Skip to content

Process Monitor Library (based on Apple's new Endpoint Security Framework)

License

Notifications You must be signed in to change notification settings

kitokyo/ProcessMonitor

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ProcessMonitor

Process Monitor Library (based on Apple's new Endpoint Security Framework)

It captures process start, fork, and exit events, providing:

  • pid
  • path
  • ancestory
  • arguments
  • code-signing information

Read More:
For more details read: "Writing a Process Monitor with Apple's Endpoint Security Framework".

To Support:
❤  Love this product or want to support it? Please check out my patreon page :)

Mahalo!
This product is supported by the following "Friends of Objective-See":
🥇CleanMyMac X
🥈Malwarebytes / Airo AV
🥉SmugMug / Guardian Mobile Firewall / SecureMac / Sophos / SentinelOne / Digital Guardian / Trail of Bits / CyberArk / Halo Privacy

About

Process Monitor Library (based on Apple's new Endpoint Security Framework)

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Objective-C 100.0%