Yeah you'll want to use osqueryd for that, however we don't have ms granularity, it's second granularity, and many of the tables aren't performant enough to be able to get data every second. What we've had success with in the past is using the Windows event logging pipeline to get data out. There's a few issues open to try and build out event publisher tables for process auditing and network socket auditing, but these aren't there yet