redcanaryco / mac-monitor

Red Canary Mac Monitor is an advanced, stand-alone system monitoring tool tailor-made for macOS security research. Beginning with Endpoint Security (ES), it collects and enriches system events, displaying them graphically, with an expansive feature set designed to reduce noise.
938 stars 46 forks source link

仅内部办公使用 For internal office use only #36

Closed ouyangningdong closed 3 months ago

ouyangningdong commented 3 months ago

Hello, when I was working on the company's network security emergency plan, I saw your tool and thought it was great. I would like to ask if I can use this tool for emergency response in the event of an intrusion

Brandon7CC commented 3 months ago

Hi @ouyangningdong,

Thank you for the kind words! Mac Monitor was designed primarily as a dynamic analysis tool and does not enable any "response" actions. Furthermore, the System Extension does not process events while a trace is not occurring. The primary use case here is detailed analysis of Endpoint Security (ES) events over short timespans (e.g. logic vulnerability research, malware analysis, system troubleshooting, etc).

Thanks for the question!

@mgraeber-rc could you close this one out?