- Print
- DarkLight
This documentation version is deprecated, please click here for the latest version.
Article summary
Did you find this summary helpful?
Thank you for your feedback
LimaCharlie's Mac sensor interfaces with the kernel to acquire deep visibility into the host's activity while taking measures to preverse the host's performance. The Mac sensor currently supports all versions of MacOS 10.7 and up.
Installation Instructions
Basic sensor installation instructions can be found here.
Looking for alternative installation methods?
- macOS Sensor Installation - Latest OS Versions
- macOS Sensor Installation - Older OS Versions
- macOS Sensor Installation - MDM Configuration profiles
Supported Events
AUTORUN_CHANGE
CLOUD_NOTIFICATION
CODE_IDENTITY
CONNECTED
DATA_DROPPED
DNS_REQUEST
EXEC_OOB
FILE_CREATE
FILE_DELETE
FILE_MODIFIED
FILE_TYPE_ACCESSED
FIM_HIT
HIDDEN_MODULE_DETECTED
MODULE_LOAD
-- temporarily disabledMODULE_MEM_DISK_MISMATCH
NETWORK_CONNECTIONS
NETWORK_SUMMARY
NEW_DOCUMENT
NEW_PROCESS
NEW_TCP4_CONNECTION
NEW_UDP4_CONNECTION
NEW_TCP6_CONNECTION
NEW_UDP6_CONNECTION
RECEIPT
SERVICE_CHANGE
SHUTTING_DOWN
SSH_LOGIN
SSH_LOGOUT
STARTING_UP
TERMINATE_PROCESS
TERMINATE_TCP4_CONNECTION
TERMINATE_UDP4_CONNECTION
TERMINATE_TCP6_CONNECTION
TERMINATE_UDP6_CONNECTION
USER_LOGIN
USER_LOGOUT
USER_OBSERVED
VOLUME_MOUNT
VOLUME_UNMOUNT
YARA_DETECTION
Supported Commands
artifact_get
deny_tree
dir_find_hash
dir_list
dns_resolve
doc_cache_get
exfil_add
exfil_del
exfil_get
file_del
file_get
file_hash
file_info
file_mov
fim_add
fim_del
fim_get
hidden_module_scan
history_dump
mem_find_handle
mem_find_string
mem_handles
mem_map
mem_read
mem_strings
netstat
os_autoruns
os_kill_process
os_processes
os_resume
os_services
os_suspend
os_version
put
reg_list
rejoin_network
restart
run
segregate_network
set_performance_mode
uninstall
yara_scan
yara_update
Artifacts
Given configured paths to collect from, the Mac sensor can batch upload logs / artifacts directly from the host.
Learn more about collecting Artifacts here.
Payloads
For more complex needs not supported by Events, Artifacts, or Commands, it's possible to execute payloads on hosts via the Mac sensor.
Learn more about executing Payloads here.
Was this article helpful?