A hammer can do a lot given context and intent; it can frame a house, pry open a door, or smash a person's head in.
I think the questions that need to be asked when approaching osquery cannot begin with something akin to:
"What can a hammer do compared to a wrench?"
but rather:
"I am trying to accomplish a specific task (eg. pull rusty nails out of a board), is it possible to do this with a hammer?"
For example, if you ask something like:
"Can osquery detect when a file in a specific directory has been modified?", you will receive much more productive responses.
Broad comparative or open-ended questions, necessitating exhaustive hypotheticals, accompanied by complex feature matrices and Venn diagrams are unlikely to be answered to any satisfying extent.