🍺 BREW Explorer

← all casks

Mac Monitor

brew install --cask mac-monitor v2.1.0

Analysis tool for security research and malware triage

53
30-day installs · #1962
200
90-day · #1735
634
365-day · #1889
1.4k
★ GitHub stars · updated 4mo ago

GitHub topics

endpoint-security macos swift swiftui

Links

Raw metadata
{
  "alternatives": [],
  "artifacts": [
    {
      "uninstall": [
        {
          "pkgutil": "com.swiftlydetecting.agent",
          "script": {
            "executable": "/Applications/Mac Monitor.app/Contents/SharedSupport/uninstall.sh",
            "must_succeed": false,
            "sudo": true
          }
        }
      ]
    },
    {
      "pkg": [
        "Mac-Monitor.pkg"
      ]
    },
    {
      "zap": [
        {
          "trash": [
            "~/Library/Application Support/Mac Monitor",
            "~/Library/Preferences/com.swiftlydetecting.agent.plist",
            "~/Library/Saved Application State/com.swiftlydetecting.agent.savedState"
          ]
        }
      ]
    }
  ],
  "auto_updates": 1,
  "categories": [],
  "deprecated": 0,
  "deprecation_reason": null,
  "desc": "Analysis tool for security research and malware triage",
  "disable_reason": null,
  "disabled": 0,
  "display_name": "Mac Monitor",
  "enrichment_fetched_at": "2026-06-20T22:46:03+00:00",
  "first_seen": "2026-06-20T00:47:34+00:00",
  "full_token": "mac-monitor",
  "github_default_branch": "main",
  "github_last_commit_at": "2026-04-07T03:11:16Z",
  "github_readme_excerpt": "## \ud83c\udf89 Welcome to \"Mac Monitor\u0027s\" official new home!\n![Feature overview](./Resources/v1.9.0/overview-graphic-v1.9.png)\n\nMac Monitor is an **advanced, stand-alone system monitoring tool tailor-made for macOS security research, malware triage, and system troubleshooting**. Leveraging Apple\u0027s Endpoint Security (ES) and System Extension APIs, it collects and enriches system events, displaying them graphically, with an expansive feature set designed to surface only the events that are relevant to you. The telemetry collected includes process, interprocess, memory, XPC, file events, and more in addition to rich metadata, allowing users to contextualize events and tell a story with ease. With an intuitive interface and a rich set of analysis features, Mac Monitor was designed for a wide range of skill levels and backgrounds to detect macOS threats that would otherwise go unnoticed. \n\n### OBTS v8.0 Presentation\n**Introducing the Next Generation of Mac Monitor**:\n* [\ud83d\udcca Slides](https://swiftlydetecting-conferences.s3.us-west-2.amazonaws.com/public/2025/OBTSv8/Introducing+the+Next+Generation+of+Mac+Monitor.pdf)\n* [\ud83d\udcfa YouTube](https://www.youtube.com/watch?v=h_i_H6RzzHA)\n\n\n## Requirements\n- Processor: We recommend an `Apple Silicon` machine, but `Intel` works too!\n- System memory: `4GB+` is recommended\n- macOS version: `13.1+` (Ventura)\n\n\n## How can I install this thing?\n\n**\u2615\ufe0f (Recommended) Homebrew**\n* `brew install --cask mac-monitor`\n\n**\ud83d\udce6 Installer package**\n* Go to the releases section and download the latest installer: https://github.com/Brandon7CC/mac-monitor/releases\n\n**Install**\n* Open the app: `Mac Monitor.app`\n* You\u0027ll be prompted to \"Open System Settings\" to \"Allow\" the System Extension.\n* Next, System Settings will automatically open to `Full Disk Access` -- you\u0027ll need to flip the switch to enable this for the `Mac Monitor Security Extension`. Full Disk Access is a [*requirement* of Endpoint Security](https://developer.apple.com/documentation/endpointsecurity/3259700-e",
  "github_repo": "Brandon7CC/mac-monitor",
  "github_stars": 1353,
  "github_topics": [
    "endpoint-security",
    "macos",
    "swift",
    "swiftui"
  ],
  "homepage": "https://github.com/Brandon7CC/mac-monitor",
  "homepage_og_description": null,
  "homepage_og_image": null,
  "homepage_title": null,
  "installs_30d": 53,
  "installs_365d": 634,
  "installs_90d": 200,
  "last_seen": "2026-06-20T00:47:34+00:00",
  "llm_generated_at": null,
  "llm_model": null,
  "names": [
    "Mac Monitor"
  ],
  "one_liner": null,
  "rank_30d": 1962,
  "rank_365d": 1889,
  "rank_90d": 1735,
  "raw_hash": "feff54288fe12630",
  "ruby_source_path": "Casks/m/mac-monitor.rb",
  "tap": "homebrew/cask",
  "token": "mac-monitor",
  "version": "2.1.0",
  "why_use_this": null
}