ronwai
|
db4ae69a0f
|
add environment variable collection behind -parseEnv flag
|
2021-06-15 23:07:57 -07:00 |
|
Objective-See
|
1a9c2e0c80
|
rpid (via ESF)
-copy of audit_token
-responsible pid via ESF (if v4+)
|
2020-12-16 11:56:35 -10:00 |
|
Objective-See
|
6608eadb51
|
v1.6.0
-process architecture (intel, apple silicon)
-dynamic code signing info, now via audit token
|
2020-12-15 22:13:23 -10:00 |
|
Objective-See
|
42a2c003b0
|
v1.5
-UI improvement(s)
-added name (via app bundle, where possible)
-process parent lookup first attempted via "responsible pid"
|
2020-12-14 20:31:23 -10:00 |
|
Objective-See
|
40b113e6b0
|
improved output
|
2020-12-09 22:57:07 -10:00 |
|
Objective-See
|
d7d89ed534
|
improved output
-cd hash
-blank team id / signing id
|
2020-12-09 22:26:56 -10:00 |
|
Objective-See
|
c3b9bda266
|
v1.4.0
- improved output (JSON)
- universal build (intel + arm64)
- ui updates (icon, dark mode++)
|
2020-12-09 17:04:16 -10:00 |
|
Patrick Wardle
|
9309f85213
|
v.1.3.0
inclusion of computed code-signing info
|
2020-01-26 12:23:15 -10:00 |
|
Patrick Wardle
|
5b3d3f20cb
|
fixed formatting of cdhash
|
2019-11-30 10:18:00 -10:00 |
|
Patrick Wardle
|
53c7af0d77
|
v1.2.1
-added timestamp to event
|
2019-11-28 09:34:19 -10:00 |
|
Patrick Wardle
|
c0a9760298
|
library now takes user-specified events
- `start` method now takes events of interest (vs. hardcoding them)
- improved tokenization of es_string_token_t
|
2019-11-27 10:35:40 -10:00 |
|
Patrick Wardle
|
9d63713915
|
added (cli) app to project
|
2019-10-31 11:19:11 -10:00 |
|