Brandon7CC/mac-monitor
"The missing ProcMon for macOS": Mac Monitor records Endpoint Security events and displays them for analysis. observed · 2026-08-28
Health v2 · maintenance only
80/100
- Activity 94
- Release rhythm 57
- Longevity 90
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 11
- age_days: 1267
- days_rel: 284
- days_push: 36
- n_releases_24m: 4
Adoption not part of the score
1379 stars · 65 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Mac Monitor is a stand-alone macOS application that uses Apple's Endpoint Security and System Extension APIs to collect and enrich system events such as process, file, XPC, and interprocess activity. It displays this telemetry graphically to support macOS security research, malware triage, and system troubleshooting.
Use cases
- monitor process and file events on macOS like ProcMon
- triage suspected macOS malware
- investigate XPC and interprocess communication
- troubleshoot unexpected system behavior on a Mac
- capture Endpoint Security telemetry for threat hunting
- analyze what a suspicious macOS application does at runtime
When to choose
- you need a ProcMon-equivalent for macOS with a GUI
- you are doing macOS security research or malware analysis
- you want Endpoint Security event collection without writing your own ES client
- you run macOS 13.1+ and want a free, open-source monitoring tool
When to avoid
- you need monitoring on Linux or Windows
- you cannot grant Full Disk Access or install a System Extension
- you need headless or automated telemetry collection rather than interactive GUI analysis
- you need long-term centralized event storage or SIEM integration
Facets
application · maturity active
monitoring security logging security operating-systems developer-tools endpoint-security malware-analysis process-monitor swiftui system-extension security-research macos
1 source
- readme: https://github.com/Brandon7CC/mac-monitor · fetched 2026-08-28 · 23decf77a27a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Brandon7CC/mac-monitor | main | 80 |
For agents
markdown · JSON · MCP: product_card(name="Brandon7CC/mac-monitor")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem