Hacker News new | ask | show | jobs
by SmellyPotato22 1389 days ago
Totally that's why Apple made endpoint security for security vendors. You can even pipe the events from the kernel with "sudo eslogger exec | jq" on the new macOS

https://developer.apple.com/documentation/endpointsecurity