Title
#general
d

Dhruv Rathod

01/21/2022, 6:28 AM
Hi everyone, I am trying to create an extension using cpp which communicates with the osquery via thrift api(for live querying). Any suggestions where should I start from, and is there any simple way to install the osquery library for it on windows, like vcpkg?
Mike Myers

Mike Myers

01/21/2022, 7:59 AM
Hi Dhruv. You can check out the #extensions channel here, study the example extensions, or the extensions by Trail of Bits https://github.com/trailofbits/osquery-extensions
8:01 AM
The process of building your extension is explained in the docs but it's not as easy as installing a developer library. https://osquery.readthedocs.io/en/latest/development/osquery-sdk/
d

Dhruv Rathod

01/21/2022, 10:31 AM
Yeah, it seems so 😛. The examples and trail of bits extensions seem great though. Thanks for your help, Mike! 😄