Dhruv Rathod

01/21/2022, 6:28 AM
Hi everyone, I am trying to create an extension using cpp which communicates with the osquery via thrift api(for live querying). Any suggestions where should I start from, and is there any simple way to install the osquery library for it on windows, like vcpkg?

Mike Myers

01/21/2022, 7:59 AM
Hi Dhruv. You can check out the #extensions channel here, study the example extensions, or the extensions by Trail of Bits
The process of building your extension is explained in the docs but it's not as easy as installing a developer library.

Dhruv Rathod

01/21/2022, 10:31 AM
Yeah, it seems so 😛. The examples and trail of bits extensions seem great though. Thanks for your help, Mike! 😄
💯 1