# Brandon7CC/mac-monitor

"The missing ProcMon for macOS": Mac Monitor records Endpoint Security events and displays them for analysis.

Repository: https://github.com/Brandon7CC/mac-monitor
Canonical: https://ross.abutalabs.com/products/mac-monitor
Language: Swift
License: BSD-3-Clause
License Family: permissive
Topics: macos, endpoint-security, swift, swiftui
Last push: 2026-07-28T20:37:27+00:00

## Health v2 (maintenance only)
Score: 80/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 94, release rhythm 57, longevity 90
- inputs: {"age_days": 1267, "days_push": 36, "days_rel": 284, "gap_med": 11, "n_releases_24m": 4}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1379, forks 65 (observed 2026-08-28T04:04:33.694935+00:00)

## What it is
Mac Monitor is a stand-alone macOS application that uses Apple's Endpoint Security and System Extension APIs to collect and enrich system events such as process, file, XPC, and interprocess activity. It displays this telemetry graphically to support macOS security research, malware triage, and system troubleshooting.

## Use cases
- monitor process and file events on macOS like ProcMon
- triage suspected macOS malware
- investigate XPC and interprocess communication
- troubleshoot unexpected system behavior on a Mac
- capture Endpoint Security telemetry for threat hunting
- analyze what a suspicious macOS application does at runtime

## When to choose
- you need a ProcMon-equivalent for macOS with a GUI
- you are doing macOS security research or malware analysis
- you want Endpoint Security event collection without writing your own ES client
- you run macOS 13.1+ and want a free, open-source monitoring tool

## When to avoid
- you need monitoring on Linux or Windows
- you cannot grant Full Disk Access or install a System Extension
- you need headless or automated telemetry collection rather than interactive GUI analysis
- you need long-term centralized event storage or SIEM integration

## Facets
- artifact type: application
- maturity: active
- function: monitoring, security, logging
- domain: security, operating-systems, developer-tools
- platform: -
- tags: endpoint-security, malware-analysis, process-monitor, swiftui, system-extension, security-research, macos

## Member repositories
- Brandon7CC/mac-monitor (main) score 80

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:33.694935+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:16.943529+00:00, confidence not recorded.
  - readme: https://github.com/Brandon7CC/mac-monitor (fetched 2026-08-28T04:04:33.694935+00:00, sha 23decf77a27a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
