Guide · 2026-10-11
Mac Intrusion Logging
How to send logs from company Macs to a central server, which events to collect to find an intrusion, which tools to use, and which files to check on a Mac you suspect.
Conclusion
- macOS has no setting that forwards its main log (the unified log) to a remote server. Install an agent on each Mac and deploy it with MDM.
- For intrusion detection, the unified log is a weak source. Use Endpoint Security events: process execution, persistence, logins, and tamper actions. These four are the minimum.
- Small company: use Elastic Defend or Jamf Protect for continuous logs, and Aftermath for a one-time check of a suspect Mac.
- On a suspect Mac, check launch items, background items, download history, permission databases and shell history first. Send logs off the Mac in near real time, because an attacker with root can delete local logs.
Sending Mac logs to a server
The unified log limit
Since macOS 10.12, most system and app messages go to the unified log (os_log). The unified log has no setting that sends it to a remote server.
The old syslogd and /etc/syslog.conf can still forward, for example *.* @logserver:514. But they only see programs that still use the old syslog() API, which is a small part. Do not depend on this.
Three setups
| Setup | How it works | Use when |
|---|---|---|
| Commercial agent | Install an EDR or log agent with MDM. It uses Apple's Endpoint Security framework and sends events to its cloud or to your SIEM. | You want detection rules and alerts without building them. Most companies do this. |
| Build it yourself | A launchd daemon runs log stream --style ndjson --predicate '<filter>' or eslogger. Fluent Bit or Vector on the Mac reads the output and forwards it over TLS to Loki, Elasticsearch, Graylog or syslog. | You need app or system logs for troubleshooting, and you have staff to write filters and alerts. |
| Collect on demand | Run log collect or sysdiagnose and upload the file. | One-time troubleshooting. This is not continuous. |
Use --predicate in a DIY setup. The full stream is very large.
MDM work
- Install the agent package silently.
- Push a PPPC profile that gives the agent Full Disk Access.
- Approve the agent's system extension with a profile. Without this, each user sees a prompt.
- Keep the agent running with a launchd job. Turn on tamper protection if the product has it.
Privacy, law and volume
- Private data. The unified log hides many values as
<private>. A logging profile can show them, but then you collect much more personal data. - Law. In Singapore, the PDPA applies10. Tell employees what you collect and why, and put it in the IT policy. Do the same in each country where you have staff.
- Volume. Filter on the Mac. Do not send everything. This saves bandwidth, battery and server cost.
What to collect
If a Mac can be compromised, its local logs cannot be fully trusted. Collect events that show what ran, what stays after a reboot, who logged in, and what was turned off. Send them off the Mac in near real time.
Main source: Endpoint Security
- The unified log does not reliably record process starts, file changes or persistence.
- Use an agent built on Apple's Endpoint Security framework1: an EDR, Elastic, Wazuh, or osquery with Endpoint Security.
- For a DIY setup, macOS 13 and later include
eslogger. It writes Endpoint Security events as JSON. It needs root and Full Disk Access. - OpenBSM audit (
praudit,/etc/security/audit_control) is deprecated. Do not build on it.
Priority list
P0 is the minimum. With P0 alone you can find most real Mac intrusions: info-stealers, fake installers and stolen SSH keys.
| Priority | Category | What to record | Source |
|---|---|---|---|
| P0 | Process execution | Path, arguments, parent process, user, code signature, Team ID, cdhash | Endpoint Security exec, fork, exit |
| P0 | Persistence | New or changed LaunchAgents and LaunchDaemons, login items, background items, cron jobs | btm_launch_item_add (macOS 13+); file writes to ~/Library/LaunchAgents and /Library/LaunchDaemons |
| P0 | Authentication | Login, logout, screen unlock, sudo, su, SSH logins, failed logins | Endpoint Security authentication, openssh_login, sudo, su (macOS 13 to 14+); unified log process == "sudo", process == "sshd" |
| P0 | Defense tampering | EDR agent stopped, MDM profile removed, firewall off, Gatekeeper off (spctl), log erase, quarantine attribute removed | exec events matched by command rules; profile events |
| P0 | Info-stealer behavior | osascript with display dialog and hidden answer (fake password prompt); non-browser processes that read browser cookie and login files or the keychain | exec arguments; Endpoint Security open with a path filter |
| P1 | Privacy permissions | Apps that get camera, microphone, screen recording, Full Disk Access or Accessibility | Unified log subsystem == "com.apple.TCC"; tcc_modify (macOS 15+) |
| P1 | Accounts | New user, new admin, group change, password change | Endpoint Security od_* events (macOS 14+) |
| P1 | Extensions | Kernel extension, system extension, configuration profile and authorization plugin installs | kextload, system extension events |
| P1 | Remote access | SSH, Screen Sharing or Remote Management turned on | exec of systemsetup and kickstart; launchd events |
| P1 | Sensitive file access | Reads of ~/.ssh and cloud CLI credentials (~/.aws, ~/.kube) | Endpoint Security open with a path filter |
| P1 | DNS | DNS queries per Mac, per process if possible | Company DNS resolver or web gateway; EDR network extension |
| P2 | Network connections | Outbound connections per process, new listening ports | EDR network extension. Endpoint Security has no network events. |
| P2 | Downloads | Files with the quarantine attribute; executables written to /tmp, /Users/Shared, ~/Downloads | Endpoint Security create, rename with xattr data |
| P2 | Malware detection | XProtect and XProtect Remediator results | Unified log for the XProtect processes |
| P2 | USB and volumes | Mounted disks and DMG files | Endpoint Security mount |
Daily state snapshot
A snapshot catches changes that you did not see as events. osquery5 is good for this. Record once a day:
- Installed apps and their signatures.
- Browser extensions.
- Configuration profiles.
- SIP, FileVault, Gatekeeper and firewall status.
- Members of the
admingroup.
Protect the logs
- Send a heartbeat every few minutes. Alert when a Mac goes silent. A gap in the logs often means that the attacker stopped the agent.
- Use TLS. Authenticate each Mac with its own certificate.
- Keep the logs on a server that the Macs can write to but cannot read or delete.
- Use one accurate time source on all Macs and servers, and a structured format such as JSON3. Without this, you cannot join events from different Macs into one timeline.
- Keep at least 90 days. Most incidents are found weeks late.
What to skip
- The full unified log stream. It is very large, and most of it does not help to find an intrusion.
- File events for every path. Filter to sensitive directories, or the volume will be too large.
Why this order
What the guidance agrees on
No official priority list exists for macOS. This order follows two common references: MITRE ATT&CK for macOS2, and the 2024 joint guidance on event logging from ASD's ACSC, CISA, NSA and partners, including Singapore's CSA3. Both put process execution, persistence and authentication first. So the P0 rows are a safe start.
Change the priorities to match your real threats. For a company with many developers, watch SSH keys and cloud credentials more closely.
Two changes for current threats
- DNS is P1. If your company DNS or web gateway already logs queries, the cost is almost zero. Most malware must contact its server, and DNS shows this.
- Info-stealer behavior is P0. Info-stealers such as AMOS and Poseidon are now the most common Mac threat. They show a fake password prompt with
osascript, then read the keychain and browser files.
Tools
There is no single best tool. Choose by goal.
Continuous collection
| Tool | Cost | Notes |
|---|---|---|
| Jamf Protect | Paid | Mac only. Strong Mac detections. Good if you already use Jamf. |
| CrowdStrike, SentinelOne, Microsoft Defender | Paid | Cross-platform EDR. Good if you also have Windows. |
| Elastic Defend (Elastic Agent) | Free tier | Endpoint Security events into Elasticsearch. The best free EDR-style option. |
| osquery + Fleet | Free | SQL queries on Mac state. Very good for snapshots and inventory. Weak for real-time events. |
| Santa | Free | Allowlist and blocklist for binaries. Logs every exec. Now maintained by North Pole Security6. |
| Wazuh | Free | Agent and server. Mac support is weaker than its Linux support. |
eslogger | Built in | Raw Endpoint Security JSON. You build the filter, the shipping and the alerts. |
One-time investigation
| Tool | Notes |
|---|---|
| Aftermath (Jamf, open source) | Collects the main forensic files from a Mac and builds a timeline4. A good first step. |
| Velociraptor | Remote collection with ready-made macOS artifacts7. Good for many Macs at once. |
| mac_apt | Parses a Mac disk image or collected files offline8. |
| Objective-See tools | Free9. KnockKnock lists all persistence items, and non-experts can read its output. BlockBlock and LuLu add live alerts. |
Files to check on a suspect Mac
Before you start
- Collect first, and analyze later. Do not reboot or clean the Mac before you collect. You will lose running processes and network connections.
- Many of these files need root and Full Disk Access.
Tier 1: always check
| What | Path | How to read | What it shows |
|---|---|---|---|
| Launch items | /Library/LaunchDaemons/, /Library/LaunchAgents/, ~/Library/LaunchAgents/ | Read the .plist files | The most common malware persistence |
| Background items (BTM) | /private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btm | sudo sfltool dumpbtm | All login and background items, with developer name |
| Download history | ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 | SQLite | Each downloaded file, its source URL and time. Shows how malware arrived. |
| Unified log | /private/var/db/diagnostics/, /private/var/db/uuidtext/ | sudo log collect, then log show with a predicate | sudo, SSH, TCC, XProtect and installs |
| Privacy permissions (TCC) | /Library/Application Support/com.apple.TCC/TCC.db, ~/Library/Application Support/com.apple.TCC/TCC.db | SQLite | Apps with Full Disk Access, screen recording, Accessibility, camera or microphone |
| Shell history | ~/.zsh_history, ~/.zsh_sessions/, ~/.bash_history | Text | Commands that the attacker typed, such as curl … | bash |
| Install history | /Library/Receipts/InstallHistory.plist, /var/log/install.log | plist, text | Packages installed, and when |
| SSH | ~/.ssh/authorized_keys, /etc/ssh/sshd_config | Text | Added keys and SSH backdoors |
Tier 2: check when Tier 1 shows something
- Configuration profiles:
sudo profiles show -all. Malware can install a profile with a proxy or a root certificate. - Accounts and admins:
dscl . -list /Users,dscl . -read /Groups/admin. - Shell startup files:
/etc/zshrc,~/.zshrc,~/.zprofile. They can run code at each terminal start. - Cron:
/usr/lib/cron/tabs/. - Browser extensions: the Chrome, Edge and Safari profile folders.
- File system change history:
/.fseventsd/. It helps to build a timeline. - Running state:
ps aux,lsof -i,systemextensionsctl list. Capture these before a reboot.
Showing the results to a user
Do not show raw logs. Make one report with four sections, in this order:
- Timeline. Downloads, installs, new persistence items and new permissions, sorted by time.
- Persistence items. Each item with signer, Team ID and path. Mark unsigned items and items from unknown developers.
- Permissions. Each app with Full Disk Access, screen recording or Accessibility.
- Findings. Mark each finding as normal, suspicious or bad, with one plain sentence for each.
Method and sources
This guide comes from a working discussion on 2026-10-09 to 2026-10-11 about logging on company Macs. It was not tested on a live fleet. Event names and macOS version limits follow Apple's Endpoint Security documentation as of mid-2026. Check them against your macOS versions. The 90-day retention is a common practice, not a legal rule. The claim that info-stealers are the most common Mac threat comes from public vendor threat reports in 2025 and 2026; no single report is cited here.
- Apple Developer, Endpoint Security framework, developer.apple.com/documentation/endpointsecurity
- MITRE ATT&CK, macOS matrix, attack.mitre.org/matrices/enterprise/macos
- ASD's ACSC, CISA, FBI, NSA and partners, Best Practices for Event Logging and Threat Detection, 2024-08-21, cisa.gov; Singapore CSA advisory AD-2024-016, csa.gov.sg
- Jamf, Aftermath, github.com/jamf/aftermath
- osquery, osquery.io; Fleet, fleetdm.com
- North Pole Security, Santa, github.com/northpolesec/santa
- Velociraptor documentation, docs.velociraptor.app
- mac_apt, github.com/ydkhatri/mac_apt
- Objective-See, tools, objective-see.org/tools.html
- Personal Data Protection Commission Singapore, pdpc.gov.sg