Skip to main content

macOS Security Audit Agent (MSAA)

MSAA is a local-first macOS audit, monitoring, and investigation platform. It is designed for analysts who need transparent evidence collection, reviewable alerts, and local-only reports without sending telemetry off the machine.

This repository is intended to be understandable, auditable, and safe enough for public review, institutional evaluation, and responsible internal deployment.

What It Does

  • Runs read-only macOS security audits
  • Surfaces findings with evidence, confidence, and rule provenance
  • Tracks review state, notes, suppression decisions, and case history
  • Correlates events into investigation patterns and flight-recorder timelines
  • Provides Apple Security Forecast summaries with low-noise grouping
  • Supports optional user LaunchAgent mode and optional root-owned system LaunchDaemon mode
  • Exports HTML and JSON reports locally
  • Preserves evidence snapshots before cleanup or remediation

What It Does Not Do

  • No telemetry
  • No cloud dependency
  • No browser history extraction
  • No cookie, token, password, or keychain extraction
  • No hidden persistence
  • No stealth behavior
  • No offensive exploitation
  • No hack-back or retaliation
  • No automatic destructive cleanup
  • No remediation without user approval

Safety Model

The default mode is conservative.

Safe by default:

  • no packet capture unless explicitly chosen
  • no aggressive scans unless explicitly chosen
  • no full localhost scan unless explicitly chosen
  • no destructive cleanup by default
  • no system daemon install by default
  • no remediation execution by default
  • no automatic uploads
  • no automatic cloud enrichment using private data

Important features that can increase risk always require explicit user action and a warning.

Privacy Model

All data stays local on the Mac unless you explicitly export a report.

The app does not collect:

  • browser history
  • private browsing state
  • cookies
  • passwords
  • keychain data
  • tokens
  • secrets
  • ambient camera/microphone content

Redaction support is available for:

  • usernames
  • IP addresses
  • MAC addresses
  • hostnames
  • filesystem paths
  • URL secrets

Supported macOS Releases

The project is developed for current Apple silicon and Intel Macs running modern macOS releases. The codebase is intended to be reviewed and tested on current supported macOS versions from Apple, not on hidden or unsupported system behavior.

Deployment Modes

User Monitor Mode

  • LaunchAgent under the logged-in user
  • Best for UI notifications and per-session alerts
  • Default install mode

System Monitor Mode

  • Root-owned LaunchDaemon under /Library/LaunchDaemons
  • Starts at boot
  • Writes to the shared system database
  • Does not show GUI alerts directly
  • Uses the user notifier companion for visible alerts after login

Scan Modes

Safe Scan

The default scan mode is read-only and low impact.

Verbose Scan

Adds more evidence detail without changing system state.

Aggressive Local Scan

Targets localhost-only port enumeration and related local checks. This is intentionally opt-in because it can be noisy.

Evidence Preservation

The platform prefers evidence preservation over cleanup.

Before cleanup or remediation, the app can:

  • warn about potential evidence loss
  • create an evidence snapshot
  • preserve logs, notes, reports, and case data

Do not delete logs automatically during an active investigation.

Main UI Areas

  • Dashboard
  • Intrusion Detection
  • Investigation Priorities
  • Flight Recorder
  • Evidence Snapshots
  • Apple Security Forecast
  • Logs
  • Settings
  • Operational Health
  • Skins
  • Results
  • Investigation Notes
  • Command Preview

Installation

PyPI

python3 -m pip install macos-security-audit-agent
macos-security-audit-agent

CLI examples:

macos-security-audit-agent --safe-scan
macos-security-audit-agent --aggressive-scan
macos-security-audit-agent --report report.html
macos-security-audit-agent --system-health

Source

python3 -m pip install -r requirements.txt
python3 launcher.py

PyInstaller app

Build the bundled macOS app with the provided spec file:

pyinstaller "Mac Audit Agent.spec"

Uninstall

  • Remove the LaunchAgent or LaunchDaemon from Launch Services
  • Remove the runtime copy if you installed system mode
  • Preserve reports, snapshots, notes, and evidence unless you intentionally choose to remove them

Legal / Authorized Use Notice

Use this software only on systems and networks you own or are explicitly authorized to assess.

If you are unsure whether you are authorized, stop and obtain written approval before running scans, monitors, or exports.

Documentation

Tests

The repository includes unit tests, storage tests, UI smoke tests, and report export tests. The public release checklist requires that the test suite, compile checks, and diff checks pass before distribution.

Metadata

Release files for macos-security-audit-agent 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for macos-security-audit-agent 0.1.0
File Size Uploaded
macos_security_audit_agent-0.1.0.tar.gz 8.8 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for macos-security-audit-agent 0.1.0
File Interpreter ABI Platform
macos_security_audit_agent-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.2 MB

Release files / macos_security_audit_agent-0.1.0.tar.gz

Download URL macos_security_audit_agent-0.1.0.tar.gz
Size 8.8 MB
Tags Source
SHA-256 checksum
How to use checksums
6fd4313a77973d9fe8596718d34d2e3c75580714181f905ae51a35b3c2723239
BLAKE2b-256 checksum
How to use checksums
c407602f2507a1f15b3412f70a74d8a74fb0822464a29b0b3e24a6c018123b57
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.5

Release files / macos_security_audit_agent-0.1.0-py3-none-any.whl

Download URL macos_security_audit_agent-0.1.0-py3-none-any.whl
Size 3.4 MB
Tags Python 3
SHA-256 checksum
How to use checksums
0c16b6a5cbbad0ca20351423d498d0892f35ad5a3fef92d781e44ec8c60d4cff
BLAKE2b-256 checksum
How to use checksums
d9538e64268259161d24056c1876960c422302859da0f98bffe9909fd9232ab5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.5

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page