@the_drow adding in a new parser just tells osquery how to get that new fields out of the JSON configuration, so if you want to extend values which are present in the config you fetch over TLS or from disk, you could add a new parser to expose values in your code. However, not totally sure that’s what you want? For the one-shot queries, you said you want to add a new configuration file, I think this is how @obelisk configured ATC, so his parsers might be good inspiration, but I believe the whole config that osquery gets ends up as one large Json object, so you should be able to just add your new options in the generic config, tls or file, and add a new parser telling your code where to find it