Saagar Jha

(replying to Bill Mill)
@llimllib @b0rk This uses Apple’s Endpoint Security framework, rather than a kernel extension. It runs entirely in userspace! If you want to just poke around there’s a built-in tool called “eslogger” on newer versions of macOS that dumps the raw events as JSON.
1 replies →
1 replies

Bill Mill

(replying to Saagar Jha)

@saagar @b0rk eslogger is fabulous! thank you for that.

Saagar Jha

(replying to Saagar Jha)
@llimllib @b0rk This is a list of the events it tracks and the data it collects for each: https://developer.apple.com/documentation/endpointsecurity/event_types