You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Anything else?
Streaming network events that also contain process information is a real pain on MacOS. It would be nice to have the telemetry stream provided by EDR without the EDR.
The text was updated successfully, but these errors were encountered:
Hey @jkennedyvz! Thank you for the excellent suggestions!
Enabling CLI like functionality has been suggestion before, but I've had to shoot it down in the past. Let me get back to you on this. In the meantime I'd suggest using the telemetry export options, using /usr/bin/eslogger or Patrick Wardle's / Jaron Bradley's tools.
Network telemetry is very much on the table. To do so we'll need to add a Network Extension -- on my backlog 😉
Thanks for the quick response! I'm currently using several tools from Objective-see, but there are some limitations on the networking side to work through there as well. See objective-see/Netiquette#11 and objective-see/DNSMonitor#4
At a high level -- can you summarize your request?
I would like the ability to stream events from the command line similar to the logging offered by little snitch https://help.obdev.at/littlesnitch5/adv-commandline or objective-see tools https://github.com/objective-see/ProcessMonitor
What is the current alternative solution?
https://help.obdev.at/littlesnitch5/adv-commandline
https://github.com/objective-see/ProcessMonitor
Anything else?
Streaming network events that also contain process information is a real pain on MacOS. It would be nice to have the telemetry stream provided by EDR without the EDR.
The text was updated successfully, but these errors were encountered: