported, I am looking at the feasibility of replacing OSSEC with osqueryd for my local and remote Windows/Mac endpoints - specifically for HIDS capabilities. Using Kolide or Doorman for management and to aggregate the distributed query logs to the Kolide/Doorman server and then ship them to ES. Within ES/Watcher I would write a number of HIDS-type rules for alerting. Is anybody else doing this or something similar? Is there a better way to go about this? Thanks....