Guide · 2026-10-11

Mac Intrusion Logging

How to send logs from company Macs to a central server, which events to collect to find an intrusion, which tools to use, and which files to check on a Mac you suspect.

Scope: company-managed Macs, macOS 13 and laterFor IT and security staff

Conclusion

  • macOS has no setting that forwards its main log (the unified log) to a remote server. Install an agent on each Mac and deploy it with MDM.
  • For intrusion detection, the unified log is a weak source. Use Endpoint Security events: process execution, persistence, logins, and tamper actions. These four are the minimum.
  • Small company: use Elastic Defend or Jamf Protect for continuous logs, and Aftermath for a one-time check of a suspect Mac.
  • On a suspect Mac, check launch items, background items, download history, permission databases and shell history first. Send logs off the Mac in near real time, because an attacker with root can delete local logs.

Sending Mac logs to a server

The unified log limit

Since macOS 10.12, most system and app messages go to the unified log (os_log). The unified log has no setting that sends it to a remote server.

The old syslogd and /etc/syslog.conf can still forward, for example *.* @logserver:514. But they only see programs that still use the old syslog() API, which is a small part. Do not depend on this.

Three setups

Ways to get logs off company Macs
SetupHow it worksUse when
Commercial agentInstall an EDR or log agent with MDM. It uses Apple's Endpoint Security framework and sends events to its cloud or to your SIEM.You want detection rules and alerts without building them. Most companies do this.
Build it yourselfA launchd daemon runs log stream --style ndjson --predicate '<filter>' or eslogger. Fluent Bit or Vector on the Mac reads the output and forwards it over TLS to Loki, Elasticsearch, Graylog or syslog.You need app or system logs for troubleshooting, and you have staff to write filters and alerts.
Collect on demandRun log collect or sysdiagnose and upload the file.One-time troubleshooting. This is not continuous.

Use --predicate in a DIY setup. The full stream is very large.

MDM work

Privacy, law and volume

What to collect

If a Mac can be compromised, its local logs cannot be fully trusted. Collect events that show what ran, what stays after a reboot, who logged in, and what was turned off. Send them off the Mac in near real time.

Main source: Endpoint Security

Priority list

P0 is the minimum. With P0 alone you can find most real Mac intrusions: info-stealers, fake installers and stolen SSH keys.

Events to collect, by priority
PriorityCategoryWhat to recordSource
P0Process executionPath, arguments, parent process, user, code signature, Team ID, cdhashEndpoint Security exec, fork, exit
P0PersistenceNew or changed LaunchAgents and LaunchDaemons, login items, background items, cron jobsbtm_launch_item_add (macOS 13+); file writes to ~/Library/LaunchAgents and /Library/LaunchDaemons
P0AuthenticationLogin, logout, screen unlock, sudo, su, SSH logins, failed loginsEndpoint Security authentication, openssh_login, sudo, su (macOS 13 to 14+); unified log process == "sudo", process == "sshd"
P0Defense tamperingEDR agent stopped, MDM profile removed, firewall off, Gatekeeper off (spctl), log erase, quarantine attribute removedexec events matched by command rules; profile events
P0Info-stealer behaviorosascript with display dialog and hidden answer (fake password prompt); non-browser processes that read browser cookie and login files or the keychainexec arguments; Endpoint Security open with a path filter
P1Privacy permissionsApps that get camera, microphone, screen recording, Full Disk Access or AccessibilityUnified log subsystem == "com.apple.TCC"; tcc_modify (macOS 15+)
P1AccountsNew user, new admin, group change, password changeEndpoint Security od_* events (macOS 14+)
P1ExtensionsKernel extension, system extension, configuration profile and authorization plugin installskextload, system extension events
P1Remote accessSSH, Screen Sharing or Remote Management turned onexec of systemsetup and kickstart; launchd events
P1Sensitive file accessReads of ~/.ssh and cloud CLI credentials (~/.aws, ~/.kube)Endpoint Security open with a path filter
P1DNSDNS queries per Mac, per process if possibleCompany DNS resolver or web gateway; EDR network extension
P2Network connectionsOutbound connections per process, new listening portsEDR network extension. Endpoint Security has no network events.
P2DownloadsFiles with the quarantine attribute; executables written to /tmp, /Users/Shared, ~/DownloadsEndpoint Security create, rename with xattr data
P2Malware detectionXProtect and XProtect Remediator resultsUnified log for the XProtect processes
P2USB and volumesMounted disks and DMG filesEndpoint Security mount
NoteEndpoint Security event names and the first macOS version for each event come from Apple's framework documentation. Check them against the macOS versions in your fleet before you write rules.

Daily state snapshot

A snapshot catches changes that you did not see as events. osquery5 is good for this. Record once a day:

Protect the logs

What to skip

Why this order

What the guidance agrees on

No official priority list exists for macOS. This order follows two common references: MITRE ATT&CK for macOS2, and the 2024 joint guidance on event logging from ASD's ACSC, CISA, NSA and partners, including Singapore's CSA3. Both put process execution, persistence and authentication first. So the P0 rows are a safe start.

Change the priorities to match your real threats. For a company with many developers, watch SSH keys and cloud credentials more closely.

Two changes for current threats

Tools

There is no single best tool. Choose by goal.

Continuous collection

Tools for all Macs, every day
ToolCostNotes
Jamf ProtectPaidMac only. Strong Mac detections. Good if you already use Jamf.
CrowdStrike, SentinelOne, Microsoft DefenderPaidCross-platform EDR. Good if you also have Windows.
Elastic Defend (Elastic Agent)Free tierEndpoint Security events into Elasticsearch. The best free EDR-style option.
osquery + FleetFreeSQL queries on Mac state. Very good for snapshots and inventory. Weak for real-time events.
SantaFreeAllowlist and blocklist for binaries. Logs every exec. Now maintained by North Pole Security6.
WazuhFreeAgent and server. Mac support is weaker than its Linux support.
esloggerBuilt inRaw Endpoint Security JSON. You build the filter, the shipping and the alerts.

One-time investigation

Tools for one suspect Mac
ToolNotes
Aftermath (Jamf, open source)Collects the main forensic files from a Mac and builds a timeline4. A good first step.
VelociraptorRemote collection with ready-made macOS artifacts7. Good for many Macs at once.
mac_aptParses a Mac disk image or collected files offline8.
Objective-See toolsFree9. KnockKnock lists all persistence items, and non-experts can read its output. BlockBlock and LuLu add live alerts.
PickSmall company: Elastic Defend or Jamf Protect for continuous logs, and Aftermath for one-time checks.

Files to check on a suspect Mac

Before you start

WarningAn attacker with root can edit all the files below. If the Mac is truly compromised, trust the logs on your server more than the files on the Mac.

Tier 1: always check

Core files for every investigation
WhatPathHow to readWhat it shows
Launch items/Library/LaunchDaemons/, /Library/LaunchAgents/, ~/Library/LaunchAgents/Read the .plist filesThe most common malware persistence
Background items (BTM)/private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btmsudo sfltool dumpbtmAll login and background items, with developer name
Download history~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2SQLiteEach downloaded file, its source URL and time. Shows how malware arrived.
Unified log/private/var/db/diagnostics/, /private/var/db/uuidtext/sudo log collect, then log show with a predicatesudo, SSH, TCC, XProtect and installs
Privacy permissions (TCC)/Library/Application Support/com.apple.TCC/TCC.db, ~/Library/Application Support/com.apple.TCC/TCC.dbSQLiteApps with Full Disk Access, screen recording, Accessibility, camera or microphone
Shell history~/.zsh_history, ~/.zsh_sessions/, ~/.bash_historyTextCommands that the attacker typed, such as curl … | bash
Install history/Library/Receipts/InstallHistory.plist, /var/log/install.logplist, textPackages installed, and when
SSH~/.ssh/authorized_keys, /etc/ssh/sshd_configTextAdded keys and SSH backdoors

Tier 2: check when Tier 1 shows something

Showing the results to a user

Do not show raw logs. Make one report with four sections, in this order:

  1. Timeline. Downloads, installs, new persistence items and new permissions, sorted by time.
  2. Persistence items. Each item with signer, Team ID and path. Mark unsigned items and items from unknown developers.
  3. Permissions. Each app with Full Disk Access, screen recording or Accessibility.
  4. Findings. Mark each finding as normal, suspicious or bad, with one plain sentence for each.

Method and sources

This guide comes from a working discussion on 2026-10-09 to 2026-10-11 about logging on company Macs. It was not tested on a live fleet. Event names and macOS version limits follow Apple's Endpoint Security documentation as of mid-2026. Check them against your macOS versions. The 90-day retention is a common practice, not a legal rule. The claim that info-stealers are the most common Mac threat comes from public vendor threat reports in 2025 and 2026; no single report is cited here.

  1. Apple Developer, Endpoint Security framework, developer.apple.com/documentation/endpointsecurity
  2. MITRE ATT&CK, macOS matrix, attack.mitre.org/matrices/enterprise/macos
  3. ASD's ACSC, CISA, FBI, NSA and partners, Best Practices for Event Logging and Threat Detection, 2024-08-21, cisa.gov; Singapore CSA advisory AD-2024-016, csa.gov.sg
  4. Jamf, Aftermath, github.com/jamf/aftermath
  5. osquery, osquery.io; Fleet, fleetdm.com
  6. North Pole Security, Santa, github.com/northpolesec/santa
  7. Velociraptor documentation, docs.velociraptor.app
  8. mac_apt, github.com/ydkhatri/mac_apt
  9. Objective-See, tools, objective-see.org/tools.html
  10. Personal Data Protection Commission Singapore, pdpc.gov.sg

Back to the reading list